OTL logfile created on: 03/12/2013 9.43.50 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\GIOVANNI\Desktop\software pc
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
1,87 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 53,20% Memory free
3,72 Gb Paging File | 2,82 Gb Available in Paging File | 75,87% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 465,75 Gb Total Space | 432,99 Gb Free Space | 92,97% Space Free | Partition Type: NTFS
Drive F: | 111,79 Gb Total Space | 75,52 Gb Free Space | 67,55% Space Free | Partition Type: NTFS
Computer Name: GIOVANNI-0DB10D | User Name: GIOVANNI | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\GIOVANNI\Desktop\software pc\OTL.exe (OldTimer Tools)
PRC - C:\Programmi\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programmi\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programmi\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programmi\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programmi\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programmi\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programmi\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Programmi\EDIMAX\Common\RaUI.exe (Edimax Technology Co., Ltd)
PRC - C:\WINDOWS\system32\PAStiSvc.exe ()
========== Modules (No Company Name) ========== MOD - C:\Programmi\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
MOD - C:\Programmi\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Programmi\WinRAR\RarExt.dll ()
MOD - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\pdfshell.ITA ()
MOD - C:\Programmi\Canon\IJPLM\ijplmsvc.exe ()
MOD - C:\Programmi\EDIMAX\Common\acAuth.dll ()
MOD - C:\WINDOWS\system32\PAStiSvc.exe ()
========== Services (SafeList) ========== SRV - (SoftwareUpd) -- C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\SoftwareUpdater\SoftwareUpdService.exe File not found
SRV - (AppMgmt) -- %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AntiVirSchedulerService) -- C:\Programmi\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programmi\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MozillaMaintenance) -- C:\Programmi\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) -- C:\Programmi\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MBAMService) -- C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) -- C:\Programmi\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (PowerOffer Service) -- C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\ServUpdater\ServiceUpd.exe (ServiceUpd)
SRV - (IJPLMSVC) -- C:\Programmi\Canon\IJPLM\ijplmsvc.exe ()
SRV - (MSCSPTISRV) -- C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) -- C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) -- C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (SSScsiSV) -- C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (IDriverT) -- C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (STI Simulator) -- C:\WINDOWS\system32\PAStiSvc.exe ()
========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found
DRV - (USBAAPL) -- System32\Drivers\usbaapl.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (FXDrv32) -- D:\FXDrv32.sys File not found
DRV - (FoxAwdWINFLASH) -- C:\PROGRA~1\Foxconn\FOXDMI~1\FoxAwdWINFLASH.sys File not found
DRV - (Changer) -- File not found
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\WINDOWS\system32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (ssudmdm) -- C:\WINDOWS\system32\drivers\ssudmdm.sys (DEVGURU Co., LTD.(
www.devguru.co.kr))DRV - (dg_ssudbus) -- C:\WINDOWS\system32\drivers\ssudbus.sys (DEVGURU Co., LTD.(
www.devguru.co.kr))DRV - (IntcAzAudAddService) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (L1c) -- C:\WINDOWS\system32\drivers\l1c51x86.sys (Atheros Communications, Inc.)
DRV - (qcusbser) -- C:\WINDOWS\system32\drivers\qcusbser.sys (QUALCOMM Incorporated)
DRV - (RT73) -- C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (PAC207) -- C:\WINDOWS\system32\drivers\PFC027.sys ()
DRV - (ACSSCR) -- C:\WINDOWS\system32\drivers\a38usbxp.sys (Advanced Card Systems Ltd)
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Sentinel) -- C:\WINDOWS\system32\drivers\SENTINEL.SYS ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.comIE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.comIE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.comIE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.comIE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-220523388-1425521274-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\S-1-5-21-220523388-1425521274-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-220523388-1425521274-725345543-1004\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-220523388-1425521274-725345543-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-220523388-1425521274-725345543-1004\..\SearchScopes\{7FD8A53D-3A2A-43BD-A9A3-3C0D70AD4466}: "URL" =
http://websearch.ask.com/redirect?clien ... src=crm&q={searchTerms}&locale=it_IT&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^IT&apn_uid=4AD2729E-B2C0-429D-98FE-0BBCE55DE699&apn_sauid=4D0AC248-E88F-438A-BA4E-BF76BE2FD974
IE - HKU\S-1-5-21-220523388-1425521274-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.useDBForOrder: "false"
FF - prefs.js..extensions.enabledAddons: %7B0b457cAA-602d-484a-8fe7-c1d894a011ba%7D:0.98.47
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Programmi\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programmi\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Programmi\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programmi\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.4: C:\Programmi\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Programmi\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: C:\Programmi\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Programmi\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programmi\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programmi\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/09 08.00.24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0.1\extensions\\Components: C:\Programmi\Mozilla Firefox\components [2013/11/06 09.56.47 | 000,000,000 | ---D | M]
[2011/04/11 18.02.11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Mozilla\Extensions
[2013/11/29 15.12.40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Mozilla\Firefox\Profiles\wvuzut3m.default-1351319440000\extensions
[2013/11/27 14.42.13 | 000,000,000 | ---D | M] (FireShot) -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Mozilla\Firefox\Profiles\wvuzut3m.default-1351319440000\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2013/11/06 09.56.47 | 000,000,000 | ---D | M] (No name found) -- C:\Programmi\Mozilla Firefox\extensions
[2013/11/06 09.56.48 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Programmi\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/11/19 19.56.38 | 000,000,000 | ---D | M] (No name found) -- C:\Programmi\Mozilla Firefox\browser\extensions
[2013/11/19 19.56.38 | 000,000,000 | ---D | M] (Default) -- C:\Programmi\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ========== CHR - Extension: No name found = C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.4_1\
CHR - Extension: No name found = C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8153_1\
CHR - Extension: No name found = C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
CHR - Extension: No name found = C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2004/08/19 13.00.00 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Guida per l'accesso a Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [avgnt] C:\Programmi\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [PosService] C:\Documents and Settings\All Users\Documenti\AppData\PoApp\PLauncher.exe File not found
O4 - HKLM..\Run: [ScanSoft OmniPage SE 4-reminder] C:\Programmi\ScanSoft\OmniPageSE4\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Wireless Utility.lnk = C:\Programmi\EDIMAX\Common\RaUI.exe (Edimax Technology Co., Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-220523388-1425521274-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-220523388-1425521274-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: E&sporta in Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 62.101.93.101 83.103.25.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5224BD8E-CED1-4250-9CAE-43EF5FBD6541}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5224BD8E-CED1-4250-9CAE-43EF5FBD6541}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E7D3BF5-6422-4DBE-AF54-ACB1B5176CE4}: DhcpNameServer = 192.168.1.254 62.101.93.101 83.103.25.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D5B4295-DEDC-4D6E-9361-736C52D511E2}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A277764D-347B-440C-B080-EB0FC14AC6AD}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programmi\File comuni\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/11 13.15.31 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 60 Days ========== [2013/12/03 09.36.46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\GIOVANNI\Desktop\software pc
[2013/12/03 09.30.07 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/11/28 18.52.00 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\GIOVANNI\Desktop\HijackThis.exe
[2013/11/25 09.12.27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware
[2013/11/25 09.12.26 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013/11/25 09.12.26 | 000,000,000 | ---D | C] -- C:\Programmi\Malwarebytes' Anti-Malware
[2013/11/22 10.35.20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\GIOVANNI\Documenti\Dropbox
[2013/11/22 10.34.07 | 000,000,000 | ---D | C] -- C:\Programmi\Dropbox
[2013/11/22 10.33.54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GIOVANNI\Menu Avvio\Programmi\Dropbox
[2013/11/22 10.32.54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Dropbox
[2013/11/19 19.56.39 | 000,000,000 | ---D | C] -- C:\Programmi\Mozilla Maintenance Service
[2013/11/19 18.03.27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GIOVANNI\Documenti\Ashampoo Burning Studio 12
[2013/11/19 18.03.04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Ashampoo
[2013/11/19 18.02.49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\ashampoo
[2013/11/19 18.02.47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GIOVANNI\Menu Avvio\Programmi\Ashampoo
[2013/11/19 18.02.46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Ashampoo
[2013/11/19 18.01.44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Ashampoo
[2013/11/19 18.01.43 | 000,000,000 | ---D | C] -- C:\Programmi\Ashampoo
[2013/11/12 11.59.46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\clp
[2013/11/12 11.59.42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dati applicazioni\Fighters
[2013/11/12 11.59.33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Fighters
[2013/11/12 11.59.02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Common Toolkit Suite
[2013/11/12 11.58.25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Fighters
[2013/11/06 09.56.47 | 000,000,000 | ---D | C] -- C:\Programmi\Mozilla Firefox
[2013/11/05 17.34.37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GIOVANNI\Desktop\giudici basilicata
[2013/10/29 17.15.29 | 000,000,000 | ---D | C] -- C:\pz
[2013/10/09 08.40.56 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidparse.sys
[2013/10/09 08.39.06 | 000,123,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbvideo.sys
[2013/10/09 08.39.06 | 000,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
[2013/10/09 08.38.03 | 000,144,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbport.sys
[2013/10/09 08.38.03 | 000,032,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/10/09 08.38.03 | 000,030,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbehci.sys
[2013/10/09 08.38.03 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbd.sys
========== Files - Modified Within 60 Days ========== [2013/12/03 09.38.25 | 000,545,946 | ---- | M] () -- C:\WINDOWS\System32\perfh010.dat
[2013/12/03 09.38.25 | 000,496,642 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/12/03 09.38.25 | 000,100,470 | ---- | M] () -- C:\WINDOWS\System32\perfc010.dat
[2013/12/03 09.38.25 | 000,085,126 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/12/03 09.36.28 | 000,001,134 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/12/03 09.34.46 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-220523388-1425521274-725345543-1004.job
[2013/12/03 09.34.45 | 000,001,130 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/12/03 09.34.27 | 000,000,338 | ---- | M] () -- C:\WINDOWS\tasks\Windows Codec Update Service.job
[2013/12/03 09.34.26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/12/03 09.02.15 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/12/03 08.41.32 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/12/02 15.40.23 | 000,001,425 | ---- | M] () -- C:\WINDOWS\Pregeo.INI
[2013/11/30 16.30.06 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-220523388-1425521274-725345543-1004.job
[2013/11/28 18.52.02 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\GIOVANNI\Desktop\HijackThis.exe
[2013/11/28 17.57.53 | 000,097,550 | ---- | M] () -- C:\Documents and Settings\GIOVANNI\Desktop\minivlley.jpg
[2013/11/27 14.30.57 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2013/11/27 14.30.57 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2013/11/27 14.30.57 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avkmgr.sys
[2013/11/27 11.19.20 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2013/11/26 16.58.18 | 000,002,241 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2013/11/25 09.35.16 | 000,001,775 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/11/25 09.12.27 | 000,000,756 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/11/20 10.19.21 | 000,014,551 | ---- | M] () -- C:\Documents and Settings\GIOVANNI\Desktop\logopetruzzi.gif
[2013/11/19 18.02.48 | 000,000,924 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ashampoo Burning Studio 12.lnk
[2013/11/13 20.39.54 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013/11/04 15.59.34 | 000,000,555 | ---- | M] () -- C:\Documents and Settings\GIOVANNI\Desktop\docfa 4.2.lnk
[2013/10/29 17.31.11 | 000,524,065 | ---- | M] () -- C:\ark_comurb.zip
[2013/10/29 17.14.48 | 000,238,610 | ---- | M] () -- C:\ark_pz(1).zip
[2013/10/24 11.49.57 | 000,109,255 | ---- | M] () -- C:\Documents and Settings\GIOVANNI\Desktop\1385724_10200707935925147_618329993_n.jpg
[2013/10/13 12.28.02 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe
[2013/10/13 12.28.02 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2013/10/13 08.22.29 | 000,920,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
[2013/10/13 08.22.27 | 000,759,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vgx.dll
[2013/10/13 08.22.26 | 001,215,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
[2013/10/13 08.22.25 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
[2013/10/13 08.22.25 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
[2013/10/13 08.22.25 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
[2013/10/13 08.22.24 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll
[2013/10/13 08.22.24 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2013/10/13 08.22.23 | 006,021,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/10/13 08.22.23 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
[2013/10/13 08.22.16 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2013/10/13 08.22.16 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2013/10/13 08.22.16 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll
[2013/10/13 08.22.16 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2013/10/13 08.22.15 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/10/13 08.22.15 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\licmgr10.dll
[2013/10/13 08.22.15 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licmgr10.dll
[2013/10/13 08.22.15 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
[2013/10/13 08.22.15 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
[2013/10/13 08.22.14 | 002,006,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2013/10/13 08.22.14 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
[2013/10/13 08.22.14 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2013/10/13 08.22.12 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll
[2013/10/13 08.22.12 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
[2013/10/13 08.21.48 | 011,113,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2013/10/13 08.21.43 | 000,743,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2013/10/13 08.21.42 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
[2013/10/13 08.21.42 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2013/10/13 08.21.42 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\corpol.dll
[2013/10/13 08.21.42 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\corpol.dll
[2013/10/13 07.57.59 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec
[2013/10/12 16.56.08 | 000,279,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oakley.dll
[2013/10/10 07.53.24 | 000,360,936 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/10/09 15.07.29 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/10/09 15.07.29 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/10/09 14.12.41 | 000,287,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gdi32.dll
[2013/10/07 11.59.15 | 000,607,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
========== Files Created - No Company Name ========== [2013/11/28 17.57.53 | 000,097,550 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\Desktop\minivlley.jpg
[2013/11/25 09.12.27 | 000,000,756 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/11/20 10.19.21 | 000,014,551 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\Desktop\logopetruzzi.gif
[2013/11/19 19.56.40 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Mozilla Firefox.lnk
[2013/11/19 18.02.48 | 000,000,924 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ashampoo Burning Studio 12.lnk
[2013/11/04 15.59.34 | 000,000,555 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\Desktop\docfa 4.2.lnk
[2013/10/29 17.32.01 | 001,606,656 | ---- | C] () -- C:\Comuni.idx
[2013/10/29 17.32.01 | 000,797,744 | ---- | C] () -- C:\Comuni.dat
[2013/10/29 17.31.04 | 000,524,065 | ---- | C] () -- C:\ark_comurb.zip
[2013/10/29 17.14.46 | 000,238,610 | ---- | C] () -- C:\ark_pz(1).zip
[2013/10/24 11.49.56 | 000,109,255 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\Desktop\1385724_10200707935925147_618329993_n.jpg
[2013/05/06 17.45.15 | 000,000,780 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2013/02/08 15.31.32 | 000,073,836 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2013/01/21 12.00.57 | 000,032,229 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2013/01/21 11.48.03 | 000,000,872 | R--- | C] () -- C:\WINDOWS\System32\okisclna.ini
[2012/11/16 03.20.28 | 001,497,090 | ---- | C] () -- C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-S-1-5-21-220523388-1425521274-725345543-1004-0.dat
[2012/10/29 12.09.28 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2012/10/29 12.09.28 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012/10/29 12.09.28 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012/10/29 12.09.28 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2012/10/29 12.09.28 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe
[2012/09/12 06.36.47 | 000,715,038 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\unins000.exe
[2012/09/12 06.36.47 | 000,004,846 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\unins000.dat
[2012/09/11 11.45.32 | 000,348,946 | ---- | C] () -- C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-System.dat
[2012/04/21 17.05.48 | 000,000,040 | ---- | C] () -- C:\WINDOWS\iris.ini
[2012/04/12 15.31.43 | 000,173,688 | ---- | C] () -- C:\WINDOWS\tscc.exe
[2012/04/07 10.09.39 | 000,472,576 | ---- | C] () -- C:\WINDOWS\bdeini.dll
[2012/03/22 16.39.57 | 000,000,048 | ---- | C] () -- C:\WINDOWS\Tariffe.ini
[2012/03/22 16.36.45 | 000,054,272 | ---- | C] () -- C:\WINDOWS\System32\Rundlg32.exe
[2012/02/15 09.39.05 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/08/30 18.02.21 | 000,000,330 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\dikeutil.ini
[2011/08/30 17.58.26 | 000,002,060 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\dikeTmpinternet
[2011/08/30 17.58.25 | 000,000,165 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\dike.ini
[2011/05/05 16.37.02 | 000,013,824 | ---- | C] () -- C:\Documents and Settings\GIOVANNI\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/11 18.19.46 | 000,040,960 | ---- | C] () -- C:\Programmi\Uninstall_CDS.exe
[2011/04/11 16.16.30 | 007,340,032 | -H-- | C] () -- C:\Documents and Settings\GIOVANNI\NTUSER.bak
========== ZeroAccess Check ========== [2011/12/15 12.16.57 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/12/19 09.54.02 | 001,510,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 11.51.43 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 03.13.56 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2013/09/09 16.49.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2011/12/15 16.26.52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Acer
[2013/11/19 18.02.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Ashampoo
[2012/09/17 14.47.34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\AVAST Software
[2012/01/24 12.09.22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Boss Media
[2011/11/14 18.05.07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonBJ
[2012/04/21 14.49.48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonIJMyPrinter
[2013/09/09 08.14.25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonIJPLM
[2013/11/12 12.29.48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\clp
[2013/05/28 11.23.06 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Common Files
[2013/11/12 11.59.02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Common Toolkit Suite
[2013/11/19 08.54.14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Fighters
[2013/05/17 20.54.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\IMSIDesign
[2013/06/08 19.23.44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\MFAData
[2013/01/21 11.48.10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Okidata
[2012/04/21 17.07.12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Panasonic
[2012/11/15 15.26.59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Samsung
[2013/01/21 12.05.34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\ScanSoft
[2013/11/28 18.23.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\TEMP
[2013/02/11 09.23.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Zeon
[2011/12/15 16.27.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Acer
[2011/12/15 12.47.55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\ACER_EUU_Download_Tools
[2013/04/11 15.38.35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Analist Group
[2013/11/19 18.03.04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Ashampoo
[2012/04/21 14.50.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Canon
[2012/12/20 16.36.03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2013/11/27 08.11.25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Dropbox
[2012/09/13 15.26.50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\EmoticoonsToolbar
[2012/03/24 17.17.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\EssentialPIM
[2013/11/12 11.59.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Fighters
[2013/06/04 15.45.23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\FireShot
[2011/11/02 16.44.32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\GrabPro
[2012/09/13 15.26.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\IEToolbar
[2013/05/17 20.54.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\IMSIDesign
[2013/05/02 09.34.32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\OkiData
[2011/06/23 20.48.21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\OpenOffice.org
[2011/11/02 16.58.57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Orbit
[2012/06/04 17.54.20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Panasonic
[2011/11/02 16.44.45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\ProgSense
[2012/12/29 09.17.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Samsung
[2013/01/22 12.31.50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\ScanSoft
[2013/05/28 11.35.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\TuneUp Software
[2013/05/20 18.36.54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Wise Registry Cleaner
[2012/12/03 17.27.04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Xmarc
[2013/02/11 09.23.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GIOVANNI\Dati applicazioni\Zeon
[2013/11/12 11.59.43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dati applicazioni\Fighters
========== Purity Check ========== ========== Files - Unicode (All) ==========[2013/10/09 19.15.27 | 100,163,860 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\멥嚬6
[2013/10/09 13.15.26 | 100,163,860 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\멥嚬6
========== Alternate Data Streams ========== @Alternate Data Stream - 223 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:C68DE4A3
@Alternate Data Stream - 183 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:48C1F0D9
< End of report >