[2013/09/27 10:56:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\Extensions
[2013/09/27 14:02:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\Firefox\Profiles\xllia1l9.default\extensions
[2013/09/27 11:08:55 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Salvatore\AppData\Roaming\mozilla\Firefox\Profiles\xllia1l9.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2013/09/27 11:08:55 | 000,000,000 | ---D | M] (IE Tab) -- C:\Users\Salvatore\AppData\Roaming\mozilla\Firefox\Profiles\xllia1l9.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2013/09/27 11:12:51 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Salvatore\AppData\Roaming\mozilla\Firefox\Profiles\xllia1l9.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/09/27 11:12:51 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Salvatore\AppData\Roaming\mozilla\Firefox\Profiles\xllia1l9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013/09/27 11:12:51 | 000,009,388 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\gmail@softice86.com.xpi
[2013/09/27 11:09:21 | 000,170,422 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\jid0-QOD8hILKQRIwhBFHoFiqa6py6ow@jetpack.xpi
[2013/09/27 11:09:31 | 000,171,505 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\jid1-mpUNXKrvqSs6dw@jetpack.xpi
[2013/09/27 11:02:43 | 000,166,101 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\jid1-ZsomX69tl35C5A@jetpack.xpi
[2013/09/27 11:08:55 | 000,098,733 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\printedit@DW-dev.xpi
[2013/09/27 11:08:55 | 000,353,425 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\smarterwiki@wikiatic.com.xpi
[2013/09/27 11:08:55 | 000,060,290 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\translator@zoli.bod.xpi
[2013/09/27 11:08:55 | 000,022,890 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\{19EB90DC-A456-458b-8AAC-616D91AAFCE1}.xpi
[2013/09/27 11:15:59 | 000,242,709 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}.xpi
[2013/09/27 11:02:20 | 000,017,429 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
[2013/09/27 11:02:35 | 000,824,302 | ---- | M] () (No name found) -- C:\Users\Salvatore\AppData\Roaming\mozilla\firefox\profiles\xllia1l9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/09/27 10:56:00 | 000,000,000 | ---D | M] (No name found) -- C:\Programmi\Mozilla Firefox\browser\extensions
[2013/09/27 10:56:00 | 000,000,000 | ---D | M] (Default) -- C:\Programmi\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ========== CHR - default_search_provider: Google Italia (Enabled)
CHR - default_search_provider: search_url =
http://www.google.it/#hl=it&source=hp&q={searchTerms}&aq=f&aqi=g10&aql=&oq=&gs_rfai=&fp=9fca69c98b5d77d7
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\pdf.dll
CHR - plugin: Nero Kwik Media Helper (Enabled) = C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Salvatore\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Salvatore\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Salvatore\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Salvatore\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1203133.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - Extension: Lightning Newtab = C:\Users\Salvatore\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.1.5.2_2\
CHR - Extension: Chrome In-App Payments service = C:\Users\Salvatore\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_2\
O1 HOSTS File: ([2009/06/10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmi\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programmi\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-2170091305-4224216958-3418588652-1001\..\Toolbar\WebBrowser: (ShareThis) - {6A719530-8443-4898-9BC4-69E76B5F1C89} - C:\Programmi\ShareThis Toolbar\share2me.dll (Nextumi, Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CNAP2 Launcher] C:\Windows\System32\spool\drivers\w32x86\3\CNAP2LAK.EXE (CANON INC.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Programmi\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBAgent] C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKU\S-1-5-21-2170091305-4224216958-3418588652-1001..\Run: [] C:\Programmi\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-2170091305-4224216958-3418588652-1001..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2170091305-4224216958-3418588652-1001..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKU\S-1-5-21-2170091305-4224216958-3418588652-1001..\Run: [Kiespreload] C:\Program Files\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-21-2170091305-4224216958-3418588652-1001..\Run: [Rainlendar2] C:\Programmi\Rainlendar2\Rainlendar2.exe ()
O4 - HKU\S-1-5-21-2170091305-4224216958-3418588652-1001..\Run: [uTorrent] C:\Users\Salvatore\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Salvatore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Salvatore\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\S-1-5-21-2170091305-4224216958-3418588652-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&sporta in Microsoft Excel - C:\Programmi\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: I&nvia a OneNote - C:\Programmi\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programmi\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programmi\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programmi\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programmi\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programmi\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programmi\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{49722094-7431-421B-9CE1-A3B7E1BF38DB}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9A2C75F8-5104-4678-B5CD-81F9780E2031}: DhcpNameServer = 8.8.8.8
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmi\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programmi\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programmi\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 60 Days ========== [2013/09/27 15:21:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2013/09/27 15:21:44 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2013/09/27 15:21:10 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013/09/27 14:12:50 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Malwarebytes
[2013/09/27 14:12:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/09/27 14:12:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/09/27 14:12:21 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013/09/27 14:12:21 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013/09/27 14:00:29 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/09/27 13:33:59 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\eUpdate
[2013/09/27 11:37:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/09/27 10:56:11 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013/09/27 10:55:59 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/09/22 13:33:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CrashDump
[2013/09/21 15:09:09 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\Desktop\Nuova cartella (3)
[2013/09/15 17:31:26 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Farm Mania 2.1
[2013/09/15 17:30:02 | 000,000,000 | ---D | C] -- C:\Windows\Farm Mania - Hot Vacation
[2013/09/11 07:27:43 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/09/11 07:27:42 | 002,876,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/09/11 07:27:41 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013/09/11 07:27:41 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/09/11 07:27:40 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/09/11 07:27:39 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/09/11 07:27:39 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013/09/11 07:27:39 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013/09/11 07:27:39 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013/09/11 07:27:39 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013/09/11 07:22:27 | 002,348,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013/09/11 07:22:25 | 000,133,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ataport.sys
[2013/09/11 07:22:08 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2013/09/11 07:22:08 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2013/09/11 07:22:08 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/09/11 07:22:08 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/11 07:22:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/11 07:22:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/11 07:22:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/11 07:22:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/09/11 07:22:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/09/11 07:22:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/09/11 07:22:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/11 07:22:06 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/09/11 07:22:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/09/11 07:22:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/09/11 07:22:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/09/08 15:39:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Particles
[2013/09/08 15:32:49 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Local\Farmington Tales
[2013/09/08 08:00:04 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ZSoft
[2013/09/08 08:00:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZSoft
[2013/09/08 08:00:02 | 000,000,000 | ---D | C] -- C:\Program Files\ZSoft
[2013/09/08 07:34:07 | 000,000,000 | ---D | C] -- C:\ProgramData\VS Revo Group
[2013/09/02 05:34:38 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\.rainlendar2
[2013/09/02 05:34:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rainlendar2
[2013/09/02 05:34:14 | 000,000,000 | ---D | C] -- C:\Program Files\Rainlendar2
[2013/08/29 07:57:15 | 000,000,000 | ---D | C] -- C:\ProgramData\{BDDB56DE-AE4E-48A2-B856-FB60C8498453}
[2013/08/23 08:31:59 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/08/23 08:23:37 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013/08/23 06:23:54 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\Desktop\IW BANK
[2013/08/21 06:32:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gmail Notifier
[2013/08/21 05:44:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013/08/21 05:43:57 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013/08/21 05:43:51 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013/08/21 05:43:51 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013/08/21 05:43:51 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013/08/21 05:43:43 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013/08/17 07:51:05 | 000,188,176 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\drivers\VBoxDrv.sys
[2013/08/17 07:51:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
[2013/08/17 07:51:03 | 000,094,480 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\drivers\VBoxUSBMon.sys
[2013/08/14 06:02:42 | 001,620,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2013/08/14 06:02:39 | 003,968,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013/08/14 06:02:39 | 003,913,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013/08/14 06:02:33 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2013/08/11 16:23:15 | 000,000,000 | R--D | C] -- C:\Users\Salvatore\Dropbox
[2013/08/11 16:21:50 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2013/08/11 16:21:16 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Talk
[2013/08/11 16:21:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Talk
[2013/08/11 16:19:23 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Dropbox
[2013/08/08 06:01:21 | 000,181,912 | ---- | C] (DEVGURU Co., LTD.(
www.devguru.co.kr)) -- C:\Windows\System32\drivers\ssudmdm.sys
[2013/08/08 06:01:21 | 000,084,248 | ---- | C] (DEVGURU Co., LTD.(
www.devguru.co.kr)) -- C:\Windows\System32\drivers\ssudbus.sys
[2013/08/08 05:56:38 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- C:\Windows\System32\dgderapi.dll
[2013/08/08 05:53:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2013/08/06 16:10:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uRexsoft
[2013/08/06 16:09:59 | 000,000,000 | ---D | C] -- C:\Program Files\uRexsoft
[2013/08/06 11:36:11 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\Local Settings
[2013/08/06 11:26:19 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\FILEminimizerPictures
[2013/08/05 20:25:45 | 000,000,000 | ---D | C] -- C:\db26031ce47636ea72f42d5e
[2013/08/05 20:25:21 | 000,023,872 | ---- | C] (IObit) -- C:\Windows\System32\RegistryDefragBootTime.exe
[2013/08/05 20:09:06 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\WinZipper
[2013/08/05 20:04:35 | 000,000,000 | ---D | C] -- C:\ProgramData\eSafe
[2013/08/05 20:02:24 | 000,000,000 | ---D | C] -- C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[2013/08/05 20:02:20 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Apple Computer
[2013/08/05 20:00:59 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2013/08/05 20:00:41 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\IObit
[2013/08/04 17:44:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Puzzle Expedition
[2013/08/04 17:44:40 | 000,000,000 | ---D | C] -- C:\Program Files\Puzzle Expedition
[2013/08/04 17:41:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2013/08/04 17:40:33 | 000,000,000 | ---D | C] -- C:\ProgramData\WinZip
[2013/08/04 17:40:26 | 000,000,000 | ---D | C] -- C:\Program Files\WinZip
[2013/08/04 14:55:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2013/08/04 08:20:21 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\Rovio
[2013/08/03 05:56:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/08/03 05:37:59 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013/08/02 12:59:12 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Roaming\TuneUp Software
[2013/08/02 12:59:03 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2013/08/02 12:58:54 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2013/08/02 12:58:54 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013/08/02 12:58:22 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\AppData\Local\FreemakeVideoConverter
[2013/07/31 09:48:13 | 000,000,000 | ---D | C] -- C:\Users\Salvatore\dwhelper
[1 C:\Users\Salvatore\Documents\*.tmp files -> C:\Users\Salvatore\Documents\*.tmp -> ]
========== Files - Modified Within 60 Days ========== [2013/09/27 16:01:00 | 000,000,978 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/27 15:50:00 | 000,001,176 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2170091305-4224216958-3418588652-1001UA.job
[2013/09/27 15:35:06 | 000,014,816 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/27 15:35:06 | 000,014,816 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/27 15:32:21 | 000,703,122 | ---- | M] () -- C:\Windows\System32\perfh010.dat
[2013/09/27 15:32:21 | 000,620,484 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/09/27 15:32:21 | 000,130,398 | ---- | M] () -- C:\Windows\System32\perfc010.dat
[2013/09/27 15:32:21 | 000,108,666 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/09/27 15:29:00 | 000,001,144 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/27 15:28:07 | 000,001,140 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/27 15:27:55 | 000,437,088 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/09/27 15:27:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/09/27 15:27:37 | 1609,424,896 | -HS- | M] () -- C:\hiberfil.sys
[2013/09/27 15:21:46 | 000,001,911 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2013/09/27 14:12:32 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/27 14:05:21 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/09/27 12:01:45 | 000,000,310 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013/09/27 11:42:48 | 000,002,290 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/09/26 05:50:00 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2170091305-4224216958-3418588652-1001Core.job
[2013/09/22 13:30:25 | 000,001,952 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
[2013/09/21 15:02:45 | 000,759,753 | ---- | M] () -- C:\Users\Salvatore\Desktop\richiesta pagamento pensione c-c banca.pdf
[2013/09/20 14:01:12 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/09/20 14:01:12 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/09/19 07:49:51 | 013,275,136 | ---- | M] () -- C:\Users\Salvatore\Desktop\sert.opd
[2013/09/19 07:44:38 | 000,591,203 | ---- | M] () -- C:\Users\Salvatore\Desktop\qwe_0003.jpg
[2013/09/19 07:44:37 | 000,877,010 | ---- | M] () -- C:\Users\Salvatore\Desktop\qwe_0001.jpg
[2013/09/19 07:44:37 | 000,674,362 | ---- | M] () -- C:\Users\Salvatore\Desktop\qwe_0002.jpg
[2013/09/11 08:03:23 | 000,043,469 | ---- | M] () -- C:\Users\Salvatore\Desktop\balotelli-kyenge-265663.jpg
[2013/09/08 15:43:29 | 000,000,915 | ---- | M] () -- C:\Users\Salvatore\Desktop\Farmington Tales - collegamento.lnk
[2013/09/08 08:00:04 | 000,001,111 | ---- | M] () -- C:\Users\Salvatore\Desktop\ZSoft Uninstaller.lnk
[2013/08/23 08:13:15 | 002,020,343 | ---- | M] () -- C:\Users\Salvatore\Desktop\ggggggggggggggggg.rar
[2013/08/22 16:06:55 | 000,001,202 | ---- | M] () -- C:\Users\Salvatore\Desktop\dwhelper - collegamento.lnk
[2013/08/21 05:43:47 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013/08/21 05:43:46 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013/08/21 05:43:46 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013/08/21 05:43:45 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2013/08/21 05:43:45 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2013/08/21 05:43:45 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013/08/18 16:41:41 | 000,118,607 | ---- | M] () -- C:\Users\Salvatore\Desktop\AP03_Banche(1).pdf
[2013/08/17 04:29:06 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013/08/11 16:22:18 | 000,001,057 | ---- | M] () -- C:\Users\Salvatore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/08/10 16:51:07 | 000,000,000 | -H-- | M] () -- C:\Users\Salvatore\Documents\Default.rdp
[2013/08/10 05:59:24 | 000,042,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013/08/10 05:58:21 | 000,493,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/08/10 05:58:09 | 002,876,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/08/10 05:58:09 | 000,039,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/08/10 05:58:06 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/08/10 05:58:06 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013/08/10 05:58:06 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013/08/10 05:58:05 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013/08/10 05:07:50 | 002,706,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/08/10 04:17:19 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013/08/08 03:03:07 | 002,348,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013/08/05 20:09:06 | 000,421,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcp100.dll
[2013/08/05 20:06:38 | 000,002,604 | ---- | M] () -- C:\Windows\System32\InstallUtil.InstallLog
[2013/08/05 03:56:47 | 000,133,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\ataport.sys
[2013/08/04 17:44:58 | 000,001,972 | ---- | M] () -- C:\Users\Salvatore\Desktop\Puzzle Expedition.lnk
[2013/08/04 17:41:47 | 000,001,811 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2013/08/03 05:38:46 | 000,000,175 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/08/03 05:38:46 | 000,000,175 | ---- | M] () -- C:\Windows\System32\drivers\aswSP.sys.sum
[2013/08/03 05:38:46 | 000,000,175 | ---- | M] () -- C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/08/03 05:38:32 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013/08/02 03:50:36 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2013/08/02 03:48:15 | 000,005,120 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/08/02 03:48:15 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/08/02 03:48:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/08/02 03:48:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/08/02 03:48:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/08/02 03:48:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/08/02 03:48:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/08/02 03:48:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/08/02 03:48:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/08/02 03:48:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/08/02 03:48:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/08/02 03:48:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/08/02 02:52:57 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2013/08/02 02:43:05 | 000,006,144 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/08/02 02:43:05 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/08/02 02:43:05 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/08/02 02:43:05 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[1 C:\Users\Salvatore\Documents\*.tmp files -> C:\Users\Salvatore\Documents\*.tmp -> ]
========== Files Created - No Company Name ========== [2013/09/27 15:27:39 | 000,437,088 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/09/27 15:21:46 | 000,001,911 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2013/09/27 14:12:32 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/27 11:37:36 | 000,002,290 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/09/27 10:56:13 | 000,001,451 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/09/27 10:56:13 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/09/22 13:30:25 | 000,001,952 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
[2013/09/21 15:02:45 | 000,759,753 | ---- | C] () -- C:\Users\Salvatore\Desktop\richiesta pagamento pensione c-c banca.pdf
[2013/09/19 07:44:37 | 000,674,362 | ---- | C] () -- C:\Users\Salvatore\Desktop\qwe_0002.jpg
[2013/09/19 07:44:37 | 000,591,203 | ---- | C] () -- C:\Users\Salvatore\Desktop\qwe_0003.jpg
[2013/09/19 07:44:36 | 000,877,010 | ---- | C] () -- C:\Users\Salvatore\Desktop\qwe_0001.jpg
[2013/09/19 07:42:24 | 013,275,136 | ---- | C] () -- C:\Users\Salvatore\Desktop\sert.opd
[2013/09/11 08:03:21 | 000,043,469 | ---- | C] () -- C:\Users\Salvatore\Desktop\balotelli-kyenge-265663.jpg
[2013/09/08 15:43:29 | 000,000,915 | ---- | C] () -- C:\Users\Salvatore\Desktop\Farmington Tales - collegamento.lnk
[2013/09/08 08:00:04 | 000,001,111 | ---- | C] () -- C:\Users\Salvatore\Desktop\ZSoft Uninstaller.lnk
[2013/08/23 08:13:14 | 002,020,343 | ---- | C] () -- C:\Users\Salvatore\Desktop\ggggggggggggggggg.rar
[2013/08/22 16:06:55 | 000,001,202 | ---- | C] () -- C:\Users\Salvatore\Desktop\dwhelper - collegamento.lnk
[2013/08/18 16:41:41 | 000,118,607 | ---- | C] () -- C:\Users\Salvatore\Desktop\AP03_Banche(1).pdf
[2013/08/11 16:22:18 | 000,001,057 | ---- | C] () -- C:\Users\Salvatore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/08/10 16:51:07 | 000,000,000 | -H-- | C] () -- C:\Users\Salvatore\Documents\Default.rdp
[2013/08/05 20:51:38 | 000,000,310 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013/08/04 17:44:58 | 000,001,972 | ---- | C] () -- C:\Users\Salvatore\Desktop\Puzzle Expedition.lnk
[2013/08/04 17:41:47 | 000,001,811 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2013/08/04 14:56:05 | 000,002,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/08/03 05:38:46 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/08/03 05:38:46 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswSP.sys.sum
[2013/08/03 05:38:46 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/05/18 12:12:30 | 002,888,384 | ---- | C] () -- C:\Windows\System32\pwNative.exe
[2013/05/18 12:12:29 | 000,015,576 | ---- | C] () -- C:\Windows\System32\pwdrvio.sys
[2013/05/18 12:12:01 | 000,010,200 | ---- | C] () -- C:\Windows\System32\pwdspio.sys
[2013/02/04 16:52:17 | 000,000,568 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012/09/10 07:27:26 | 000,000,008 | RHS- | C] () -- C:\Users\Salvatore\ntuser.pol
[2012/06/23 10:07:26 | 000,000,065 | ---- | C] () -- C:\Windows\FISHUI.INI
[2012/06/23 09:51:12 | 000,003,584 | ---- | C] () -- C:\Users\Salvatore\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/09 15:53:54 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2012/06/09 15:52:41 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/06/08 19:51:38 | 000,011,776 | ---- | C] () -- C:\Windows\System32\pmsbfn32.dll
[2012/06/08 19:50:20 | 000,000,412 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2012/06/08 19:41:23 | 000,003,584 | ---- | C] () -- C:\Windows\System32\CNCFLdNL.DLL
[2012/06/08 19:24:05 | 000,007,605 | ---- | C] () -- C:\Users\Salvatore\AppData\Local\resmon.resmoncfg
[2012/06/08 15:20:02 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/06/08 15:17:47 | 000,003,929 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2012/05/23 18:49:34 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/05/23 18:49:32 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2012/05/23 18:49:32 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2012/05/23 18:49:32 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2012/05/23 18:49:32 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
========== ZeroAccess Check ========== [2009/07/14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2012/10/27 09:02:28 | 000,000,000 | -HSD | M] -- C:\Users\Salvatore\AppData\Roaming\.#
[2013/06/12 13:44:16 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\.deskpdf
[2012/11/15 14:25:05 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\.minecraft
[2012/11/19 13:51:14 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\1morebee
[2012/12/04 19:25:52 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\AlawarEntertainment
[2013/01/03 09:24:30 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Amaranth Games
[2012/12/10 08:37:03 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Artogon
[2013/08/22 16:28:45 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Audacity
[2013/05/13 14:40:29 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Blue Tea Games
[2013/04/16 15:59:02 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Boomzap
[2012/06/13 10:34:26 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Canon
[2013/05/13 14:00:11 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\casualArts
[2013/01/04 16:14:13 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Chayowo Games
[2012/10/27 09:05:57 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\CianoDock
[2012/12/08 19:17:52 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\DAEMON Tools
[2013/09/27 12:53:05 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\DAEMON Tools Lite
[2013/05/01 14:53:47 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\DailyMagic
[2012/06/23 09:56:43 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\DataCast
[2013/09/27 15:28:43 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Dropbox
[2012/10/22 19:32:06 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\DVDVideoSoft
[2013/04/24 19:58:18 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\EleFun Games
[2013/04/06 15:05:11 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Elephant Games
[2012/12/03 11:50:30 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Enki Games
[2013/05/01 09:12:47 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\ERS G-Studio
[2013/04/19 14:22:50 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\ERS Game Studios
[2013/09/27 13:33:59 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\eUpdate
[2013/09/15 17:31:26 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Farm Mania 2.1
[2013/08/08 15:16:10 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\FILEminimizerPictures
[2013/04/06 06:17:21 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Free Audio Editor
[2013/01/26 12:31:27 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Free PDF to Word Converter
[2012/08/07 18:16:21 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\FreeAudioPack
[2013/06/02 07:45:21 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Friday's games
[2013/04/14 11:43:03 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Frogwares
[2012/12/31 13:42:39 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\GameMill Entertainment
[2013/05/01 06:26:30 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Games
[2013/03/19 10:23:55 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\GetRightToGo
[2013/05/13 14:48:40 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\HdO Adventure
[2013/03/15 07:26:30 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Import Audio from Video
[2013/08/08 13:02:04 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\IObit
[2012/11/11 18:24:19 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Jetbricks
[2013/02/05 19:11:21 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\MagicIndie
[2013/03/15 07:39:59 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\MP3Rocket
[2012/06/13 10:34:47 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\NewSoft
[2012/06/08 17:50:33 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Nitro PDF
[2013/06/07 09:04:08 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\OpenOffice.org
[2013/02/24 08:54:18 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Orneon
[2013/06/25 14:35:57 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\PowerISO
[2013/08/04 08:20:21 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Rovio
[2013/08/08 06:02:06 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Samsung
[2012/06/08 19:50:12 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\ScanSoft
[2012/11/09 14:17:47 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Simple Sudoku
[2012/12/02 20:41:26 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\ThreeDays2
[2013/02/06 11:11:00 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Thunderbird
[2013/01/04 15:52:51 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\TrickySoftware
[2013/08/02 12:59:12 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\TuneUp Software
[2013/09/01 08:50:56 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\UK's Kalender
[2013/09/27 16:08:53 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\uTorrent
[2013/05/01 08:52:56 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\VendelGAMES
[2013/06/26 18:29:34 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\VS Revo Group
[2013/03/18 08:01:23 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\Winyl
[2013/08/23 07:36:54 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\WinZipper
[2012/09/15 08:31:09 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\www.TheXSoft.com
[2012/10/25 15:07:08 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\XBMC
[2013/06/02 07:53:36 | 000,000,000 | ---D | M] -- C:\Users\Salvatore\AppData\Roaming\YoudaGames
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:373E1720
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:CC30FDA5
< End of report >