OTL logfile created on: 15/11/2013 23.51.07 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\flora\Documenti\Download
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
1022,05 Mb Total Physical Memory | 73,36 Mb Available Physical Memory | 7,18% Memory free
2,40 Gb Paging File | 1,48 Gb Available in Paging File | 61,43% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 35,70 Gb Total Space | 9,93 Gb Free Space | 27,82% Space Free | Partition Type: FAT32
Drive D: | 35,87 Gb Total Space | 28,17 Gb Free Space | 78,52% Space Free | Partition Type: FAT32
Computer Name: ACER-DAC357703E | User Name: flora | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\flora\Documenti\Download\OTL(1).exe (OldTimer Tools)
PRC - C:\Programmi\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programmi\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Programmi\Panda Security\Panda Cloud Antivirus\PSUAService.exe (Panda Security, S.L.)
PRC - C:\Programmi\Panda Security\Panda Cloud Antivirus\PSUAMain.exe (Panda Security, S.L.)
PRC - C:\Programmi\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.)
PRC - C:\Programmi\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
PRC - C:\Programmi\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Programmi\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Programmi\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Programmi\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Programmi\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Programmi\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Documents and Settings\flora\Impostazioni locali\Dati applicazioni\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
PRC - C:\Programmi\File comuni\Java\Java Update\jusched.exe (Oracle Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Spyware Terminator\st_rsser.exe (Crawler.com)
PRC - C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
PRC - C:\Programmi\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Programmi\File comuni\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programmi\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe (Broadcom Corporation.)
PRC - c:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Programmi\acer\eRecovery\Monitor.exe (acer Inc.)
PRC - C:\Acer\eManager\anbmServ.exe (OSA Technologies Inc.)
PRC - C:\Acer\ePM\EPM-DM.exe (Acer Inc)
PRC - C:\Programmi\Arcade\PCMService.exe (CyberLink Corp.)
PRC - C:\Programmi\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
========== Modules (No Company Name) ========== MOD - C:\Programmi\Mozilla Firefox\mozjs.dll ()
MOD - C:\Programmi\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Programmi\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Programmi\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Programmi\Panda Security\Panda Cloud Antivirus\sqlite3.dll ()
MOD - C:\Programmi\Logitech\Logitech WebCam Software\LWS.exe ()
MOD - C:\Programmi\File comuni\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Programmi\WIDCOMM\Software Bluetooth\BTKeyInd.dll ()
========== Services (SafeList) ========== SRV - (SDWSCService) -- C:\Programmi\Spybot File not found
SRV - (SDUpdateService) -- C:\Programmi\Spybot File not found
SRV - (SDScannerService) -- C:\Programmi\Spybot File not found
SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) -- %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) -- C:\Programmi\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) -- C:\Programmi\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (PSUAService) -- C:\Programmi\Panda Security\Panda Cloud Antivirus\PSUAService.exe (Panda Security, S.L.)
SRV - (SpyHunter 4 Service) -- C:\Programmi\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (NanoServiceMain) -- C:\Programmi\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (McComponentHostService) -- C:\Programmi\McAfee Security Scan\3.8.130\McCHSvc.exe (McAfee, Inc.)
SRV - (TomTomHOMEService) -- C:\Programmi\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (MBAMService) -- C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (ST2012_Svc) -- C:\Programmi\Spyware Terminator\st_rsser.exe (Crawler.com)
SRV - (LVPrcSrv) -- C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (btwdins) -- c:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe (Broadcom Corporation.)
SRV - (anbmService) -- C:\Acer\eManager\anbmServ.exe (OSA Technologies Inc.)
SRV - (rpcapd) -- C:\Programmi\WinPCap\rpcapd.exe ()
========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (PSINAflt) -- C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (PSINReg) -- C:\WINDOWS\system32\drivers\PSINReg.sys (Panda Security, S.L.)
DRV - (PSINProt) -- C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINProc) -- C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINKNC) -- C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINFile) -- C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (NNSSTRM) -- C:\WINDOWS\system32\drivers\NNSStrm.sys (Panda Security, S.L.)
DRV - (NNSSMTP) -- C:\WINDOWS\system32\drivers\NNSSmtp.sys (Panda Security, S.L.)
DRV - (NNSTLSC) -- C:\WINDOWS\system32\drivers\NNStlsc.sys (Panda Security, S.L.)
DRV - (NNSPROT) -- C:\WINDOWS\system32\drivers\NNSProt.sys (Panda Security, S.L.)
DRV - (NNSPRV) -- C:\WINDOWS\system32\drivers\NNSPrv.sys (Panda Security, S.L.)
DRV - (NNSIDS) -- C:\WINDOWS\system32\drivers\NNSIds.sys (Panda Security, S.L.)
DRV - (NNSPOP3) -- C:\WINDOWS\system32\drivers\NNSPop3.sys (Panda Security, S.L.)
DRV - (NNSPICC) -- C:\WINDOWS\system32\drivers\NNSpicc.sys (Panda Security, S.L.)
DRV - (NNSPIHS) -- C:\WINDOWS\system32\drivers\NNSpihs.sys (Panda Security, S.L.)
DRV - (NNSHTTP) -- C:\WINDOWS\system32\drivers\NNSHttp.sys (Panda Security, S.L.)
DRV - (NNSHTTPS) -- C:\WINDOWS\system32\drivers\NNSHttps.sys (Panda Security, S.L.)
DRV - (NNSALPC) -- C:\WINDOWS\system32\drivers\NNSAlpc.sys (Panda Security, S.L.)
DRV - (PSKMAD) -- C:\WINDOWS\system32\drivers\PSKMAD.sys (Panda Security, S.L.)
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (EsgScanner) -- C:\WINDOWS\system32\drivers\EsgScanner.sys ()
DRV - (sp_rsdrv2) -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (esgiguard) -- C:\Programmi\Enigma Software Group\SpyHunter\esgiguard.sys ()
DRV - (w29n51) -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (PID_0928) -- C:\WINDOWS\system32\drivers\LV561AV.SYS (Logitech Inc.)
DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) -- C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTSLBCSP) -- C:\WINDOWS\system32\drivers\btslbcsp.sys (Broadcom Corporation.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (osaio) -- C:\WINDOWS\system32\drivers\osaio.sys (OSA Technologies, An Avocent Company)
DRV - (EpmShd) -- C:\WINDOWS\system32\drivers\epm-shd.sys (Acer Value Labs, USA)
DRV - (tifm21) -- C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWICH) -- C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (osanbm) -- C:\WINDOWS\system32\drivers\osanbm.sys (Windows (R) 2000 DDK provider)
DRV - (int15.sys) -- C:\Programmi\acer\eRecovery\int15.sys ()
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (EpmPsd) -- C:\WINDOWS\system32\drivers\epm-psd.sys (Acer Value Labs, USA)
DRV - (CAMCHALA) -- C:\WINDOWS\system32\drivers\camchal.sys (Conexant Systems Inc.)
DRV - (CAMCAUD) -- C:\WINDOWS\system32\drivers\camcaud.sys (Conexant Systems Inc.)
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (NPF) -- C:\WINDOWS\system32\drivers\npf.sys (Politecnico di Torino)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.comIE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-797491427-2050873350-1473301086-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.aruba.itIE - HKU\S-1-5-21-797491427-2050873350-1473301086-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-21-797491427-2050873350-1473301086-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-797491427-2050873350-1473301086-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-797491427-2050873350-1473301086-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-797491427-2050873350-1473301086-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "www.google.it"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0.1
FF - prefs.js..keyword.URL: ""
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programmi\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Programmi\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Programmi\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Programmi\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programmi\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programmi\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programmi\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmi\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\flora\Impostazioni locali\Dati applicazioni\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0.1\extensions\\Components: C:\Programmi\Mozilla Firefox\components [2013/11/15 20.40.28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0.1\extensions\\Plugins: C:\Programmi\Mozilla Firefox\plugins
[2012/09/08 21.29.34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\flora\Dati applicazioni\Mozilla\Extensions
[2013/10/27 19.52.06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\flora\Dati applicazioni\Mozilla\Extensions\home2@tomtom.com
[2012/09/08 21.33.40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\flora\Dati applicazioni\Mozilla\Firefox\Profiles\rcnn0ibd.default\extensions
[2013/11/15 20.40.28 | 000,000,000 | ---D | M] (No name found) -- C:\Programmi\Mozilla Firefox\browser\extensions
[2013/11/15 20.40.28 | 000,000,000 | ---D | M] (Default) -- C:\Programmi\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/01/27 17.11.08 | 000,002,325 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\pandasecuritytb.xml
========== Chrome ========== CHR - default_search_provider: Mysearchdial ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
http://www.google.comCHR - plugin: Primo utente (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll
CHR - plugin: Error reading preferences file
O1 HOSTS File: ([2004/08/19 05.00.00 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Programmi\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (BuzzSearch) - {5cf5a690-c8f4-488e-9d20-f21aef602d41} - C:\Programmi\BuzzSearch\BuzzSearchBHO.dll (BuzzSearch)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [EPM-DM] c:\Acer\ePM\EPM-DM.exe (Acer Inc)
O4 - HKLM..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe (Acer Value Labs, Taiwan)
O4 - HKLM..\Run: [eRecoveryService] C:\Programmi\acer\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Programmi\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Programmi\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PCMService] C:\Programmi\Arcade\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PSUAMain] C:\Programmi\Panda Security\Panda Cloud Antivirus\PSUAMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [SDTray] C:\Programmi\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Programmi\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [SpywareTerminatorShield] C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKLM..\Run: [SpywareTerminatorUpdater] C:\Programmi\Spyware Terminator\SpywareTerminatorUpdate.exe (Crawler.com)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmi\File comuni\Java\Java Update\jusched.exe (Oracle Corporation)
O4 - HKLM..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKU\S-1-5-21-797491427-2050873350-1473301086-1005..\Run: [Facebook Update] C:\Documents and Settings\flora\Impostazioni locali\Dati applicazioni\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-797491427-2050873350-1473301086-1005..\Run: [TomTomHOME.exe] C:\Programmi\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKU\S-1-5-21-797491427-2050873350-1473301086-1005..\Run: [Xvid] C:\Programmi\Xvid\CheckUpdate.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\BTTray.lnk = C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\McAfee Security Scan Plus.lnk = C:\Programmi\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.)
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-797491427-2050873350-1473301086-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Invia a &Bluetooth - c:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm ()
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7EF3FC81-725A-4D36-B531-8D8D32A5EFF7}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Acer.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Acer.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/06 15.33.30 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2013/01/06 21.06.12 | 000,000,098 | ---- | M] () - D:\AUTORUN.INF -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 60 Days ========== [2013/11/15 23.15.40 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/11/15 21.03.30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\flora\Menu Avvio\Programmi\SpyHunter
[2013/11/15 21.03.10 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2013/11/15 21.03.10 | 000,000,000 | ---D | C] -- C:\Programmi\Enigma Software Group
[2013/11/15 21.01.47 | 000,000,000 | ---D | C] -- C:\Programmi\File comuni\Wise Installation Wizard
[2013/11/15 20.40.26 | 000,000,000 | ---D | C] -- C:\Programmi\Mozilla Firefox
[2013/11/15 20.16.48 | 000,000,000 | ---D | C] -- C:\Avenger
[2013/11/14 23.07.02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\flora\Menu Avvio\Programmi\HiJackThis
[2013/11/14 23.07.00 | 000,000,000 | ---D | C] -- C:\Programmi\Trend Micro
[2013/11/14 23.03.40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Spybot - Search & Destroy 2
[2013/11/14 23.03.00 | 000,018,968 | ---- | C] (Safer Networking Limited) -- C:\WINDOWS\System32\sdnclean.exe
[2013/11/14 23.02.48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
[2013/11/14 23.02.19 | 000,000,000 | ---D | C] -- C:\Programmi\Spybot - Search & Destroy 2
[2013/11/14 22.48.32 | 000,000,000 | ---D | C] -- C:\Programmi\Mozilla Maintenance Service
[2013/11/14 22.22.16 | 000,000,000 | ---D | C] -- C:\Programmi\Driver Mender
[2013/11/14 21.00.46 | 000,000,000 | -HSD | C] -- C:\FOUND.014
[2013/11/14 20.50.51 | 000,000,000 | ---D | C] -- C:\Programmi\BuzzSearch
[2013/11/13 18.03.49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\McAfee Security Scan Plus
[2013/11/13 16.00.00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Panda Cloud Antivirus
[2013/11/11 19.13.40 | 000,000,000 | -HSD | C] -- C:\FOUND.013
[2013/11/06 20.56.48 | 000,047,632 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSKMAD.sys
[2013/10/27 20.00.18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\TomTom
[2013/10/27 19.52.20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\flora\Documenti\TomTom
[2013/10/27 19.51.58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\flora\Impostazioni locali\Dati applicazioni\TomTom
[2013/10/27 19.51.58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\flora\Dati applicazioni\TomTom
[2013/10/27 19.45.38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\TomTom
[2013/10/27 19.45.08 | 000,000,000 | ---D | C] -- C:\Programmi\TomTom HOME 2
[2013/10/27 19.44.11 | 000,000,000 | ---D | C] -- C:\Programmi\TomTom International B.V
[2013/10/27 18.47.43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\flora\Documenti\Tom Tom
[2013/10/27 18.22.16 | 000,000,000 | -HSD | C] -- C:\FOUND.012
[2013/10/27 17.14.22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\flora\Impostazioni locali\Dati applicazioni\Downloaded Installations
[2013/10/27 17.01.55 | 000,000,000 | ---D | C] -- C:\Programmi\File comuni\Java
[2013/10/27 17.01.46 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013/10/27 17.01.46 | 000,145,408 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2013/10/27 17.01.34 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/10/27 17.01.34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Java
[2013/10/27 17.01.33 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013/10/27 17.01.33 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013/10/18 15.38.48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\flora\Impostazioni locali\Dati applicazioni\PCHealth
[2013/10/17 22.45.41 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013/10/17 20.31.22 | 000,145,640 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINAflt.sys
[2013/10/16 22.47.48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2013/10/16 22.47.41 | 000,000,000 | ---D | C] -- C:\Programmi\MSBuild
[2013/10/16 22.47.38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2013/10/16 22.47.29 | 000,000,000 | ---D | C] -- C:\Programmi\Reference Assemblies
[2013/10/16 22.46.42 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2013/10/16 22.46.42 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2013/10/16 22.46.41 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2013/10/16 22.46.41 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2013/10/16 22.46.41 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2013/10/16 22.46.41 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2013/10/16 22.45.14 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2013/10/16 22.44.30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2013/10/11 10.47.24 | 000,097,896 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINReg.sys
[2013/10/11 10.46.44 | 000,128,232 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINProt.sys
[2013/10/11 10.46.44 | 000,115,048 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINProc.sys
[2013/10/11 10.46.42 | 000,179,944 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINKNC.sys
[2013/10/11 10.46.42 | 000,103,528 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINFile.sys
[2013/10/09 19.52.51 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbd.sys
[2013/10/09 19.52.50 | 000,032,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/10/09 19.52.43 | 000,030,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbehci.sys
[2013/10/09 19.52.41 | 000,144,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbport.sys
[2013/10/08 22.51.28 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidparse.sys
[2013/10/08 22.50.40 | 000,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
[2013/10/08 22.50.35 | 000,123,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbvideo.sys
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 60 Days ========== [2013/11/16 00.23.20 | 000,001,128 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/11/15 23.53.02 | 000,000,412 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2013/11/15 23.50.38 | 000,000,412 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2013/11/15 23.47.48 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/11/15 23.40.44 | 000,000,636 | ---- | M] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/11/15 23.40.22 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2013/11/15 23.39.12 | 000,001,124 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/11/15 23.38.48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/11/15 23.38.40 | 1071,763,456 | -HS- | M] () -- C:\hiberfil.sys
[2013/11/15 23.34.24 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2013/11/15 21.03.34 | 000,001,855 | ---- | M] () -- C:\Documents and Settings\flora\Desktop\SpyHunter.lnk
[2013/11/15 20.55.02 | 000,000,988 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-797491427-2050873350-1473301086-1005Core1ce864323c7fb84.job
[2013/11/14 23.07.04 | 000,001,978 | ---- | M] () -- C:\Documents and Settings\flora\Desktop\HiJackThis.lnk
[2013/11/14 23.04.54 | 000,000,608 | ---- | M] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/11/14 23.04.54 | 000,000,438 | ---- | M] () -- C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/11/14 23.03.42 | 000,001,708 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk
[2013/11/14 22.49.16 | 000,000,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/11/13 21.19.44 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013/11/13 20.28.34 | 000,189,000 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/11/13 18.03.50 | 000,001,655 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/11/13 18.03.50 | 000,001,649 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\McAfee Security Scan Plus.lnk
[2013/11/11 15.45.52 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/10/27 17.01.16 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/10/27 17.01.08 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013/10/27 17.01.08 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013/10/27 17.01.06 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013/10/27 17.01.06 | 000,145,408 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2013/10/20 21.47.48 | 000,001,685 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/10/18 21.45.40 | 000,481,090 | ---- | M] () -- C:\WINDOWS\System32\perfh010.dat
[2013/10/18 21.45.40 | 000,434,454 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/10/18 21.45.40 | 000,080,850 | ---- | M] () -- C:\WINDOWS\System32\perfc010.dat
[2013/10/18 21.45.40 | 000,068,740 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/10/17 20.31.22 | 000,145,640 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINAflt.sys
[2013/10/13 12.28.02 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe
[2013/10/13 12.28.02 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2013/10/13 08.22.30 | 000,920,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
[2013/10/13 08.22.28 | 000,759,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vgx.dll
[2013/10/13 08.22.26 | 001,215,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
[2013/10/13 08.22.26 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
[2013/10/13 08.22.26 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
[2013/10/13 08.22.26 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
[2013/10/13 08.22.24 | 006,021,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/10/13 08.22.24 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll
[2013/10/13 08.22.24 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2013/10/13 08.22.24 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
[2013/10/13 08.22.16 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2013/10/13 08.22.16 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2013/10/13 08.22.16 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/10/13 08.22.16 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll
[2013/10/13 08.22.16 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2013/10/13 08.22.16 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\licmgr10.dll
[2013/10/13 08.22.16 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licmgr10.dll
[2013/10/13 08.22.16 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
[2013/10/13 08.22.16 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
[2013/10/13 08.22.14 | 002,006,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2013/10/13 08.22.14 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
[2013/10/13 08.22.14 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2013/10/13 08.22.12 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll
[2013/10/13 08.22.12 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
[2013/10/13 08.21.48 | 011,113,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2013/10/13 08.21.44 | 000,743,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2013/10/13 08.21.42 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
[2013/10/13 08.21.42 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2013/10/13 08.21.42 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\corpol.dll
[2013/10/13 08.21.42 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\corpol.dll
[2013/10/13 07.58.00 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec
[2013/10/12 16.56.08 | 000,279,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oakley.dll
[2013/10/11 10.47.24 | 000,097,896 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINReg.sys
[2013/10/11 10.46.44 | 000,128,232 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINProt.sys
[2013/10/11 10.46.44 | 000,115,048 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINProc.sys
[2013/10/11 10.46.42 | 000,179,944 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINKNC.sys
[2013/10/11 10.46.42 | 000,103,528 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSINFile.sys
[2013/10/09 19.56.10 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/10/09 19.56.10 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/10/09 14.12.42 | 000,287,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gdi32.dll
[2013/10/07 11.59.16 | 000,607,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[2013/10/04 19.43.10 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/09/21 06.21.10 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\jvdii.sys
[2013/09/20 10.49.30 | 000,018,968 | ---- | M] (Safer Networking Limited) -- C:\WINDOWS\System32\sdnclean.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2013/11/15 21.03.32 | 000,001,855 | ---- | C] () -- C:\Documents and Settings\flora\Desktop\SpyHunter.lnk
[2013/11/14 23.07.03 | 000,001,978 | ---- | C] () -- C:\Documents and Settings\flora\Desktop\HiJackThis.lnk
[2013/11/14 23.04.50 | 000,000,438 | ---- | C] () -- C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/11/14 23.04.49 | 000,000,608 | ---- | C] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/11/14 23.04.48 | 000,000,636 | ---- | C] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/11/14 23.03.41 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Spybot-S&D Start Center.lnk
[2013/11/14 23.03.41 | 000,001,708 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk
[2013/11/14 22.49.13 | 000,000,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/11/14 22.49.08 | 000,000,610 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Mozilla Firefox.lnk
[2013/11/14 20.53.09 | 000,000,412 | ---- | C] () -- C:\WINDOWS\tasks\At2.job
[2013/11/14 20.50.54 | 000,000,412 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2013/11/13 18.03.49 | 000,001,655 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/10/16 19.48.42 | 000,001,649 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\McAfee Security Scan Plus.lnk
[2013/09/21 06.21.08 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\jvdii.sys
[2013/05/12 21.31.33 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2013/04/07 16.17.09 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2013/01/11 19.33.27 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/01/08 22.50.25 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2013/01/08 21.11.52 | 000,109,256 | ---- | C] () -- C:\WINDOWS\System32\EasyHook64.dll
[2013/01/08 21.11.52 | 000,090,824 | ---- | C] () -- C:\WINDOWS\System32\EasyHook32.dll
[2012/12/02 22.46.36 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dati applicazioni\0x0304A000.sfl
[2012/09/16 18.36.22 | 000,000,424 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/09/11 19.03.22 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/09/09 20.44.08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\flora\ipconfig
[2012/09/07 21.52.11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\eRLog.ini
[2012/09/07 21.42.28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2012/08/21 04.15.22 | 003,978,240 | ---- | C] () -- C:\WINDOWS\System32\ffmpeg.dll
[2012/08/21 04.14.04 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2012/08/21 04.12.48 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2012/08/21 04.12.34 | 000,099,840 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2012/08/21 04.12.32 | 000,157,184 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2012/08/21 04.12.30 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2012/08/21 04.12.28 | 001,525,760 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2012/08/21 04.12.28 | 000,211,968 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2012/08/21 04.12.28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2012/08/21 04.12.24 | 000,330,240 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2012/07/19 19.56.08 | 000,172,544 | ---- | C] () -- C:\WINDOWS\System32\libbluray.dll
[2012/07/19 19.56.02 | 006,894,331 | ---- | C] () -- C:\WINDOWS\System32\avcodec-lav-54.dll
[2012/07/19 19.56.02 | 001,111,581 | ---- | C] () -- C:\WINDOWS\System32\avformat-lav-54.dll
[2012/07/19 19.56.02 | 000,401,685 | ---- | C] () -- C:\WINDOWS\System32\swscale-lav-2.dll
[2012/07/19 19.56.02 | 000,232,895 | ---- | C] () -- C:\WINDOWS\System32\avutil-lav-51.dll
[2012/07/19 19.56.02 | 000,162,743 | ---- | C] () -- C:\WINDOWS\System32\avfilter-lav-3.dll
[2012/07/19 19.56.02 | 000,101,820 | ---- | C] () -- C:\WINDOWS\System32\avresample-lav-0.dll
[2012/06/22 11.01.32 | 000,019,984 | ---- | C] () -- C:\WINDOWS\System32\ESGScanner.sys
[2012/06/22 11.01.32 | 000,019,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\EsgScanner.sys
[2012/06/17 22.15.04 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\spdif_test.exe
[2012/06/17 22.14.58 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\ac3config.exe
[2012/06/17 22.14.42 | 001,021,440 | ---- | C] () -- C:\WINDOWS\System32\ac3filter_intl.dll
[2012/05/12 23.42.16 | 001,272,320 | ---- | C] () -- C:\WINDOWS\System32\avcodec-53.dll
[2012/05/12 23.42.16 | 000,146,432 | ---- | C] () -- C:\WINDOWS\System32\avutil-51.dll
[2011/12/07 20.32.24 | 000,216,064 | ---- | C] ( ) -- C:\WINDOWS\System32\Lagarith.dll
========== ZeroAccess Check ========== [2013/10/16 22.45.16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2012/06/28 23.33.18 | 001,510,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 12.51.44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 19.13.58 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2012/09/08 22.13.54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Panda Security
[2012/09/08 22.19.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\TEMP
[2013/01/08 21.11.46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\SpeedBit
[2013/02/02 09.05.48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\FUJIFILM
[2013/05/12 21.31.32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Spyware Terminator
[2013/05/12 21.40.26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Licenses
[2013/10/27 20.00.20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\TomTom
[2012/09/08 22.23.34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\flora\Dati applicazioni\Panda Security
[2012/12/22 20.02.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\flora\Dati applicazioni\PhotoFiltre 7
[2013/01/08 20.47.32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\flora\Dati applicazioni\uTorrent
[2013/01/29 19.48.08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\flora\Dati applicazioni\PhotoScape
[2013/04/07 16.20.02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\flora\Dati applicazioni\Leadertech
[2013/05/12 21.31.32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\flora\Dati applicazioni\Spyware Terminator
[2013/10/27 19.52.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\flora\Dati applicazioni\TomTom
========== Purity Check ========== < End of report >