ecco qua OTListIt.txt , ho dovuto dividere per superamento caratteri permessi
OTL logfile created on: 29/05/2012 21.10.54 - Run 1
OTL by OldTimer - Version 3.2.44.0 Folder = C:\Documents and Settings\Computer\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,25 Gb Total Physical Memory | 2,61 Gb Available Physical Memory | 80,31% Memory free
7,04 Gb Paging File | 6,60 Gb Available in Paging File | 93,71% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 273,44 Gb Total Space | 242,90 Gb Free Space | 88,83% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 734,61 Gb Free Space | 78,86% Space Free | Partition Type: NTFS
Drive F: | 24,65 Gb Total Space | 18,65 Gb Free Space | 75,66% Space Free | Partition Type: NTFS
Drive H: | 960,34 Mb Total Space | 950,96 Mb Free Space | 99,02% Space Free | Partition Type: FAT32
Computer Name: IVAN | User Name: Computer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/05/29 21.09.37 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Computer\Desktop\OTL.exe
PRC - [2012/03/07 02.15.17 | 004,241,512 | ---- | M] (AVAST Software) -- C:\Programmi\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/03/07 02.15.14 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Programmi\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012/02/27 01.15.42 | 000,055,144 | ---- | M] (Apple Inc.) -- C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2012/02/15 01.03.14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Computer\Dati applicazioni\Dropbox\bin\Dropbox.exe
PRC - [2010/01/09 21.37.50 | 004,640,000 | ---- | M] (Microsoft Corporation) -- C:\Programmi\File comuni\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
PRC - [2009/12/13 18.45.46 | 001,619,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== MOD - [2012/05/29 08.55.39 | 001,763,328 | ---- | M] () -- C:\Programmi\Alwil Software\Avast5\defs\12052900\algo.dll
MOD - [2012/05/28 19.54.33 | 001,763,328 | ---- | M] () -- C:\Programmi\Alwil Software\Avast5\defs\12052801\algo.dll
MOD - [2012/04/04 07.53.58 | 000,301,056 | ---- | M] () -- C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA
MOD - [2011/09/27 08.23.00 | 000,087,912 | ---- | M] () -- C:\Programmi\File comuni\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08.22.40 | 001,242,472 | ---- | M] () -- C:\Programmi\File comuni\Apple\Apple Application Support\libxml2.dll
MOD - [2011/03/17 00.11.16 | 004,297,568 | ---- | M] () -- C:\Programmi\File comuni\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- C:\Programmi\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2012/05/05 15.24.33 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/03/07 02.15.14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programmi\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/02/27 01.15.42 | 000,055,144 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/12/08 15.31.06 | 000,628,736 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Programmi\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/05/05 18.31.35 | 000,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2010/03/18 13.16.28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2010/01/09 21.37.50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programmi\File comuni\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010/01/09 21.18.00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009/12/13 17.29.32 | 000,030,720 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\msdtc.exe -- (MSDTC)
SRV - [2009/12/13 17.29.30 | 000,053,248 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\mnmsrvc.exe -- (mnmsrvc)
SRV - [2009/12/13 17.29.12 | 000,043,008 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\clipsrv.exe -- (ClipSrv)
SRV - [2008/07/29 20.24.50 | 000,881,664 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
SRV - [2008/06/24 16.05.56 | 000,537,896 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2008/06/08 09.31.04 | 000,877,864 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3)
SRV - [2008/04/13 20.14.24 | 000,293,888 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\vssvc.exe -- (VSS)
SRV - [2008/04/13 20.14.24 | 000,074,752 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\tlntsvr.exe -- (TlntSvr)
SRV - [2008/04/13 20.14.22 | 000,092,672 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\smlogsvc.exe -- (SysmonLog)
SRV - [2008/04/13 20.14.20 | 000,142,336 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\sessmgr.exe -- (RDSessMgr)
SRV - [2008/04/13 20.14.16 | 000,113,152 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\netdde.exe -- (NetDDEdsdm)
SRV - [2008/04/13 20.14.16 | 000,113,152 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\netdde.exe -- (NetDDE)
SRV - [2008/04/13 20.14.12 | 000,013,312 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\lsass.exe -- (NtLmSsp)
SRV - [2008/04/13 20.14.12 | 000,013,312 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\lsass.exe -- (Netlogon)
SRV - [2008/04/13 20.14.10 | 000,150,528 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\imapi.exe -- (ImapiService)
SRV - [2008/04/13 20.13.58 | 000,068,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\webclnt.dll -- (WebClient)
SRV - [2008/04/13 20.13.50 | 000,088,576 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\rasauto.dll -- (RasAuto)
SRV - [2008/04/13 20.13.50 | 000,059,904 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\regsvc.dll -- (RemoteRegistry)
SRV - [2008/04/13 20.13.48 | 000,437,248 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\ntmssvc.dll -- (NtmsSvc)
SRV - [2008/04/13 20.13.44 | 000,053,248 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\mprdim.dll -- (RemoteAccess)
SRV - [2008/04/13 20.13.44 | 000,033,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\msgsvc.dll -- (Messenger)
SRV - [2008/04/13 20.13.42 | 000,013,824 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\lmhsvc.dll -- (LmHosts)
SRV - [2008/04/13 20.13.38 | 000,017,408 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\alrsvc.dll -- (Alerter)
SRV - [2006/04/12 10.29.30 | 000,266,295 | ---- | M] (Broadcom Corporation.) [Disabled | Stopped] -- C:\Programmi\D-Link\Bluetooth Software\bin\btwdins.exe -- (btwdins)
SRV - [2004/10/22 03.24.18 | 000,073,728 | ---- | M] (Macrovision Corporation) [Disabled | Stopped] -- C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004/08/19 14.00.00 | 000,132,608 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\rsvp.exe -- (RSVP)
SRV - [2004/03/18 16.55.48 | 000,065,536 | ---- | M] (HP) [Disabled | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2003/06/20 00.25.00 | 000,322,120 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Programmi\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x86\Sandra.sys -- (SANDRA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\Drivers\AsrCDDrv.sys -- (AsrCDDrv)
DRV - [2012/03/07 02.03.51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/03/07 02.03.38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/03/07 02.02.00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012/03/07 02.01.53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/03/07 02.01.39 | 000,095,704 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/03/07 02.01.30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/03/07 01.58.29 | 000,024,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/01/17 22.55.42 | 000,028,424 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PRSBDrvr.sys -- (PRSBDrvr)
DRV - [2010/07/30 15.16.46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010/07/30 15.16.44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/07/30 15.16.42 | 000,023,040 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/07/30 15.16.38 | 000,018,048 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010/07/26 13.24.46 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2010/07/26 13.24.42 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2010/06/08 21.30.16 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\Lbd.sys -- (Lbd)
DRV - [2010/04/19 19.29.20 | 000,018,432 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\netaapl.sys -- (Netaapl)
DRV - [2010/03/11 11.17.14 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV - [2009/08/17 20.16.06 | 001,390,976 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/06/29 01.36.36 | 000,017,920 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2009/03/10 14.17.44 | 000,103,552 | R--- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\qscvusb.sys -- (MobileAdapter)
DRV - [2009/01/22 16.43.56 | 000,046,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvhda32.sys -- (NVHDA)
DRV - [2008/08/26 10.26.12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/08/18 12.54.24 | 000,145,952 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts)
DRV - [2008/04/13 19.56.02 | 000,120,448 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\pcmcia.sys -- (Pcmcia)
DRV - [2008/04/13 19.53.56 | 000,800,256 | ---- | M] (Microsoft Corp., Veritas Software) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\dmboot.sys -- (dmboot)
DRV - [2008/04/13 13.14.22 | 000,063,744 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\cdfs.sys -- (Cdfs)
DRV - [2008/04/13 12.32.38 | 000,066,048 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\udfs.sys -- (Udfs)
DRV - [2008/03/25 05.48.08 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008/03/25 05.48.06 | 000,054,400 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2007/12/17 18.14.04 | 000,012,400 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2006/04/12 10.14.50 | 000,329,837 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2006/04/12 10.11.36 | 000,023,271 | ---- | M] (Broadcom Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\btserial.sys -- (BTSERIAL)
DRV - [2006/04/12 10.09.32 | 000,854,538 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2006/04/12 10.05.48 | 000,030,427 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006/04/12 10.04.46 | 000,065,784 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2006/04/12 10.02.14 | 000,148,932 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2006/04/12 10.00.46 | 000,047,811 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2004/08/19 14.00.00 | 000,013,952 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\cbidf2k.sys -- (cbidf2k)
DRV - [2004/08/19 14.00.00 | 000,012,160 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\acpiec.sys -- (ACPIEC)
DRV - [2004/08/13 11.56.20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ IE - HKU\S-1-5-21-842925246-179605362-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/IE - HKU\S-1-5-21-842925246-179605362-682003330-1003\..\URLSearchHook: {c91fec63-9f25-400d-95e5-6cd334dd3cc1} - C:\Programmi\IncrediMail_MediaBar_Italiano_2\prxtbInc2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-842925246-179605362-682003330-1003\..\SearchScopes,DefaultScope = {FE719720-E048-40FE-A783-1A7A418AEBC4}
IE - HKU\S-1-5-21-842925246-179605362-682003330-1003\..\SearchScopes\{FE719720-E048-40FE-A783-1A7A418AEBC4}: "URL" =
http://www.google.com/search?hl=en&q={searchTerms}&rlz=1I7ADFA_it
IE - HKU\S-1-5-21-842925246-179605362-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-842925246-179605362-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local;*.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "MyStart Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://mystart.incredimail.com?a=13T2U2d4vgl"
FF - prefs.js..extensions.enabledItems:
add-to-searchbox@maltekraus.de:2.0
FF - prefs.js..extensions.enabledItems:
amin.eft_Shutdown@gmail.com:3.0.2A
FF - prefs.js..extensions.enabledItems:
piclens@cooliris.com:1.8.2.4690
FF - prefs.js..extensions.enabledItems:
it-IT@dictionaries.addons.mozilla.org:3.1
FF - prefs.js..extensions.enabledItems:
dlembed@aeruder.net:0.5
FF - prefs.js..extensions.enabledItems: {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.9.1
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.3
FF - prefs.js..extensions.enabledItems: {c2d0e930-64de-11db-bd13-0800200c9a66}:2.0.4
FF - prefs.js..extensions.enabledItems: {c91fec63-9f25-400d-95e5-6cd334dd3cc1}:3.5.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems:
linkalert.conlan@addons.mozilla.com:0.8.2.1
FF - prefs.js..extensions.enabledItems: {9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}:6.0.1
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:2.0.0.0
FF - prefs.js..extensions.enabledItems: {b548b086-6516-4d37-83f7-302f2bea93b1}:1.5.45.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.7
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.5.0.7896
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.3.0.1
FF - prefs.js..extensions.enabledItems: {992791ee-61dc-7b98-a8fd-dc49b7deeee9}:3.2.0
FF - prefs.js..extensions.enabledItems: {95f24680-9e31-11da-a746-0800200c9a66}:0.1.5.4
FF - prefs.js..extensions.enabledItems: {1e334369-810a-4aca-b482-209966fdde24}:1.5.46.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31
FF - prefs.js..extensions.enabledItems:
wrc@avast.com:7.0.1426
FF - prefs.js..keyword.URL: "http://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.sweetim.com/search.asp?src=2&q="
FF - user.js..browser.search.openintab: false
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programmi\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programmi\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmi\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programmi\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: c:\programmi\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: c:\programmi\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: c:\programmi\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programmi\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programmi\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\Documents and Settings\All Users\Dati applicazioni\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmi\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Programmi\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010/12/24 23.35.08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/12 21.45.26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Programmi\Alwil Software\Avast5\WebRep\FF [2012/03/10 19.15.05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Programmi\Mozilla Firefox\components [2011/12/12 21.45.19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Programmi\Mozilla Firefox\plugins [2012/04/19 21.47.25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Programmi\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010/12/24 23.35.09 | 000,000,000 | ---D | M]
[2010/09/29 12.52.57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Extensions
[2010/09/29 12.52.57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/05/06 10.45.46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions
[2008/10/13 01.41.48 | 000,000,000 | ---D | M] (UWP Toolbar) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{1e334369-810a-4aca-b482-209966fdde24}
[2011/10/30 09.00.51 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/10/13 01.41.47 | 000,000,000 | ---D | M] (MinimizeToTray) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{31513E58-F253-47ad-86DB-D5F21E905429}
[2008/10/13 01.41.47 | 000,000,000 | ---D | M] (PDF Download) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2008/10/13 01.41.46 | 000,000,000 | ---D | M] (Forecastbar Enhanced) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
[2008/10/13 01.41.44 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2008/10/13 01.41.44 | 000,000,000 | ---D | M] (MR Tech Toolkit (formerly Local Install)) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}
[2010/02/17 22.53.16 | 000,000,000 | ---D | M] (TryAgain) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{992791ee-61dc-7b98-a8fd-dc49b7deeee9}
[2008/10/13 01.41.43 | 000,000,000 | ---D | M] (Blue Ice 2) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}
[2008/10/13 01.41.43 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2010/02/17 22.53.16 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2008/10/13 01.41.43 | 000,000,000 | ---D | M] (Phaze Bar Toolbar) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{b548b086-6516-4d37-83f7-302f2bea93b1}
[2008/10/13 01.41.42 | 000,000,000 | ---D | M] (FAYT) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{c2d0e930-64de-11db-bd13-0800200c9a66}
[2008/10/13 01.41.42 | 000,000,000 | ---D | M] (Fasterfox) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a66}
[2011/06/29 19.51.35 | 000,000,000 | ---D | M] (IncrediMail MediaBar Italiano 2 Community Toolbar) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{c91fec63-9f25-400d-95e5-6cd334dd3cc1}
[2008/10/13 01.41.42 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011/11/08 22.38.15 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2010/02/17 22.53.15 | 000,000,000 | ---D | M] (Download Manager Tweak) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}
[2010/02/17 22.53.14 | 000,000,000 | ---D | M] (Add to Search Bar) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\add-to-searchbox@maltekraus.de
[2008/10/13 01.41.53 | 000,000,000 | ---D | M] (Auto Shutdown - InBasic) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\amin.eft_Shutdown@gmail.com
[2008/10/13 01.41.52 | 000,000,000 | ---D | M] (Download Embedded) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\dlembed@aeruder.net
[2008/10/13 01.41.52 | 000,000,000 | ---D | M] (Dizionario italiano) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\it-IT@dictionaries.addons.mozilla.org
[2008/10/13 01.41.52 | 000,000,000 | ---D | M] ("Link Alert") -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\linkalert.conlan@addons.mozilla.com
[2008/10/13 01.41.51 | 000,000,000 | ---D | M] (Cooliris) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\piclens@cooliris.com
[2008/10/13 01.41.49 | 000,000,000 | ---D | M] (Translation Panel) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\translation@nazo
[2008/10/13 01.41.48 | 000,000,000 | ---D | M] ("Undo Closed Tabs Button") -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\extensions\undoclosedtabsbutton@supernova00.biz
[2010/02/17 22.43.19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\g5e6l7wp.default\extensions
[2010/05/26 15.18.50 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\askcom.xml
[2008/10/09 04.48.08 | 000,002,013 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\crack-spider.xml
[2008/02/18 12.19.24 | 000,000,943 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\filmmusicru.xml
[2008/09/08 23.17.14 | 000,000,992 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\gamecopyworld.xml
[2008/02/18 12.18.32 | 000,005,327 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\infinitewarez.xml
[2008/09/30 00.44.46 | 000,001,001 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\mininova.xml
[2011/04/11 11.53.15 | 000,002,185 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\MyStart Search.xml
[2008/10/14 23.36.03 | 000,001,954 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\phazeddl-warez.xml
[2008/02/21 17.59.20 | 000,001,031 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\phazemp3-albums.xml
[2008/02/18 12.16.14 | 000,000,542 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\serials--keys.xml
[2011/11/08 22.38.08 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\Mozilla\Firefox\Profiles\bao8jswp.default\searchplugins\sweetim.xml
[2012/05/06 10.45.46 | 000,000,000 | ---D | M] (No name found) -- C:\Programmi\Mozilla Firefox\extensions
[2011/07/23 11.22.28 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programmi\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/05/04 21.58.11 | 000,000,000 | ---D | M] (Java Console) -- C:\Programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/07 20.26.46 | 000,000,000 | ---D | M] (Java Console) -- C:\Programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/29 20.03.54 | 000,000,000 | ---D | M] (Java Console) -- C:\Programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/07 10.33.10 | 000,000,000 | ---D | M] (Java Console) -- C:\Programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/06/20 18.28.37 | 000,000,000 | ---D | M] (Java Console) -- C:\Programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/05/06 10.45.34 | 000,000,000 | ---D | M] (Java Console) -- C:\Programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2011/12/12 21.45.26 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\DATI APPLICAZIONI\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/03/10 19.15.05 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAMMI\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2012/04/15 18.34.57 | 000,000,000 | ---D | M] (No name found) -- C:\PROGRAMMI\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/10/03 05.06.04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programmi\mozilla firefox\plugins\npdeployJava1.dll
[2006/09/26 12.03.14 | 000,098,304 | ---- | M] (Zylom) -- C:\Programmi\mozilla firefox\plugins\npzylomgamesplayer.dll
[2010/05/04 22.01.00 | 000,001,412 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\demauro.xml
[2010/05/04 22.01.00 | 000,000,744 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\eBay-it.xml
[2010/05/04 22.01.00 | 000,001,182 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\wikipedia-it.xml
[2010/05/04 22.01.00 | 000,000,649 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\yahoo-it.xml
========== Chrome ========== O1 HOSTS File: ([2004/08/19 14.00.00 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Programmi\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmi\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmi\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Guida per l'accesso a Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programmi\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (IncrediMail MediaBar Italiano 2 Toolbar) - {c91fec63-9f25-400d-95e5-6cd334dd3cc1} - C:\Programmi\IncrediMail_MediaBar_Italiano_2\prxtbInc2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmi\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (IncrediMail MediaBar Italiano 2 Toolbar) - {c91fec63-9f25-400d-95e5-6cd334dd3cc1} - C:\Programmi\IncrediMail_MediaBar_Italiano_2\prxtbInc2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-842925246-179605362-682003330-1003\..\Toolbar\WebBrowser: (IncrediMail MediaBar Italiano 2 Toolbar) - {C91FEC63-9F25-400D-95E5-6CD334DD3CC1} - C:\Programmi\IncrediMail_MediaBar_Italiano_2\prxtbInc2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] C:\Programmi\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - Startup: C:\Documents and Settings\Computer\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk = C:\Documents and Settings\Computer\Dati applicazioni\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-842925246-179605362-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-842925246-179605362-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-21-842925246-179605362-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-842925246-179605362-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-842925246-179605362-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O8 - Extra context menu item: Cerca nel web - C:\Programmi\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O8 - Extra context menu item: E&sporta in Microsoft Excel - C:\Programmi\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... -
res://C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html File not found
O8 - Extra context menu item: I&nvia a OneNote - C:\Programmi\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\D-Link\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programmi\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programmi\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programmi\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programmi\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programmi\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9}
http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC}
https://h20436.www2.hp.com/ediags/dex/s ... DEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2C5CE2E1-40D6-4E6F-AAAE-FB84F38DAF17}: NameServer = 80.79.48.66,79.137.95.200
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3B066AB-3D56-4A5F-8812-859E5C2DC95C}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmi\File comuni\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programmi\File comuni\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Wallpapers & Etc)
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - File not found
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Computer\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Computer\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programmi\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programmi\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Programmi\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/02/29 16.34.58 | 000,000,654 | ---- | M] () - C:\autoAlbum.log -- [ NTFS ]
O32 - AutoRun File - [2010/02/17 19.55.34 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{4191bec8-75b3-11e0-b727-b5f343fae7d6}\Shell - "" = AutoRun
O33 - MountPoints2\{4191bec8-75b3-11e0-b727-b5f343fae7d6}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O33 - MountPoints2\{4191bec9-75b3-11e0-b727-b5f343fae7d6}\Shell - "" = AutoRun
O33 - MountPoints2\{4191bec9-75b3-11e0-b727-b5f343fae7d6}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O33 - MountPoints2\{4d301096-6409-11e0-b711-8f210abf15b5}\Shell - "" = AutoRun
O33 - MountPoints2\{4d301096-6409-11e0-b711-8f210abf15b5}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O33 - MountPoints2\{4d301097-6409-11e0-b711-8f210abf15b5}\Shell - "" = AutoRun
O33 - MountPoints2\{4d301097-6409-11e0-b711-8f210abf15b5}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O33 - MountPoints2\{4d301099-6409-11e0-b711-8f210abf15b5}\Shell - "" = AutoRun
O33 - MountPoints2\{4d301099-6409-11e0-b711-8f210abf15b5}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O33 - MountPoints2\{515f4484-aad5-11df-b617-86197a81c019}\Shell - "" = AutoRun
O33 - MountPoints2\{515f4484-aad5-11df-b617-86197a81c019}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O33 - MountPoints2\{515f4485-aad5-11df-b617-86197a81c019}\Shell - "" = AutoRun
O33 - MountPoints2\{515f4485-aad5-11df-b617-86197a81c019}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O33 - MountPoints2\{b8e1ecde-91a9-11df-b601-e4c5d96f49b7}\Shell - "" = AutoRun
O33 - MountPoints2\{b8e1ecde-91a9-11df-b601-e4c5d96f49b7}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O33 - MountPoints2\{b8e1ecdf-91a9-11df-b601-da97358f463f}\Shell - "" = AutoRun
O33 - MountPoints2\{b8e1ecdf-91a9-11df-b601-da97358f463f}\Shell\AutoRun\command - "" = G:\VDFPcAssistant.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/05/29 21.09.35 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Computer\Desktop\OTL.exe
[2012/05/29 06.40.45 | 000,000,000 | ---D | C] -- D:\Documenti\File di Outlook
[2012/05/29 06.16.36 | 000,000,000 | ---D | C] -- D:\Documenti\FILMS E VIDEO
[2012/05/29 06.00.30 | 000,000,000 | ---D | C] -- D:\Documenti\eMule Downloads
[2012/05/29 05.58.10 | 000,000,000 | ---D | C] -- D:\Documenti\FFOutput
[2012/05/28 22.53.13 | 000,000,000 | ---D | C] -- D:\Documenti\IncrediMail Transferred Data
[2012/05/28 22.52.32 | 000,000,000 | ---D | C] -- D:\Documenti\impianti idroelettrici sarca
[2012/05/28 22.50.40 | 000,000,000 | ---D | C] -- D:\Documenti\arena
[2012/05/28 22.49.09 | 000,000,000 | R--D | C] -- D:\Documenti\Ivan
[2012/05/28 22.49.08 | 000,000,000 | ---D | C] -- D:\Documenti\X IPHONE
[2012/05/28 22.28.13 | 000,000,000 | ---D | C] -- D:\Documenti\Video
[2012/05/28 22.28.13 | 000,000,000 | ---D | C] -- D:\Documenti\varie articoli
[2012/05/28 22.28.13 | 000,000,000 | ---D | C] -- D:\Documenti\Updater
[2012/05/28 22.28.13 | 000,000,000 | ---D | C] -- D:\Documenti\Skype
[2012/05/28 22.27.58 | 000,000,000 | R--D | C] -- D:\Documenti\Immagini
[2012/05/28 22.27.06 | 000,000,000 | ---D | C] -- D:\Documenti\foto stampate I°serie
[2012/05/28 22.27.05 | 000,000,000 | ---D | C] -- D:\Documenti\NeroVision
[2012/05/28 22.27.05 | 000,000,000 | ---D | C] -- D:\Documenti\documenti vari
[2012/05/28 22.24.19 | 000,000,000 | ---D | C] -- D:\Documenti\Nero
[2012/05/28 22.24.19 | 000,000,000 | ---D | C] -- D:\Documenti\daniela
[2012/05/28 21.55.59 | 000,000,000 | R--D | C] -- D:\Documenti\FOTO
[2012/05/28 21.23.02 | 000,000,000 | ---D | C] -- D:\Documenti\film
[2012/05/28 21.22.43 | 000,000,000 | ---D | C] -- D:\Documenti\Scansioni personali
[2012/05/28 21.22.32 | 000,000,000 | R--D | C] -- D:\Documenti\Anacli
[2012/05/28 21.22.32 | 000,000,000 | ---D | C] -- D:\Documenti\Album personali
[2012/05/28 21.22.32 | 000,000,000 | ---D | C] -- D:\Documenti\Adobe Scripts
[2012/05/28 21.22.03 | 000,000,000 | R--D | C] -- D:\Documenti\Musica
[2012/05/28 21.22.00 | 000,000,000 | ---D | C] -- D:\Documenti\2010-11 (Nov)
[2012/05/28 21.22.00 | 000,000,000 | ---D | C] -- D:\Documenti\[pcgame]Tetris XP v1
[2012/05/28 21.21.59 | 000,000,000 | ---D | C] -- D:\Documenti\Cartella Scambio Bluetooth
[2012/05/22 19.07.05 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Computer\Recent
[2012/05/22 17.45.16 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012/05/21 19.49.24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DBBK
[2012/05/15 16.35.41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Dati applicazioni\PriceGong
[2012/05/05 14.54.56 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Computer\Desktop\TFC.exe
[2012/05/04 18.02.43 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/05/04 11.08.53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Dati applicazioni\Malwarebytes
[2012/05/04 11.08.49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware
[2012/05/04 11.08.48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
[2012/05/04 11.08.47 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/05/04 11.08.19 | 000,000,000 | ---D | C] -- C:\Programmi\Malwarebytes' Anti-Malware
[2012/05/04 11.06.47 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- C:\Programmi\mbam-setup-1.61.0.1400.exe
[2012/05/04 11.04.10 | 000,000,000 | ---D | C] -- C:\Programmi\Trend Micro
[2012/05/04 11.04.10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Menu Avvio\Programmi\HiJackThis
[2012/05/03 17.45.24 | 000,000,000 | R--D | C] -- D:\Documenti\Dropbox
[2012/05/03 15.48.50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Dati applicazioni\Windows Search
[2012/05/03 15.46.25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Dati applicazioni\Windows Desktop Search
[2012/05/03 15.44.58 | 000,000,000 | ---D | C] -- C:\Programmi\Windows Desktop Search
[2012/05/03 15.44.58 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2010/10/04 23.04.12 | 002,944,904 | ---- | C] (Ask) -- C:\Programmi\File comuni\AskToolbarInstaller.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/05/29 21.09.37 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Computer\Desktop\OTL.exe
[2012/05/29 20.46.01 | 000,001,130 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/29 20.34.28 | 000,000,202 | ---- | M] () -- C:\WINDOWS\tasks\AutoKMSDaily.job
[2012/05/29 20.34.27 | 000,000,206 | ---- | M] () -- C:\WINDOWS\tasks\AutoKMS.job
[2012/05/29 20.34.19 | 000,078,848 | ---- | M] () -- C:\WINDOWS\KMSEmulator.exe
[2012/05/29 20.33.44 | 000,212,641 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/05/29 20.33.13 | 000,001,126 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/29 20.33.13 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-842925246-179605362-682003330-1003.job
[2012/05/29 20.33.11 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/29 20.33.10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/29 06.24.00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/05/28 22.32.34 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{9646D064-3E58-45F4-A7FE-B1451095F60C}.job
[2012/05/28 21.20.46 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/05/28 21.20.45 | 000,157,184 | ---- | M] () -- C:\Documents and Settings\Computer\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/28 20.45.00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-842925246-179605362-682003330-1003.job
[2012/05/28 17.37.51 | 000,002,621 | ---- | M] () -- C:\Documents and Settings\Computer\Desktop\Microsoft Outlook 2010.lnk
[2012/05/28 17.35.09 | 000,000,042 | ---- | M] () -- C:\Documents and Settings\Computer\Dati applicazioni\default.pls
[2012/05/21 20.20.43 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/05/21 19.48.40 | 001,410,373 | ---- | M] () -- C:\Documents and Settings\Computer\Desktop\yorkyt.exe
[2012/05/21 19.46.38 | 003,642,720 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/05/21 18.22.27 | 000,001,012 | ---- | M] () -- C:\Documents and Settings\Computer\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk
[2012/05/17 19.59.41 | 000,008,612 | ---- | M] () -- C:\Documents and Settings\Computer\Desktop\hijackthis1
[2012/05/17 19.59.14 | 000,002,431 | ---- | M] () -- C:\Documents and Settings\Computer\Desktop\HiJackThis.lnk
[2012/05/16 21.26.01 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/05/15 21.29.14 | 000,000,492 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/05/06 18.07.53 | 001,732,608 | ---- | M] () -- D:\Documenti\Database1.accdb
[2012/05/06 18.00.41 | 000,000,064 | ---- | M] () -- D:\Documenti\Database1.laccdb
[2012/05/05 14.55.01 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Computer\Desktop\TFC.exe
[2012/05/04 11.08.49 | 000,000,756 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/04 11.06.47 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Programmi\mbam-setup-1.61.0.1400.exe
[2012/05/03 18.18.15 | 001,253,376 | ---- | M] () -- D:\Documenti\Attività1.accdb
[2012/05/03 18.16.30 | 002,326,528 | ---- | M] () -- D:\Documenti\Progetti di marketing1.accdb
[2012/05/03 18.03.29 | 000,761,856 | ---- | M] () -- D:\Documenti\Eventi.accdb
[2012/05/03 15.45.03 | 000,580,018 | ---- | M] () -- C:\WINDOWS\System32\perfh010.dat
[2012/05/03 15.45.03 | 000,114,204 | ---- | M] () -- C:\WINDOWS\System32\perfc010.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========