OTL logfile created on: 31/01/2014 20:56:18 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\colors\Downloads
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16476)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
1,96 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,17% Memory free
3,92 Gb Paging File | 2,51 Gb Available in Paging File | 63,93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149,88 Gb Total Space | 98,42 Gb Free Space | 65,67% Space Free | Partition Type: NTFS
Drive D: | 70,00 Gb Total Space | 69,91 Gb Free Space | 99,87% Space Free | Partition Type: NTFS
Computer Name: ALFA | User Name: colors | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ========== PRC - C:\Users\colors\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Windows\System32\escsvc.exe (Seiko Epson Corporation)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wlrmdr.exe (Microsoft Corporation)
========== Modules (No Company Name) ========== ========== Services (SafeList) ========== SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (IEEtwCollectorService) -- C:\Windows\System32\IEEtwCollector.exe (Microsoft Corporation)
SRV - (EpsonCustomerResearchParticipation) -- C:\Program Files\epson\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (EPSON_PM_RPCV4_05) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE (SEIKO EPSON CORPORATION)
SRV - (EpsonScanSvc) -- C:\Windows\System32\escsvc.exe (Seiko Epson Corporation)
SRV - (VmbService) -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (vodafone_K3805-z_cdc_ecm) -- C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) -- C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) -- C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Serial) -- C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.comIE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {462be121-2b54-4218-bf00-b9bf8135b23f} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>;
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>;
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://msn.it/IE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://it.msn.com/IE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = it-IT
IE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.comIE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.comIE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\..\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}: "URL" =
http://search.conduit.com/Results.aspx? ... BE36486&q={searchTerms}&SSPV=
IE - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
FF - prefs.js..browser.search.selectedEngine: "StartWeb"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\colors\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\e-webprint@epson.com: C:\Program Files\Epson Software\E-Web Print\Firefox Add-on [2013/11/24 10:20:30 | 000,000,000 | ---D | M]
[2013/12/20 16:26:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\colors\AppData\Roaming\mozilla\Extensions
[2013/12/20 16:26:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\colors\AppData\Roaming\mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
[2014/01/31 20:45:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\colors\AppData\Roaming\mozilla\Firefox\Profiles\954j3pqg.default\extensions
[2014/01/31 16:07:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\colors\AppData\Roaming\mozilla\Firefox\Profiles\954j3pqg.default\extensions\staged
[2014/01/31 16:07:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\colors\AppData\Roaming\mozilla\Firefox\Profiles954j3pqg.default\extensions
[2014/01/31 16:07:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\colors\AppData\Roaming\mozilla\Firefox\Profiles954j3pqg.default\extensions\staged
[2012/10/11 12:56:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
http://www.google.com/CHR - Extension: Music Box Toolbar = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaiihjniipljfegaknmbkneamnoajd\29.1_0\
CHR - Extension: Documenti Google = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0\
CHR - Extension: Ricerca Google = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock Premium = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj\2.6.4.3_0\
CHR - Extension: Google Wallet = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\
CHR - Extension: Gmail = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Music Box Toolbar = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaiihjniipljfegaknmbkneamnoajd\29.1_0\
CHR - Extension: Documenti Google = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0\
CHR - Extension: Ricerca Google = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock Premium = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj\2.6.4.3_0\
CHR - Extension: Google Wallet = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\
CHR - Extension: Gmail = C:\Users\colors\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EzPrint] "C:\Program Files\Lexmark 5400 Series\ezprint.exe" File not found
O4 - HKLM..\Run: [Lexmark 5400 Series Fax Server] "C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s File not found
O4 - HKLM..\Run: [LXCTCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16 File not found
O4 - HKLM..\Run: [lxctmon.exe] "C:\Program Files\Lexmark 5400 Series\lxctmon.exe" File not found
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-4105648700-3277945650-2585042511-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE0F13AD-31AC-4B99-8E47-4555654FCCCD}: DhcpNameServer = 192.168.1.1
O20 - AppInit_DLLs: (C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{60dab53a-1258-11e2-8a64-001377bff108}\Shell - "" = AutoRun
O33 - MountPoints2\{60dab53a-1258-11e2-8a64-001377bff108}\Shell\AutoRun\command - "" = G:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{60dab5fc-1258-11e2-8a64-001377bff108}\Shell - "" = AutoRun
O33 - MountPoints2\{60dab5fc-1258-11e2-8a64-001377bff108}\Shell\AutoRun\command - "" = G:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{60dab6cb-1258-11e2-8a64-001377bff108}\Shell - "" = AutoRun
O33 - MountPoints2\{60dab6cb-1258-11e2-8a64-001377bff108}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{cbe841a4-3d2f-11e3-bf41-001377bff108}\Shell - "" = AutoRun
O33 - MountPoints2\{cbe841a4-3d2f-11e3-bf41-001377bff108}\Shell\AutoRun\command - "" = F:\CMADownloader.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 60 Days ========== [2014/01/31 20:43:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2014/01/31 20:42:54 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Roaming\Uniblue
[2014/01/31 20:42:54 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2014/01/31 20:42:38 | 000,000,000 | ---D | C] -- C:\Users\colors\Documents\Mobogenie
[2014/01/31 20:42:38 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Local\Mobogenie
[2014/01/31 20:41:59 | 000,000,000 | ---D | C] -- C:\Program Files\Mobogenie
[2014/01/31 20:41:08 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
[2014/01/31 16:08:19 | 000,000,000 | ---D | C] -- C:\Program Files\SupTab
[2014/01/31 16:08:19 | 000,000,000 | ---D | C] -- C:\ProgramData\IePluginService
[2014/01/31 16:08:14 | 000,000,000 | ---D | C] -- C:\ProgramData\WPM
[2014/01/31 15:55:21 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2014/01/24 21:32:25 | 000,000,000 | ---D | C] -- C:\Program Files\BearShare Applications
[2014/01/20 13:36:08 | 000,000,000 | ---D | C] -- C:\Users\colors\Desktop\matrimonio maci roby
[2014/01/17 20:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014/01/17 13:06:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2014/01/17 13:05:54 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2014/01/17 13:05:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/01/17 13:05:43 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2014/01/17 13:05:43 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2014/01/17 13:05:43 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2014/01/17 13:05:31 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2014/01/17 12:41:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2014/01/17 12:34:19 | 000,692,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014/01/17 12:34:19 | 000,071,048 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/01/17 12:25:27 | 000,000,000 | -HSD | C] -- C:\Windows\System32\AI_RecycleBin
[2014/01/16 13:31:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/01/16 12:40:38 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/01/15 07:31:15 | 002,349,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2014/01/15 07:31:14 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
[2014/01/15 07:31:14 | 000,240,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2014/01/15 07:31:14 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys
[2014/01/12 17:21:05 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rdpvideominiport.sys
[2014/01/12 17:21:05 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2014/01/12 17:21:05 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RdpGroupPolicyExtension.dll
[2014/01/12 17:21:05 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2014/01/12 17:21:04 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\TsUsbFlt.sys
[2014/01/12 17:21:03 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprt.exe
[2014/01/12 17:21:03 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
[2014/01/12 17:21:03 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpudd.dll
[2014/01/12 17:21:03 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpendp_winip.dll
[2014/01/12 17:21:03 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWbPrxy.exe
[2014/01/12 17:21:03 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsRdpWebAccess.dll
[2014/01/12 17:21:03 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll
[2014/01/12 17:21:03 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbGDCoInstaller.dll
[2014/01/12 17:21:03 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprtPS.dll
[2014/01/12 17:21:02 | 002,739,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2014/01/12 17:20:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2014/01/12 17:15:47 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014/01/12 17:13:45 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2014/01/12 17:13:44 | 000,000,000 | ---D | C] -- C:\Intel
[2014/01/12 17:11:43 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2014/01/11 11:39:24 | 000,000,000 | ---D | C] -- C:\hijackthis
[2014/01/09 13:57:00 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Roaming\AVG
[2014/01/09 13:56:03 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG
[2014/01/09 13:56:00 | 000,000,000 | -HSD | C] -- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
[2014/01/03 21:55:18 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Local\Mozilla
[2014/01/03 21:55:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2014/01/02 10:51:42 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Local\VirtualStore
[2013/12/24 22:43:39 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Roaming\driver
[2013/12/24 22:37:56 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Roaming\Carambis
[2013/12/20 12:31:50 | 000,000,000 | ---D | C] -- C:\Users\colors\.android
[2013/12/20 12:31:48 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Local\cache
[2013/12/17 13:26:50 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Roaming\AVAST Software
[2013/12/17 13:06:58 | 000,000,000 | ---D | C] -- C:\Program Files\Amazon
[2013/12/15 13:00:58 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/12/15 13:00:58 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013/12/15 13:00:57 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/12/15 13:00:56 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013/12/15 13:00:56 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/12/15 13:00:56 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013/12/15 13:00:56 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013/12/15 13:00:56 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
[2013/12/15 13:00:55 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2013/12/15 13:00:55 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/12/15 13:00:55 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
[2013/12/15 13:00:54 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
[2013/12/15 13:00:52 | 001,928,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/12/15 13:00:50 | 004,243,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/12/14 13:02:06 | 000,646,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/12/14 13:02:06 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll
[2013/12/14 13:02:05 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsIntl.dll
[2013/12/14 13:02:05 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013/12/14 13:02:05 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013/12/14 13:02:05 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013/12/14 13:02:05 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
[2013/12/14 13:02:04 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2013/12/14 13:02:04 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013/12/14 13:02:04 | 000,523,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/12/14 13:02:04 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013/12/14 13:02:04 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013/12/14 13:02:04 | 000,244,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013/12/14 13:02:04 | 000,238,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2013/12/14 13:02:04 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/12/14 13:02:04 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013/12/14 13:02:04 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013/12/14 13:02:04 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013/12/14 13:02:04 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013/12/14 13:02:04 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013/12/14 13:02:03 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013/12/14 13:02:03 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013/12/14 13:02:03 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013/12/14 13:02:03 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013/12/14 13:02:03 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MshtmlDac.dll
[2013/12/14 13:02:03 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013/12/14 13:02:03 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2013/12/14 13:02:03 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013/12/14 13:02:03 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013/12/12 18:18:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/12/11 13:01:55 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2013/12/11 07:30:09 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cscript.exe
[2013/12/11 07:30:08 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2013/12/11 07:30:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2013/12/11 07:29:56 | 000,177,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\portcls.sys
[2013/12/11 07:29:56 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\drmk.sys
[2013/12/10 11:57:07 | 000,000,000 | ---D | C] -- C:\Users\colors\AppData\Roaming\Google
========== Files - Modified Within 60 Days ========== [2014/01/31 21:00:00 | 000,000,268 | ---- | M] () -- C:\Windows\tasks\SpeedUpMyPC Maintenance.job
[2014/01/31 20:56:20 | 000,010,832 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/01/31 20:56:20 | 000,010,832 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/01/31 20:51:00 | 000,000,978 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/01/31 20:48:58 | 000,001,134 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/01/31 20:48:45 | 000,000,262 | ---- | M] () -- C:\Windows\tasks\SpeedUpMyPC Startup.job
[2014/01/31 20:48:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/01/31 20:48:16 | 1579,634,688 | -HS- | M] () -- C:\hiberfil.sys
[2014/01/31 20:41:24 | 000,002,348 | ---- | M] () -- C:\Windows\System32\InstallUtil.InstallLog
[2014/01/31 20:21:07 | 000,000,936 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/01/31 20:15:00 | 000,001,138 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/01/31 18:41:07 | 000,741,518 | ---- | M] () -- C:\Windows\System32\perfh010.dat
[2014/01/31 18:41:07 | 000,654,346 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/01/31 18:41:07 | 000,147,540 | ---- | M] () -- C:\Windows\System32\perfc010.dat
[2014/01/31 18:41:07 | 000,122,218 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/01/31 17:08:02 | 000,000,028 | ---- | M] () -- C:\Users\colors\AppData\Roaming\mbam.context.scan
[2014/01/31 16:30:37 | 000,298,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/01/31 08:53:31 | 000,000,625 | ---- | M] () -- C:\Users\colors\Desktop\Gmail l'email di Google.website
[2014/01/31 07:39:15 | 000,000,506 | ---- | M] () -- C:\Users\colors\Desktop\Virgilio Mail.website
[2014/01/24 14:14:58 | 000,034,133 | ---- | M] () -- C:\Users\colors\GLORIA DNA.odt
[2014/01/22 11:07:32 | 000,755,713 | ---- | M] () -- C:\Users\colors\certificato.png
[2014/01/17 17:19:19 | 000,001,882 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2014/01/17 13:05:34 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2014/01/17 13:05:33 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2014/01/17 13:05:33 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2014/01/17 13:05:33 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2014/01/17 12:41:56 | 000,001,956 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014/01/17 12:34:19 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014/01/17 12:34:19 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/01/11 20:04:21 | 000,023,335 | ---- | M] () -- C:\Users\colors\AppData\Roaming\UserTile.png
[2014/01/01 11:50:37 | 000,000,627 | ---- | M] () -- C:\Users\colors\Desktop\curriculum (2).lnk
[2013/12/21 11:15:07 | 000,135,648 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2013/12/21 11:15:07 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2013/12/21 11:15:07 | 000,069,240 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avnetflt.sys
[2013/12/21 11:15:07 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2013/12/14 13:02:06 | 000,646,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/12/14 13:02:06 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll
[2013/12/14 13:02:05 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsIntl.dll
[2013/12/14 13:02:05 | 000,182,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013/12/14 13:02:05 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013/12/14 13:02:05 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013/12/14 13:02:05 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
[2013/12/14 13:02:04 | 001,051,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2013/12/14 13:02:04 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013/12/14 13:02:04 | 000,523,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/12/14 13:02:04 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013/12/14 13:02:04 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013/12/14 13:02:04 | 000,244,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013/12/14 13:02:04 | 000,238,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2013/12/14 13:02:04 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/12/14 13:02:04 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013/12/14 13:02:04 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013/12/14 13:02:04 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013/12/14 13:02:04 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013/12/14 13:02:04 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013/12/14 13:02:04 | 000,016,284 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2013/12/14 13:02:03 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013/12/14 13:02:03 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013/12/14 13:02:03 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013/12/14 13:02:03 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013/12/14 13:02:03 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MshtmlDac.dll
[2013/12/14 13:02:03 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013/12/14 13:02:03 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2013/12/14 13:02:03 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013/12/14 13:02:03 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013/12/12 18:18:20 | 000,002,137 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
========== Files Created - No Company Name ========== [2014/01/31 20:43:46 | 000,000,268 | ---- | C] () -- C:\Windows\tasks\SpeedUpMyPC Maintenance.job
[2014/01/31 20:43:45 | 000,000,262 | ---- | C] () -- C:\Windows\tasks\SpeedUpMyPC Startup.job
[2014/01/24 14:14:55 | 000,034,133 | ---- | C] () -- C:\Users\colors\GLORIA DNA.odt
[2014/01/22 11:07:31 | 000,755,713 | ---- | C] () -- C:\Users\colors\certificato.png
[2014/01/20 18:27:19 | 000,000,506 | ---- | C] () -- C:\Users\colors\Desktop\Virgilio Mail.website
[2014/01/17 20:29:46 | 000,000,936 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/01/17 12:41:56 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2014/01/17 12:41:56 | 000,001,956 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014/01/17 12:34:20 | 000,000,978 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/01/11 20:04:21 | 000,023,335 | ---- | C] () -- C:\Users\colors\AppData\Roaming\UserTile.png
[2014/01/01 11:50:37 | 000,000,627 | ---- | C] () -- C:\Users\colors\Desktop\curriculum (2).lnk
[2013/12/14 13:02:04 | 000,016,284 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2013/12/12 18:18:20 | 000,002,137 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2013/10/04 18:08:47 | 000,001,664 | ---- | C] () -- C:\Windows\System32\ASOROSet.bin
[2013/07/20 16:51:34 | 000,000,093 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2013/03/15 21:22:23 | 000,280,227 | ---- | C] () -- C:\Users\colors\PR.odp
[2013/03/05 11:01:50 | 000,131,447 | ---- | C] () -- C:\Users\colors\cud 2013.xps
[2013/02/27 12:57:50 | 000,000,028 | ---- | C] () -- C:\Users\colors\AppData\Roaming\mbam.context.scan
[2013/02/25 17:32:57 | 000,000,270 | RHS- | C] () -- C:\Users\colors\ntuser.pol
[2013/01/22 11:51:38 | 000,020,405 | ---- | C] () -- C:\Users\colors\ISCRIZIONE SCUOLA NIK.xps
[2012/12/03 10:00:20 | 000,017,136 | ---- | C] () -- C:\Windows\System32\sasnative32.exe
[2012/10/11 13:57:32 | 000,032,768 | ---- | C] () -- C:\Windows\System32\LXCTFXPU.DLL
[2012/10/11 12:27:13 | 000,000,048 | ---- | C] () -- C:\Windows\WinInit.Ini
[2012/10/11 08:38:08 | 000,045,056 | ---- | C] () -- C:\Windows\System32\lxctpmon.dll
[2011/04/18 14:39:56 | 000,226,364 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
========== ZeroAccess Check ========== [2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2012/10/11 13:59:51 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\5400 Series
[2012/12/08 12:16:11 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\APP_NAME_NON_STRING
[2013/12/17 13:26:50 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\AVAST Software
[2014/01/09 13:57:00 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\AVG
[2013/12/20 16:26:45 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\Canneverbe Limited
[2013/12/24 22:37:56 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\Carambis
[2013/12/24 22:43:39 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\driver
[2013/12/20 16:26:45 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\Epson
[2014/01/31 20:41:08 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
[2012/12/19 16:14:10 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\MusicNet
[2013/12/20 16:24:50 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\OpenOffice.org
[2012/12/08 12:20:19 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\PDF Architect
[2014/01/08 09:42:45 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\TFP
[2012/12/08 12:16:40 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\TuneUp Software
[2014/01/31 20:45:41 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\Uniblue
[2014/01/17 20:34:16 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\uTorrent
[2013/12/20 16:24:56 | 000,000,000 | ---D | M] -- C:\Users\colors\AppData\Roaming\Vodafone
[2012/10/11 14:12:40 | 000,000,000 | ---D | M] -- C:\Users\SYSTEM\AppData\Roaming\5400 Series
[2012/10/11 13:58:06 | 000,000,000 | ---D | M] -- C:\Users\SYSTEM\AppData\Roaming\Coverpgs
========== Purity Check ========== < End of report >