eccoli:
OTL logfile created on: 06/07/2016 4.58.44 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Boschetti\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
1,99 Gb Total Physical Memory | 1,42 Gb Available Physical Memory | 71,23% Memory free
3,84 Gb Paging File | 3,38 Gb Available in Paging File | 88,15% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 298,08 Gb Total Space | 271,00 Gb Free Space | 90,92% Space Free | Partition Type: NTFS
Drive E: | 980,72 Mb Total Space | 782,39 Mb Free Space | 79,78% Space Free | Partition Type: FAT
Computer Name: BORIAN-DE10A491 | User Name: Boschetti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Boschetti\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programmi\AVAST Software\Avast\avastui.exe (AVAST Software)
PRC - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Programmi\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Programmi\File comuni\Java\Java Update\jusched.exe (Oracle Corporation)
PRC - C:\Programmi\Nitro\Reader 3\NitroPDFReaderDriverService3.exe (Nitro PDF Software)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATILFE.EXE (SEIKO EPSON CORPORATION)
PRC - C:\WINDOWS\system32\escsvc.exe (Seiko Epson Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ========== MOD - C:\Programmi\AVAST Software\Avast\defs\16070501\algo.dll ()
MOD - C:\Programmi\AVAST Software\Avast\defs\16070401\algo.dll ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\winffi.wininet._winffi_wininet.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\winffi.winerror._winffi_winerror.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32com.shell.shell.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\winffi.kernel32._winffi_kernel32.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\tornado.speedups.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\PyQt5.QtWidgets.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\PyQt5.QtWebKit.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\PyQt5.QtGui.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\PyQt5.QtNetwork.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\PyQt5.QtPrintSupport.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\PyQt5.QtCore.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\psutil._psutil_windows.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\dropbox_sqlite_ext.dll ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\fastpath.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\cpuid.compiled._cpuid.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\breakpad.client.windows.handler.pyd ()
MOD - C:\Programmi\AVAST Software\Avast\libcef.dll ()
MOD - C:\Programmi\AVAST Software\Avast\ffl2.dll ()
MOD - C:\Programmi\AVAST Software\Avast\browser_pass.dll ()
MOD - C:\Programmi\AVAST Software\Avast\JsonRpcServer.dll ()
MOD - C:\Programmi\AVAST Software\Avast\log.dll ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\librsync.dll ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\winxpgui.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32security.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32service.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32process.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32ts.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32profile.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32gui.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32file.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32print.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32pipe.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32api.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32evtlog.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32event.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\win32clipboard.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\mmapfile.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\_cffi_backend.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\sip.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\jpegtran.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\faulthandler.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\unicodedata.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\_elementtree.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\_ctypes.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\_multiprocessing.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\pythoncom27.dll ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\pyexpat.pyd ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\pywintypes27.dll ()
MOD - C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\select.pyd ()
MOD - C:\Programmi\WinRAR\RarExt.dll ()
MOD - C:\Programmi\FileZilla FTP Client\fzshellext.dll ()
========== Services (SafeList) ========== SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (avast! Antivirus) -- C:\Programmi\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (Sony SCSI Helper Service) -- C:\Programmi\File comuni\Sony Shared\Fsk\SonySCSIHelperService.exe (Sony Corporation)
SRV - (NitroReaderDriverReadSpool3) -- C:\Programmi\Nitro\Reader 3\NitroPDFReaderDriverService3.exe (Nitro PDF Software)
SRV - (Apple Mobile Device) -- C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SkypeUpdate) -- C:\Programmi\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (EpsonScanSvc) -- C:\WINDOWS\system32\escsvc.exe (Seiko Epson Corporation)
========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found
DRV - (StarOpen) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (MBAMSwissArmy) -- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (cpuz134) -- C:\DOCUME~1\BOSCHE~1\IMPOST~1\Temp\cpuz134\cpuz134_x32.sys File not found
DRV - (Changer) -- File not found
DRV - (aswKbd) -- C:\WINDOWS\system32\drivers\aswKbd.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\system32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) -- C:\WINDOWS\System32\drivers\aswVmm.sys (AVAST Software)
DRV - (aswStmXP) -- C:\WINDOWS\system32\drivers\aswStmXP.sys (AVAST Software)
DRV - (aswMonFlt) -- C:\WINDOWS\system32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswTdi) -- C:\WINDOWS\system32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\system32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswRvrt) -- C:\WINDOWS\System32\drivers\aswRvrt.sys (AVAST Software)
DRV - (aswHwid) -- C:\WINDOWS\system32\drivers\aswHwid.sys (AVAST Software)
DRV - (aswSnx) -- C:\WINDOWS\system32\drivers\aswSnx.sys (AVAST Software)
DRV - (RTL8187B) -- C:\WINDOWS\system32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (PAC207) -- C:\WINDOWS\system32\drivers\PFC027.SYS (PixArt Imaging Inc.)
DRV - (Afc) -- C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (APL531) -- C:\WINDOWS\system32\drivers\ov550i.sys (Omnivision Technologies, Inc.)
DRV - (USBCCID) -- C:\WINDOWS\system32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (fa120) -- C:\WINDOWS\system32\drivers\fa120.sys (NETGEAR Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.comIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.comIE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.bing.comIE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.comIE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\..\SearchScopes,DefaultScope = {01D6959E-F7AA-4CFC-B57C-ED238FF4F02A}
IE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\..\SearchScopes\{01D6959E-F7AA-4CFC-B57C-ED238FF4F02A}: "URL" =
http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b2ie7
IE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\..\SearchScopes\{1E7F3124-669D-4054-B9A5-A980007834D4}: "URL" =
http://ricerca.virgilio.it/ricerca?qs={searchTerms}&f=ie8vs
IE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\..\SearchScopes\{2052BCF8-95DE-4E12-95D3-6D50A585DF4F}: "URL" =
http://it.wikipedia.org/w/index.php?tit ... ca&search={searchTerms}
IE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\..\SearchScopes\{2ACD218D-7F8A-4DF1-84D9-6AEF9D25C4A5}: "URL" =
http://www.google.com/search?hl=en&q={searchTerms}&rlz=1I7ADFA_it
IE - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_22_0_0_192.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programmi\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.51.2: C:\Programmi\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.51.2: C:\Programmi\Java\jre1.8.0_51\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programmi\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Programmi\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Programmi\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Programmi\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programmi\Google\Update\1.3.30.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programmi\Google\Update\1.3.30.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmi\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Programmi\AVAST Software\Avast\WebRep\FF [2016/06/10 10.53.16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\sp@avast.com: C:\Programmi\AVAST Software\Avast\SafePrice\FF [2016/06/10 10.53.16 | 000,000,000 | ---D | M]
[2016/08/22 13.46.17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Boschetti\Dati applicazioni\Mozilla\Extensions
[2013/02/15 10.57.43 | 000,000,000 | ---D | M] (SpecialSavings) -- C:\Documents and Settings\Boschetti\Dati applicazioni\Mozilla\Extensions\SpecialSavings@SpecialSavings.com
[2014/09/17 20.37.25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Boschetti\Dati applicazioni\Mozilla\Firefox\Profiles\extensions
[2013/01/30 20.27.42 | 000,205,094 | ---- | M] () (No name found) -- C:\Documents and Settings\Boschetti\Dati applicazioni\Mozilla\Firefox\Profiles\extensions\clickmoviedownloader@clickmoviedownloader.com.xpi
========== Chrome ========== CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij\0.0.0.26_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\8.3.0.9150_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\mmeljkaonnbjgofmihnbimepcaiblkbi\1.0.0_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\
CHR - Extension: No name found = C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
O1 HOSTS File: ([2004/08/19 14.00.00 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.8.0_51\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmi\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre1.8.0_51\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [AvastUI.exe] C:\Programmi\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmi\File comuni\Java\Java Update\jusched.exe (Oracle Corporation)
O4 - HKU\S-1-5-21-1757981266-343818398-1417001333-1003..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-1757981266-343818398-1417001333-1003..\Run: [SpybotPostWindows10UpgradeReInstall] C:\Programmi\File comuni\AV\Spybot - Search and Destroy\Test.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Boschetti\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk = C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1757981266-343818398-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{14BA00A3-19E7-4EEC-9A67-C0587A5D39E2}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B9FC8E55-C581-4A25-87C9-9ACD141E8B1E}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programmi\File comuni\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programmi\File comuni\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/20 16.03.53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 60 Days ========== [2016/08/22 12.28.30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
[2016/07/06 04.57.46 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Boschetti\Desktop\OTL.exe
[2016/07/05 06.26.05 | 001,740,288 | ---- | C] (Farbar) -- C:\Documents and Settings\Boschetti\Desktop\FRST.exe
[2016/07/04 07.05.22 | 000,000,000 | ---D | C] -- C:\FRST
[2016/07/03 10.59.29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\eMule
[2016/07/03 10.59.28 | 000,000,000 | ---D | C] -- C:\Programmi\eMule
[2016/07/03 10.46.29 | 000,000,000 | ---D | C] -- C:\Programmi\File comuni\Designer
[2016/07/03 10.12.06 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Boschetti\Recent
[2016/07/03 09.03.16 | 000,821,920 | ---- | C] (Safer-Networking Ltd. ) -- C:\Documents and Settings\All Users\Desktop\Post Win10 Spybot-install.exe
[2016/07/03 09.03.16 | 000,000,000 | ---D | C] -- C:\Programmi\File comuni\AV
[2016/07/03 09.01.16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
[2016/07/03 09.01.12 | 000,000,000 | ---D | C] -- C:\Programmi\Spybot - Search & Destroy 2
[2016/07/03 08.06.04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boschetti\Menu Avvio\Programmi\Dropbox
[2016/06/23 20.44.24 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Boschetti\Documenti\Immagini
[2016/06/10 11.00.13 | 000,035,096 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswKbd.sys
[2016/06/10 10.54.54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boschetti\Dati applicazioni\AVAST Software
[2016/06/10 10.54.47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\AVAST Software
[2016/06/10 10.53.35 | 000,187,208 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswStmXP.sys
[2016/06/10 10.53.35 | 000,067,216 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2016/06/10 10.53.34 | 000,449,640 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2016/06/10 10.53.34 | 000,221,368 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2016/06/10 10.53.34 | 000,058,776 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2016/06/10 10.53.33 | 000,091,168 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2016/06/10 10.53.33 | 000,032,792 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswHwid.sys
[2016/06/10 10.53.32 | 000,064,272 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2016/06/10 10.53.31 | 000,815,792 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2016/06/10 10.53.17 | 000,334,280 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2016/06/10 10.53.10 | 000,052,184 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2016/06/10 10.50.40 | 000,000,000 | ---D | C] -- C:\Programmi\AVAST Software
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 60 Days ========== [2016/08/24 15.51.31 | 000,000,442 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{FBC4A5A9-88F4-4BB4-A6C5-8CF614196E17}.job
[2016/08/22 13.42.42 | 000,796,352 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2016/08/22 13.42.42 | 000,142,528 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2016/08/22 13.41.29 | 009,717,952 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2016/07/06 05.02.53 | 000,001,216 | ---- | M] () -- C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-1757981266-343818398-1417001333-1003UA.job
[2016/07/06 04.55.24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Boschetti\Desktop\OTL.exe
[2016/07/06 04.47.04 | 000,001,126 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2016/07/06 04.47.04 | 000,000,362 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2016/07/06 04.47.03 | 000,000,478 | ---- | M] () -- C:\WINDOWS\tasks\SafeZone scheduled Autoupdate 1465549232.job
[2016/07/06 04.47.02 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2016/07/06 04.47.02 | 000,000,230 | ---- | M] () -- C:\WINDOWS\tasks\Notifica di interruzione del servizio per Microsoft Windows XP - Accesso.job
[2016/07/06 04.45.39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2016/07/05 06.41.00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2016/07/05 06.30.20 | 000,001,130 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2016/07/05 06.25.00 | 000,000,917 | ---- | M] () -- C:\WINDOWS\tasks\EPSON XP-312 313 315 Series Update {4DC280AD-3322-4B9E-A687-45D116AFEAF5}.job
[2016/07/05 06.25.00 | 000,000,731 | ---- | M] () -- C:\WINDOWS\tasks\EPSON XP-312 313 315 Series Invitation {4DC280AD-3322-4B9E-A687-45D116AFEAF5}.job
[2016/07/04 07.11.00 | 000,001,026 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1757981266-343818398-1417001333-1003UA.job
[2016/07/04 06.56.14 | 000,144,424 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2016/07/04 06.56.06 | 001,740,288 | ---- | M] (Farbar) -- C:\Documents and Settings\Boschetti\Desktop\FRST.exe
[2016/07/03 10.59.33 | 000,000,624 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\eMule.lnk
[2016/07/03 10.51.08 | 000,002,517 | ---- | M] () -- C:\Documents and Settings\Boschetti\Desktop\Microsoft Word.lnk
[2016/07/03 10.51.03 | 000,002,489 | ---- | M] () -- C:\Documents and Settings\Boschetti\Desktop\Microsoft Excel.lnk
[2016/07/03 10.47.00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2016/07/03 10.46.46 | 000,001,744 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Microsoft Office.lnk
[2016/07/03 09.51.25 | 000,000,628 | ---- | M] () -- C:\WINDOWS\tasks\Boschetti Local Autobackup.job
[2016/07/03 09.51.25 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\Boschetti NBAgent.job
[2016/07/03 09.51.20 | 000,000,175 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2016/07/03 09.45.27 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2016/07/03 08.07.07 | 000,001,177 | ---- | M] () -- C:\Documents and Settings\Boschetti\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk
[2016/06/27 20.02.00 | 000,001,164 | ---- | M] () -- C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-1757981266-343818398-1417001333-1003Core.job
[2016/06/23 16.11.00 | 000,001,004 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1757981266-343818398-1417001333-1003Core.job
[2016/06/23 12.54.56 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\last.dump
[2016/06/10 11.00.10 | 000,035,096 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswKbd.sys
[2016/06/10 10.54.47 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avast Free Antivirus.lnk
[2016/06/10 10.53.15 | 000,449,640 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2016/06/10 10.53.15 | 000,221,368 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2016/06/10 10.53.15 | 000,187,208 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswStmXP.sys
[2016/06/10 10.53.15 | 000,091,168 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2016/06/10 10.53.15 | 000,067,216 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2016/06/10 10.53.15 | 000,064,272 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2016/06/10 10.53.15 | 000,058,776 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2016/06/10 10.53.15 | 000,032,792 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswHwid.sys
[2016/06/10 10.53.10 | 000,334,280 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2016/06/10 10.53.10 | 000,052,184 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2016/06/10 10.53.06 | 000,815,792 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2016/06/08 15.00.00 | 000,000,224 | ---- | M] () -- C:\WINDOWS\tasks\Notifica di interruzione del servizio per Microsoft Windows XP - Mensile.job
[2016/06/06 09.54.00 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2016/07/03 10.59.33 | 000,000,624 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\eMule.lnk
[2016/07/03 10.46.46 | 000,001,744 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Microsoft Office.lnk
[2016/07/03 09.26.58 | 000,000,175 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2016/07/03 08.07.07 | 000,001,177 | ---- | C] () -- C:\Documents and Settings\Boschetti\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk
[2016/06/23 12.54.56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\last.dump
[2016/06/10 11.00.43 | 000,000,478 | ---- | C] () -- C:\WINDOWS\tasks\SafeZone scheduled Autoupdate 1465549232.job
[2016/06/10 10.54.47 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avast Free Antivirus.lnk
[2016/06/10 10.53.40 | 000,000,362 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2015/10/29 10.45.40 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI
[2015/03/09 16.23.34 | 000,000,424 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2015/02/02 21.29.24 | 000,268,744 | ---- | C] () -- C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
[2014/10/24 09.36.38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
[2014/09/17 20.40.20 | 000,001,664 | ---- | C] () -- C:\Documents and Settings\Boschetti\${LOGFILE}
[2013/02/21 20.33.09 | 000,126,254 | ---- | C] () -- C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-S-1-5-21-1757981266-343818398-1417001333-1003-0.dat
[2013/02/21 20.33.08 | 000,126,254 | ---- | C] () -- C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-System.dat
[2010/08/14 17.18.34 | 000,000,138 | ---- | C] () -- C:\Documents and Settings\Boschetti\Impostazioni locali\Dati applicazioni\fusioncache.dat
========== ZeroAccess Check ========== [2010/05/20 18.35.31 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2010/03/10 06.41.31 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 12.51.43 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 19.13.58 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2013/04/17 19.25.31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2016/06/10 11.00.10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\AVAST Software
[2013/01/21 18.57.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\AVG January 2013 Campaign
[2010/05/20 18.38.23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Canneverbe Limited
[2012/04/06 10.47.06 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Common Files
[2015/06/13 10.51.02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Dropbox
[2016/07/20 11.54.47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Epson
[2013/09/18 17.37.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\FileOpen
[2013/04/03 22.27.55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\InstallMate
[2014/02/12 13.48.55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\kinoma
[2013/09/18 17.37.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Nitro
[2015/09/16 10.02.22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Oracle
[2011/12/02 22.00.10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\OviInstallerCache
[2013/01/09 18.17.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\PopCap Games
[2012/06/24 18.16.30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\tmp
[2014/10/23 17.31.23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\UDL
[2015/07/29 14.26.06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\AISoftware
[2016/06/10 10.54.54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\AVAST Software
[2010/05/20 18.38.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\Canneverbe Limited
[2013/09/18 17.36.44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\Downloaded Installations
[2016/07/03 08.06.25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\Dropbox
[2014/08/26 16.25.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\EncryptStick
[2016/07/20 11.54.46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\EPSON
[2013/09/18 17.37.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\FileOpen
[2016/05/29 22.50.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\FileZilla
[2012/12/29 21.07.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\LolClient
[2016/01/19 22.30.20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\Nitro
[2016/07/05 06.25.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\Nitro PDF
[2010/05/20 18.37.30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\OpenOffice.org
[2015/10/20 21.10.45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\Oracle
[2014/09/14 19.06.27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\qBittorrent
[2013/02/14 18.02.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\Scan2PDF
[2013/02/14 17.51.26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\SumatraPDF
[2013/06/14 13.32.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\TeamViewer
[2013/03/29 17.14.36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\TuneUp Software
[2014/01/01 15.34.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boschetti\Dati applicazioni\uTorrent
[2013/01/31 14.30.19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Dati applicazioni\TuneUp Software
========== Purity Check ========== < End of report >