OTL logfile created on: 27/09/2012 15.13.08 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\Documents and Settings\USER\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,39 Gb Available Physical Memory | 69,63% Memory free
3,35 Gb Paging File | 2,93 Gb Available in Paging File | 87,29% Paging File free
Paging file location(s): F:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Programmi
Drive C: | 149,05 Gb Total Space | 78,90 Gb Free Space | 52,93% Space Free | Partition Type: NTFS
Drive E: | 1,87 Gb Total Space | 1,82 Gb Free Space | 97,05% Space Free | Partition Type: FAT32
Drive F: | 149,04 Gb Total Space | 71,63 Gb Free Space | 48,06% Space Free | Partition Type: NTFS
Computer Name: UTENTE-8F489A77 | User Name: USER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/09/27 15.01.54 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\USER\desktop\OTL.exe
PRC - [2012/08/25 22.27.58 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) -- F:\Programmi\Sandboxie\SbieSvc.exe
PRC - [2012/05/15 12.18.00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- F:\Programmi\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/03/11 23.13.21 | 001,983,232 | ---- | M] (COMODO) -- F:\Programmi\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011/09/20 09.30.41 | 000,269,480 | ---- | M] (Avira GmbH) -- F:\Programmi\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/09/19 15.45.48 | 000,136,360 | ---- | M] (Avira GmbH) -- F:\Programmi\Avira\AntiVir Desktop\sched.exe
PRC - [2011/03/04 14.39.09 | 000,281,768 | ---- | M] (Avira GmbH) -- F:\Programmi\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/01/14 21.11.21 | 000,076,968 | ---- | M] (Avira GmbH) -- F:\Programmi\Avira\AntiVir Desktop\avshadow.exe
PRC - [2007/06/13 15.22.28 | 001,035,776 | ---- | M] (Microsoft Corporation) -- F:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== MOD - [2012/07/27 22.51.42 | 000,301,056 | ---- | M] () -- F:\Programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA
MOD - [2012/05/15 12.18.00 | 000,357,184 | ---- | M] () -- F:\Programmi\NVIDIA Corporation\nview\nvShell.dll
MOD - [2011/07/20 16.40.27 | 000,355,688 | ---- | M] () -- F:\Programmi\Avira\AntiVir Desktop\sqlite3.dll
========== Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2012/09/01 13.52.18 | 000,161,768 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- F:\Programmi\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/08/25 22.27.58 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- F:\Programmi\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2012/07/03 13.46.44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- F:\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/06/07 19.12.14 | 000,160,944 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- F:\Programmi\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/05/15 12.18.00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- F:\Programmi\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/04/22 13.51.04 | 000,720,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- F:\Programmi\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012/04/15 01.05.30 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- F:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/11 23.39.56 | 000,175,632 | ---- | M] (Nitro PDF Software) [Disabled | Stopped] -- F:\Programmi\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe -- (NitroReaderDriverReadSpool2)
SRV - [2012/03/11 23.13.21 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- F:\Programmi\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011/09/20 09.30.41 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- F:\Programmi\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/09/19 15.45.48 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- F:\Programmi\Avira\AntiVir Desktop\sched.exe -- (AntiVirScheduler)
SRV - [2007/05/16 09.27.28 | 000,271,920 | ---- | M] (Nero AG) [Disabled | Stopped] -- F:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2005/10/18 15.00.10 | 000,241,152 | ---- | M] (ASUSTeK COMPUTER INC.) [Disabled | Stopped] -- F:\WINDOWS\ATKKBService.exe -- (ATKKeyboardService)
SRV - [2005/04/04 01.41.10 | 000,069,632 | ---- | M] (Macrovision Corporation) [Disabled | Stopped] -- F:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004/05/24 13.35.52 | 000,322,104 | ---- | M] (Eastman Kodak Company) [Disabled | Stopped] -- F:\WINDOWS\system32\drivers\KodakCCS.exe -- (KodakCCS)
SRV - [2003/07/28 20.28.22 | 000,089,136 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- F:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2001/08/09 03.01.00 | 000,090,112 | ---- | M] (SEIKO EPSON CORPORATION) [Disabled | Stopped] -- F:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe -- (EPSONStatusAgent2)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | Disabled | Stopped] -- F:\Programmi\Internet Explorer\SABProcEnum.sys -- (SABProcEnum)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\drivers\npf.sys -- (NPF)
DRV - [2012/08/25 22.27.54 | 000,157,776 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- F:\Programmi\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2012/07/03 13.46.44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/04/22 13.51.38 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2012/03/11 23.13.46 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- F:\WINDOWS\system32\drivers\inspect.sys -- (Inspect)
DRV - [2012/03/11 23.13.45 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2012/03/11 23.13.44 | 000,494,968 | ---- | M] (COMODO) [File_System | System | Running] -- F:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2012/01/09 17.28.20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2012/01/09 17.28.20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2012/01/09 17.28.20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2012/01/09 17.28.20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/09/20 09.30.44 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/09/20 09.30.44 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- F:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011/05/03 16.33.46 | 006,404,712 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2010/09/04 00.24.40 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/06/17 14.28.21 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/17 14.28.11 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- F:\Programmi\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/11/18 07.17.00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/18 07.16.00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/10/19 10.55.40 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- F:\Programmi\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2009/10/19 10.55.40 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- F:\Programmi\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2005/10/21 03.47.05 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2005/10/20 16.30.00 | 000,011,264 | R--- | M] (ASUSTeK Computer Inc.) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\EIO.sys -- (EIO)
DRV - [2005/10/18 15.01.38 | 000,011,008 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\atkkbnt.sys -- (asuskbnt)
DRV - [2004/11/22 18.36.40 | 000,018,003 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- F:\Programmi\Common Files\Motive\MRENDIS5.sys -- (MRENDIS5)
DRV - [2004/11/22 18.36.34 | 000,019,345 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- F:\Programmi\Common Files\Motive\MREMPR5.sys -- (MREMPR5)
DRV - [2004/08/04 01.08.22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2004/07/07 11.27.28 | 000,070,070 | ---- | M] (Eastman Kodak Company) [Kernel | Disabled | Stopped] -- F:\WINDOWS\system32\drivers\DcPtp.sys -- (DcPTP)
DRV - [2004/07/07 09.55.12 | 000,152,049 | ---- | M] (Eastman Kodak Company) [Kernel | Disabled | Stopped] -- F:\WINDOWS\system32\drivers\ExportIt.sys -- (Exportit)
DRV - [2004/06/02 14.19.00 | 000,038,705 | ---- | M] (Eastman Kodak Company) [Kernel | Disabled | Stopped] -- F:\WINDOWS\system32\drivers\DCFS2k.sys -- (DCFS2K)
DRV - [2004/05/20 09.41.54 | 000,061,564 | ---- | M] (Eastman Kodak Company) [Kernel | Disabled | Stopped] -- F:\WINDOWS\system32\drivers\DcFpoint.sys -- (DcFpoint)
DRV - [2004/05/20 09.39.42 | 000,008,022 | ---- | M] (Eastman Kodak Company) [Kernel | Disabled | Stopped] -- F:\WINDOWS\system32\drivers\DcLps.sys -- (DcLps)
DRV - [2004/05/20 09.21.10 | 000,036,918 | ---- | M] (Eastman Kodak Company) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\DcCam.sys -- (DcCam)
DRV - [2001/08/18 00.00.04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2001/08/17 23.51.32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\irsir.sys -- (irsir)
DRV - [1999/09/10 14.06.00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\aspi32.sys -- (Aspi32)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1390067357-261478967-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://g.msn.com/0SEENUS/SAOS01IE - HKU\S-1-5-21-1390067357-261478967-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-1390067357-261478967-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/IE - HKU\S-1-5-21-1390067357-261478967-839522115-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1390067357-261478967-839522115-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MOOI_it
IE - HKU\S-1-5-21-1390067357-261478967-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: F:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: F:\Programmi\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: F:\Programmi\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: F:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: F:\Programmi\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: F:\Programmi\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: F:\Programmi\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: F:\Programmi\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: F:\Programmi\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: F:\Programmi\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: F:\Programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: F:\Programmi\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: F:\Programmi\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.13\npGoogleOneClick8.dll (Google Inc.)
========== Chrome ========== CHR - homepage:
http://www.google.it/CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.it/CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Enabled) = F:\Programmi\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = F:\Programmi\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = F:\Programmi\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = F:\Programmi\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = F:\Programmi\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = F:\Programmi\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.13\npGoogleOneClick8.dll
CHR - plugin: Motive Plugin (Enabled) = F:\Programmi\Common Files\Motive\npMotive.dll
CHR - plugin: Picasa (Enabled) = F:\Programmi\Google\Picasa3\npPicasa3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = F:\Programmi\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = F:\Programmi\Microsoft\Office Live\npOLW.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = F:\Programmi\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = F:\Programmi\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: VLC Web Plugin (Enabled) = F:\Programmi\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = F:\Programmi\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = F:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Ricerca Google = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Disattivazione permanente degli annunci personalizzati = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\hhnjdplhmcnkiecampfdgfjilccfpfoe\1.0.14_0\
CHR - Extension: Skype Click to Call = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
CHR - Extension: MVideoDownload = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pbgdpjejogccpfbncoehmfidcpmcafkj\1.0_0\
CHR - Extension: Gmail = F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/09/17 13.13.29 | 000,444,049 | R--- | M]) - F:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1
www.007guard.comO1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
www.008k.comO1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
www.00hq.comO1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.comO1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.0scan.comO1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
www.1000gratisproben.comO1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1
www.1001namen.comO1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100888290cs.comO1 - Hosts: 127.0.0.1
www.100sexlinks.comO1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.10sek.comO1 - Hosts: 127.0.0.1
www.1-2005-search.comO1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15253 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - Reg Error: Value error. File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Programmi\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Programmi\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKU\S-1-5-21-1390067357-261478967-839522115-1003\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Programmi\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [avgnt] F:\Programmi\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [COMODO Internet Security] F:\Programmi\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKU\S-1-5-21-1390067357-261478967-839522115-1003..\Run: [H/PC Connection Agent] "F:\Programmi\Microsoft ActiveSync\wcescomm.exe" File not found
O4 - HKU\S-1-5-21-1390067357-261478967-839522115-1009..\RunOnce: [NeroHomeFirstStart] F:\Programmi\File comuni\Ahead\Lib\NMFirstStart.exe (Nero AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1390067357-261478967-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1390067357-261478967-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-1390067357-261478967-839522115-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Search - ?p=ZUxdm266YYIT File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - F:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki... -
res://F:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll File not found
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71}
http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Value error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/ ... vc1dmo.cab (Reg Error: Value error.)
O16 - DPF: {63BAECA2-9E3C-45DE-B2B1-BBC5FA99958E}
http://aiuto.alice.it/ata/static/instal ... _4-1-5.cab (MCCWrapperObj Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/200 ... ader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Reg Error: Value error.)
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F}
http://aiuto.alice.it/ata/static/instal ... er_6.6.cab (McciSM Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_05)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O16 - DPF: Microsoft XML Parser for Java file:///F:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B5E59204-0126-4928-98EB-D7ACCCADD8AF}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Programmi\File comuni\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\AutorunsDisabled\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - F:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - F:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - F:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - F:\Programmi\File comuni\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - F:\Programmi\File comuni\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - F:\Programmi\File comuni\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Programmi\File comuni\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - F:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (F:\WINDOWS\system32\guard32.dll) - F:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - F:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop Components:0 () -
O24 - Desktop Components:1 () -
O24 - Desktop WallPaper: F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Value error. File not found
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2001/11/11 08.07.18 | 000,000,112 | ---- | M] () - C:\Autoplay.ply -- [ NTFS ]
O32 - AutoRun File - [2012/04/21 16.44.24 | 002,080,944 | ---- | M] () - C:\AutoRuns.arn -- [ NTFS ]
O32 - AutoRun File - [2012/09/27 13.39.56 | 000,000,127 | RHS- | M] () - E:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{5cb897a4-5bae-11e0-a1a9-00138fed3c54}\Shell - "" = AutoRun
O33 - MountPoints2\{5cb897a4-5bae-11e0-a1a9-00138fed3c54}\Shell\AutoRun\command - "" = E:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{6522fe4c-3551-11dc-bb2b-937a4b28ff4b}\Shell\AutoRun\command - "" = pkkwng.exe
O33 - MountPoints2\{6522fe4c-3551-11dc-bb2b-937a4b28ff4b}\Shell\open\Command - "" = pkkwng.exe
O33 - MountPoints2\{924971b2-864b-11dd-a3b0-00138fed3c54}\Shell\AutoRun\command - "" = F:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
O33 - MountPoints2\{ccfaff54-5d50-11dd-addf-00138fed3c54}\Shell\AutoRun\command - "" = F:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
O33 - MountPoints2\{ccfaff54-5d50-11dd-addf-00138fed3c54}\Shell\Open(&0)\command - "" = Recycled\ctfmon.exe
O33 - MountPoints2\{ce578e31-5643-11dd-a57d-00138fed3c54}\Shell\AutoRun\command - "" = F:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
O33 - MountPoints2\{e8793c6b-c810-11e0-a29b-00138fed3c54}\Shell\AutoRun\command - "" = E:\driver\usb\usb3.EXE -- [2010/02/09 16.41.16 | 000,106,496 | RHS- | M] ()
O33 - MountPoints2\{e8793c6b-c810-11e0-a29b-00138fed3c54}\Shell\open\command - "" = E:\driver\usb\usb3.EXE -- [2010/02/09 16.41.16 | 000,106,496 | RHS- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/09/27 15.07.20 | 002,212,440 | ---- | C] (Kaspersky Lab ZAO) -- F:\Documents and Settings\USER\Desktop\tdsskiller.exe
[2012/09/27 15.07.20 | 000,602,112 | ---- | C] (OldTimer Tools) -- F:\Documents and Settings\USER\Desktop\OTL.exe
[2012/09/27 14.22.52 | 000,000,000 | -HSD | C] -- F:\RECYCLER
[2012/09/27 12.48.25 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Dati applicazioni\SUPERSetup
[2012/09/27 12.44.54 | 000,000,000 | ---D | C] -- F:\ComboFix
[2012/09/27 12.40.19 | 000,000,000 | ---D | C] -- F:\Qoobox
[2012/09/27 12.39.30 | 000,000,000 | ---D | C] -- F:\WINDOWS\erdnt
[2012/09/27 12.39.15 | 000,000,000 | --SD | C] -- F:\32788R22FWJFW
[2012/09/27 09.26.24 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- F:\Documents and Settings\USER\Desktop\mbam-setup-1.65.0.1400.exe
[2012/09/27 09.26.23 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- F:\Documents and Settings\USER\Desktop\HijackThis.exe
[2012/09/27 09.26.22 | 004,769,305 | R--- | C] (Swearware) -- F:\Documents and Settings\USER\Desktop\ComboFix.exe
[2012/09/27 00.33.54 | 000,000,000 | ---D | C] -- F:\WINDOWS\S82P64REYYLLKK4E
[2012/09/26 21.36.03 | 000,000,000 | -H-D | C] -- F:\VritualRoot
[2012/09/26 21.36.03 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Dati applicazioni\COMODO
[2012/09/10 19.59.17 | 000,000,000 | -HSD | C] -- F:\Config.Msi
[2012/09/01 16.11.55 | 000,000,000 | ---D | C] -- F:\Documents and Settings\USER\Dati applicazioni\NVIDIA
[2012/09/01 15.58.16 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Menu Avvio\Programmi\VideoLAN
[2012/09/01 15.47.00 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Dati applicazioni\NVIDIA
[2012/09/01 15.45.11 | 000,065,536 | ---- | C] (Khronos Group) -- F:\WINDOWS\System32\OpenCL.dll
[2012/09/01 15.43.48 | 000,000,000 | ---D | C] -- F:\Programmi\NVIDIA Corporation
[2012/09/01 15.42.52 | 000,000,000 | ---D | C] -- F:\NVIDIA
[2012/09/01 13.53.09 | 000,000,000 | ---D | C] -- F:\Programmi\File comuni\Java
[2012/08/31 15.58.49 | 000,000,000 | ---D | C] -- F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\Wajam
[2012/08/31 15.30.38 | 000,000,000 | ---D | C] -- F:\Documents and Settings\USER\Dati applicazioni\ProgSense
[2012/08/31 15.30.38 | 000,000,000 | ---D | C] -- F:\Downloads
[2012/08/31 15.30.26 | 000,000,000 | ---D | C] -- F:\Documents and Settings\USER\Dati applicazioni\Orbit
[2009/11/19 22.25.55 | 000,047,360 | ---- | C] (VSO Software) -- F:\Documents and Settings\USER\Dati applicazioni\pcouffin.sys
[2004/07/09 05.27.28 | 000,958,464 | ---- | C] (Microsoft Corporation) -- F:\Documents and Settings\USER\dxdiag.exe
[8 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[54 F:\Documents and Settings\USER\Desktop\*.tmp files -> F:\Documents and Settings\USER\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/09/27 15.05.24 | 000,002,048 | --S- | M] () -- F:\WINDOWS\bootstat.dat
[2012/09/27 15.01.54 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\USER\Desktop\OTL.exe
[2012/09/27 15.00.18 | 002,212,440 | ---- | M] (Kaspersky Lab ZAO) -- F:\Documents and Settings\USER\Desktop\tdsskiller.exe
[2012/09/27 09.23.06 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- F:\Documents and Settings\USER\Desktop\HijackThis.exe
[2012/09/27 09.16.36 | 076,872,943 | ---- | M] () -- F:\Documents and Settings\USER\Desktop\vdf_fusebundle.zip
[2012/09/27 09.14.22 | 004,769,305 | R--- | M] (Swearware) -- F:\Documents and Settings\USER\Desktop\ComboFix.exe
[2012/09/27 09.09.38 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- F:\Documents and Settings\USER\Desktop\mbam-setup-1.65.0.1400.exe
[2012/09/27 09.06.52 | 094,820,904 | ---- | M] () -- F:\Documents and Settings\USER\Desktop\avira_free_antivirus_it_12.0.0.330.exe
[2012/09/26 21.13.40 | 001,074,636 | ---- | M] () -- F:\WINDOWS\System32\nvdrsdb0.bin
[2012/09/26 21.13.40 | 000,000,001 | ---- | M] () -- F:\WINDOWS\System32\nvdrssel.bin
[2012/09/26 11.37.07 | 000,002,206 | ---- | M] () -- F:\WINDOWS\System32\wpa.dbl
[2012/09/24 11.52.10 | 000,000,074 | ---- | M] () -- F:\Documents and Settings\USER\default.pls
[2012/09/17 13.13.29 | 000,444,049 | R--- | M] () -- F:\WINDOWS\System32\drivers\etc\hosts
[2012/09/10 19.20.02 | 000,002,528 | ---- | M] () -- F:\Documents and Settings\USER\Dati applicazioni\$_hpcst$.hpc
[2012/09/10 19.16.06 | 000,482,458 | ---- | M] () -- F:\WINDOWS\System32\perfh010.dat
[2012/09/10 19.16.06 | 000,434,838 | ---- | M] () -- F:\WINDOWS\System32\perfh009.dat
[2012/09/10 19.16.06 | 000,081,240 | ---- | M] () -- F:\WINDOWS\System32\perfc010.dat
[2012/09/10 19.16.06 | 000,068,828 | ---- | M] () -- F:\WINDOWS\System32\perfc009.dat
[2012/09/10 19.13.54 | 000,001,374 | ---- | M] () -- F:\WINDOWS\imsins.BAK
[2012/09/08 20.48.05 | 000,000,069 | ---- | M] () -- F:\WINDOWS\NeroDigital.ini
[2012/09/05 01.58.17 | 000,001,928 | ---- | M] () -- F:\WINDOWS\Sandboxie.ini
[2012/09/01 15.53.51 | 001,074,636 | ---- | M] () -- F:\WINDOWS\System32\nvdrsdb1.bin
[2012/09/01 15.44.58 | 000,000,000 | ---- | M] () -- F:\WINDOWS\System32\nvdrswr.lk
[2012/08/31 13.15.54 | 000,000,302 | ---- | M] () -- F:\WINDOWS\tasks\GlaryInitialize.job
[8 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[54 F:\Documents and Settings\USER\Desktop\*.tmp files -> F:\Documents and Settings\USER\Desktop\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/09/27 09.26.26 | 076,872,943 | ---- | C] () -- F:\Documents and Settings\USER\Desktop\vdf_fusebundle.zip
[2012/09/27 09.26.07 | 094,820,904 | ---- | C] () -- F:\Documents and Settings\USER\Desktop\avira_free_antivirus_it_12.0.0.330.exe
[2012/09/10 19.20.02 | 000,002,528 | ---- | C] () -- F:\Documents and Settings\USER\Dati applicazioni\$_hpcst$.hpc
[2012/09/01 15.44.59 | 001,074,636 | ---- | C] () -- F:\WINDOWS\System32\nvdrsdb0.bin
[2012/09/01 15.44.58 | 001,074,636 | ---- | C] () -- F:\WINDOWS\System32\nvdrsdb1.bin
[2012/09/01 15.44.58 | 000,000,001 | ---- | C] () -- F:\WINDOWS\System32\nvdrssel.bin
[2012/09/01 15.44.58 | 000,000,000 | ---- | C] () -- F:\WINDOWS\System32\nvdrswr.lk
[2012/09/01 15.44.38 | 002,807,708 | ---- | C] () -- F:\WINDOWS\System32\nvdata.data
[2012/09/01 15.44.38 | 000,010,264 | ---- | C] () -- F:\WINDOWS\System32\nvinfo.pb
[2012/08/31 13.03.44 | 000,001,374 | ---- | C] () -- F:\WINDOWS\imsins.BAK
[2011/06/27 18.35.18 | 000,000,218 | ---- | C] () -- F:\Documents and Settings\USER\.recently-used.xbel
[2011/06/27 17.35.33 | 000,000,000 | ---- | C] () -- F:\Documents and Settings\USER\.gtk-bookmarks
[2011/02/11 00.10.34 | 000,000,000 | ---- | C] () -- F:\WINDOWS\EEventManager.INI
[2010/12/27 22.35.39 | 000,147,744 | ---- | C] () -- F:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
[2010/10/23 00.32.58 | 000,001,928 | ---- | C] () -- F:\WINDOWS\Sandboxie.ini
[2009/11/19 22.26.33 | 000,001,041 | ---- | C] () -- F:\Documents and Settings\USER\Dati applicazioni\vso_ts_preview.xml
[2009/11/19 22.25.55 | 000,087,608 | ---- | C] () -- F:\Documents and Settings\USER\Dati applicazioni\inst.exe
[2009/11/19 22.25.55 | 000,007,887 | ---- | C] () -- F:\Documents and Settings\USER\Dati applicazioni\pcouffin.cat
[2009/11/19 22.25.55 | 000,001,144 | ---- | C] () -- F:\Documents and Settings\USER\Dati applicazioni\pcouffin.inf
[2009/02/28 14.16.04 | 000,004,382 | ---- | C] () -- F:\Documents and Settings\USER\updater.html
[2008/10/09 17.41.40 | 000,000,000 | ---- | C] () -- F:\Documents and Settings\All Users\Dati applicazioni\LauncherAccess.dt
[2008/02/14 18.25.34 | 008,683,520 | ---- | C] () -- F:\Documents and Settings\USER\s-1-5-21-1390067357-261478967-839522115-1003.rrr
[2007/02/26 00.58.25 | 000,000,074 | ---- | C] () -- F:\Documents and Settings\USER\default.pls
[2007/01/25 13.12.40 | 000,000,133 | ---- | C] () -- F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\fusioncache.dat
[2007/01/25 12.53.10 | 000,138,752 | ---- | C] () -- F:\Documents and Settings\USER\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ========== [2007/01/25 13.06.14 | 000,000,227 | RHS- | M] () -- F:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2007/08/22 15.12.14 | 001,495,040 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = F:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 12.18.59 | 000,473,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = F:\WINDOWS\system32\wbem\wbemess.dll -- [2004/08/19 15.39.30 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2010/05/15 18.25.50 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\EPSON
[2011/06/25 14.19.15 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\Installations
[2012/05/29 23.12.22 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\Nitro PDF
[2012/06/12 11.02.58 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\Nokia
[2012/03/12 21.53.47 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\NokiaInstallerCache
[2010/12/27 21.45.44 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\NokiaMusic
[2012/05/14 22.18.24 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\PC Suite
[2010/05/09 11.20.30 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\SecTaskMan
[2012/09/27 12.48.25 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\SUPERSetup
[2009/11/19 22.31.26 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\vsosdk
[2011/08/06 14.59.04 | 000,000,000 | -H-D | M] -- F:\Documents and Settings\All Users\Dati applicazioni\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}
[2007/06/03 11.16.42 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Anvil Studio
[2011/10/15 15.20.47 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Auslogics
[2012/05/29 23.11.28 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Downloaded Installations
[2009/12/31 18.35.35 | 000,000,000 | -H-D | M] -- F:\Documents and Settings\USER\Dati applicazioni\drivers
[2012/05/02 21.09.24 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\EPSON
[2009/11/19 22.25.09 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\GetRightToGo
[2012/08/18 20.04.25 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\GlarySoft
[2011/06/27 18.01.04 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\gtk-2.0
[2012/02/09 17.30.06 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\it.vodafone.desktopwidget
[2011/11/12 17.03.57 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1
[2012/09/10 10.35.35 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Nitro PDF
[2012/06/12 11.10.19 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Nokia
[2010/12/27 16.23.24 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Nokia Ovi Suite
[2011/11/12 16.45.19 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Nokia Suite
[2012/06/17 16.53.14 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Oracle
[2012/08/31 15.56.15 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Orbit
[2010/12/26 01.40.03 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\PC Suite
[2012/08/31 15.30.38 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\ProgSense
[2008/12/24 14.24.50 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Software Informer
[2012/09/01 18.27.49 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\uTorrent
[2011/03/21 17.44.54 | 000,000,000 | ---D | M] -- F:\Documents and Settings\USER\Dati applicazioni\Windows Live Writer
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 3875 bytes -> F:\WINDOWS\NFS: Carbon (testo) Setup Log.txt
< End of report >