OTL logfile created on: 27/08/2013 00:32:24 - Run 1਍ഀ OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Federico\Downloads਍ഀ Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation਍ഀ Internet Explorer (Version = 9.10.9200.16660)਍ഀ Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy਍ഀ ਍ഀ 3,18 Gb Total Physical Memory | 1,50 Gb Available Physical Memory | 47,14% Memory free਍ഀ 6,35 Gb Paging File | 4,15 Gb Available in Paging File | 65,38% Paging File free਍ഀ Paging file location(s): ?:\pagefile.sys [binary data]਍ഀ ਍ഀ %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files਍ഀ Drive C: | 439,36 Gb Total Space | 359,19 Gb Free Space | 81,75% Space Free | Partition Type: NTFS਍ഀ Drive D: | 492,06 Gb Total Space | 340,35 Gb Free Space | 69,17% Space Free | Partition Type: NTFS਍ഀ Drive F: | 37,28 Gb Total Space | 5,51 Gb Free Space | 14,78% Space Free | Partition Type: NTFS਍ഀ Drive G: | 465,76 Gb Total Space | 311,00 Gb Free Space | 66,77% Space Free | Partition Type: NTFS਍ഀ ਍ഀ Computer Name: FEDERICO-PC | User Name: Federico | Logged in as Administrator.਍ഀ Boot Mode: Normal | Scan Mode: All users਍ഀ Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days਍ഀ ਍ഀ [color=#E56717]========== Processes (SafeList) ==========[/color]਍ഀ ਍ഀ PRC - C:\Users\Federico\Downloads\OTL.exe (OldTimer Tools)਍ഀ PRC - C:\Users\Federico\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)਍ഀ PRC - C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)਍ഀ PRC - C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe (MyHeritage)਍ഀ PRC - C:\Program Files\Google\Drive\googledrivesync.exe (Google)਍ഀ PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)਍ഀ PRC - C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)਍ഀ PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)਍ഀ PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)਍ഀ PRC - C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia)਍ഀ PRC - C:\Program Files\PDF Architect\HelperService.exe (pdfforge GmbH)਍ഀ PRC - C:\Program Files\PDF Architect\ConversionService.exe (pdfforge GmbH)਍ഀ PRC - C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)਍ഀ PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)਍ഀ PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)਍ഀ PRC - C:\Program Files\Samsung\Easy Printer Manager\ScrPrint.exe (Samsung Electronics Co., Ltd.)਍ഀ PRC - C:\Windows\System32\spool\drivers\w32x86\3\NetFaxServer.exe (Samsung Electronics Co., Ltd.)਍ഀ PRC - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)਍ഀ PRC - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)਍ഀ PRC - C:\Program Files\SmarThru Office\LegacyLauncher.exe (Samsung Electronics Co., Ltd.)਍ഀ PRC - C:\Program Files\SmarThru Office\BackUpSvr.exe (Samsung Electronics Co., Ltd.)਍ഀ PRC - C:\Program Files\TortoiseSVN\bin\TSVNCache.exe (http://tortoisesvn.net)਍ഀ PRC - C:\Program Files\FreeCountdownTimer\FreeCountdownTimer.exe (Comfort Software Group)਍ഀ PRC - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)਍ഀ PRC - C:\Windows\explorer.exe (Microsoft Corporation)਍ഀ PRC - C:\Windows\System32\atieclxx.exe (AMD)਍ഀ PRC - C:\Windows\System32\atiesrxx.exe (AMD)਍ഀ PRC - C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe (AMD)਍ഀ PRC - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe ()਍ഀ PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)਍ഀ PRC - C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)਍ഀ PRC - C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)਍ഀ ਍ഀ ਍ഀ [color=#E56717]========== Modules (No Company Name) ==========[/color]਍ഀ ਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\wx._core_.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\_ssl.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\wx._controls_.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\wx._windows_.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\wx._gdi_.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\wx._misc_.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\_hashlib.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\unicodedata.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\pysqlite2._sqlite.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\windows._cacheinvalidation.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\pythoncom27.dll ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32com.shell.shell.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\_elementtree.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\pyexpat.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\wx._wizard.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32file.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\pywintypes27.dll ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32security.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32api.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\_ctypes.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\wx._html2.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\_socket.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32inet.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32process.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\_multiprocessing.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32pdh.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32ts.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32event.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32profile.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\win32crypt.pyd ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Temp\_MEI35482\select.pyd ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\03dc83fbe48384390aed7a455e949789\WindowsFormsIntegration.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\9e38ddbb3a90cc3e782a0640788b1fcb\System.Core.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\40b43527d6fdbeb6e905a7b6123f3a42\System.Web.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\dd8f4efb7e81c75fe444a180f6f1aacf\System.Runtime.Remoting.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\930e99b2f62cea8c4aa070527d15f748\PresentationFramework.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\28ea347a952d20959ac6ae02d7457d39\System.Windows.Forms.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\585b8f6cc7ba86886462d0dc9753c98f\PresentationCore.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1f6f220f9efe936d1158c79b9d4b451f\WindowsBase.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\439eb22c3f6967beb8a3364626883423\System.Xml.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\8f7d83126a3cf283e5ac97f2d6d99f12\System.Configuration.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Google\Chrome\Application\28.0.1500.95\libglesv2.dll ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Google\Chrome\Application\28.0.1500.95\libegl.dll ()਍ഀ MOD - C:\Users\Federico\AppData\Local\Google\Chrome\Application\28.0.1500.95\ffmpegsumo.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5de32c4f69c7141f68b383915ab87ff4\PresentationFramework.Classic.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\8f4a3d09bd38a742ccfe4a20a126fff5\UIAutomationProvider.ni.dll ()਍ഀ MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\phonon4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\qjson.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtXmlPatterns4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtXml4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtWebKit4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtScript4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtSql4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtNetwork4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtOpenGL4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtGui4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtMultimediaKit1.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtDeclarative4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\QtCore4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\imageformats\qjpeg4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\imageformats\qico4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\imageformats\qgif4.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\NService.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\CommonUpdateChecker.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\ssoengine.dll ()਍ഀ MOD - C:\Program Files\Nokia\Nokia Suite\securestorage.dll ()਍ഀ MOD - C:\Program Files\TortoiseSVN\bin\libsasl32.dll ()਍ഀ MOD - C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_it_31bf3856ad364e35\PresentationFramework.resources.dll ()਍ഀ MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_it_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()਍ഀ MOD - C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll ()਍ഀ MOD - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()਍ഀ MOD - C:\Program Files\ATI Technologies\HydraVision\HydraIta.dll ()਍ഀ MOD - C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll ()਍ഀ MOD - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe ()਍ഀ MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_it_b77a5c561934e089\System.Windows.Forms.resources.dll ()਍ഀ MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll ()਍ഀ ਍ഀ ਍ഀ [color=#E56717]========== Services (SafeList) ==========[/color]਍ഀ ਍ഀ SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)਍ഀ SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)਍ഀ SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)਍ഀ SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)਍ഀ SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)਍ഀ SRV - (PDF Architect Helper Service) -- C:\Program Files\PDF Architect\HelperService.exe (pdfforge GmbH)਍ഀ SRV - (PDF Architect Service) -- C:\Program Files\PDF Architect\ConversionService.exe (pdfforge GmbH)਍ഀ SRV - (NisSrv) -- C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)਍ഀ SRV - (MsMpSvc) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)਍ഀ SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)਍ഀ SRV - (Samsung UPD Service2) -- C:\Windows\System32\SUPDSvc2.exe (Samsung Electronics)਍ഀ SRV - (Samsung Network Fax Server) -- C:\Windows\System32\spool\drivers\w32x86\3\NetFaxServer.exe (Samsung Electronics Co., Ltd.)਍ഀ SRV - (TeamViewer7) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)਍ഀ SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)਍ഀ SRV - (NitroReaderDriverReadSpool2) -- C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)਍ഀ SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)਍ഀ SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)਍ഀ SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)਍ഀ SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)਍ഀ SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)਍ഀ SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)਍ഀ ਍ഀ ਍ഀ [color=#E56717]========== Driver Services (SafeList) ==========[/color]਍ഀ ਍ഀ DRV - (mbr) -- C:\Users\Federico\AppData\Local\Temp\mbr.sys File not found਍ഀ DRV - (catchme) -- C:\Users\Federico\AppData\Local\Temp\catchme.sys File not found਍ഀ DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)਍ഀ DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)਍ഀ DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)਍ഀ DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)਍ഀ DRV - (NisDrv) -- C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)਍ഀ DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)਍ഀ DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)਍ഀ DRV - (SSPORT) -- C:\Windows\System32\drivers\SSPORT.SYS (Samsung Electronics)਍ഀ DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)਍ഀ DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)਍ഀ DRV - (MSHUSBVideo) -- C:\Windows\System32\drivers\nx6000.sys (Microsoft Corporation)਍ഀ DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)਍ഀ DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)਍ഀ DRV - (dmvsc) -- C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)਍ഀ DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)਍ഀ DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)਍ഀ DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)਍ഀ DRV - (TsUsbGD) -- C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)਍ഀ DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)਍ഀ DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)਍ഀ DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)਍ഀ DRV - (RTL8192su) -- C:\Windows\System32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )਍ഀ DRV - (ZTEusbnet) -- C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)਍ഀ DRV - (ZTEusbser6k) -- C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)਍ഀ DRV - (ZTEusbnmea) -- C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)਍ഀ DRV - (massfilter) -- C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)਍ഀ DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)਍ഀ DRV - (DgiVecp) -- C:\Windows\System32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)਍ഀ DRV - (ACSSCR) -- C:\Windows\System32\drivers\a38usbxp.sys (Advanced Card Systems Ltd)਍ഀ DRV - (ICAM5USB) -- C:\Windows\System32\drivers\Icam5USB.sys (Microsoft Corporation)਍ഀ ਍ഀ ਍ഀ [color=#E56717]========== Standard Registry (SafeList) ==========[/color]਍ഀ ਍ഀ ਍ഀ [color=#E56717]========== Internet Explorer ==========[/color]਍ഀ ਍ഀ IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchdwebs.info/?pid=34&r=2013/07/04&hid=2883937412&lg=EN&cc=IT&unqvl=22਍ഀ IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}਍ഀ IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC਍ഀ IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.searchdwebs.info/?l=1&q={searchTerms}&pid=34&r=2013/07/04&hid=2883937412&lg=EN&cc=IT&unqvl=22਍ഀ ਍ഀ ਍ഀ IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0਍ഀ ਍ഀ IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0਍ഀ ਍ഀ ਍ഀ ਍ഀ IE - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\Federico\Downloads\Musica Giulia਍ഀ IE - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/਍ഀ IE - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\..\SearchScopes,DefaultScope = {2C934593-7032-4326-9EC0-968E938AE8D2}਍ഀ IE - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR਍ഀ IE - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\..\SearchScopes\{2C934593-7032-4326-9EC0-968E938AE8D2}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}਍ഀ IE - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.searchdwebs.info/?l=1&q={searchTerms}&pid=34&r=2013/07/04&hid=2883937412&lg=EN&cc=IT&unqvl=22਍ഀ IE - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0਍ഀ ਍ഀ ਍ഀ [color=#E56717]========== FireFox ==========[/color]਍ഀ ਍ഀ FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()਍ഀ FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)਍ഀ FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)਍ഀ FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)਍ഀ FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found਍ഀ FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)਍ഀ FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)਍ഀ FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)਍ഀ FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )਍ഀ FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)਍ഀ FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)਍ഀ FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)਍ഀ FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)਍ഀ FF - HKLM\Software\MozillaPlugins\NitroPDF: C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll ( )਍ഀ FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Federico\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)਍ഀ FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Federico\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)਍ഀ FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Federico\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()਍ഀ FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Federico\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)਍ഀ FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Federico\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)਍ഀ ਍ഀ FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012/01/05 23:41:15 | 000,000,000 | ---D | M]਍ഀ FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\helperframework@zonemedia.com: C:\Program Files\Internet Explorer\bin [2012/12/08 13:12:49 | 000,000,000 | ---D | M]਍ഀ FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\FFPDFArchitectConverter@pdfarchitect.com: C:\Program Files\PDF Architect\FFPDFArchitectExt [2013/07/08 10:48:41 | 000,000,000 | ---D | M]਍ഀ ਍ഀ [2012/05/04 22:01:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Federico\AppData\Roaming\mozilla\Firefox\extensions਍ഀ [2012/05/04 22:01:57 | 000,000,000 | ---D | M] (BittorrentBar_IT Community Toolbar) -- C:\Users\Federico\AppData\Roaming\mozilla\Firefox\extensions\{1d03a978-ac0c-4004-b9fd-9cf361c7bd3f}਍ഀ ਍ഀ [color=#E56717]========== Chrome ==========[/color]਍ഀ ਍ഀ CHR - default_search_provider: Google (Enabled)਍ഀ CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}਍ഀ CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter},਍ഀ CHR - homepage: ਍ഀ CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.225\pepflashplayer.dll਍ഀ CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer਍ഀ CHR - plugin: Native Client (Enabled) = C:\Users\Federico\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll਍ഀ CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Federico\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll਍ഀ CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll਍ഀ CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Federico\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll਍ഀ CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Federico\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll਍ഀ CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Federico\AppData\Roaming\Mozilla\plugins\npo1d.dll਍ഀ CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL਍ഀ CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL਍ഀ CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll਍ഀ CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll਍ഀ CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll਍ഀ CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll਍ഀ CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll਍ഀ CHR - plugin: Google Update (Enabled) = C:\Users\Federico\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll਍ഀ CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll਍ഀ CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\system32\npDeployJava1.dll਍ഀ CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll਍ഀ CHR - Extension: Google Drive = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\਍ഀ CHR - Extension: YouTube = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\਍ഀ CHR - Extension: Ricerca Google = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\਍ഀ CHR - Extension: BittorrentBar_IT = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkjdegoaioeecahaflmobghfcihcdkpf\2.5.0.1_0\਍ഀ CHR - Extension: avast! Online Security = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0\਍ഀ CHR - Extension: Skype Click to Call = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkkeikdkpjenmoiicggnnodbkebafgpc\1.2_0\਍ഀ CHR - Extension: Skype Click to Call = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.9.0.12585_0\਍ഀ CHR - Extension: ilcorsaronero = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\oficlppjlnlhimobpjhogopmcdjmfpgg\10.19.2.505_0\਍ഀ CHR - Extension: Gmail = C:\Users\Federico\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\਍ഀ ਍ഀ O1 HOSTS File: ([2013/08/27 00:18:18 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts਍ഀ O1 - Hosts: 127.0.0.1 localhost਍ഀ O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems Incorporated.)਍ഀ O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)਍ഀ O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)਍ഀ O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)਍ഀ O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)਍ഀ O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)਍ഀ O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)਍ഀ O3 - HKLM\..\Toolbar: (PDF Architect Toolbar) - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH)਍ഀ O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems Incorporated.)਍ഀ O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)਍ഀ O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)਍ഀ O4 - HKLM..\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe ()਍ഀ O4 - HKLM..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe (MyHeritage)਍ഀ O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)਍ഀ O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)਍ഀ O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)਍ഀ O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)਍ഀ O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)਍ഀ O4 - HKLM..\Run: [STO Backup Service] C:\Program Files\SmarThru Office\BackUpSvr.exe (Samsung Electronics Co., Ltd.)਍ഀ O4 - HKLM..\Run: [STO Launcher Service] C:\Program Files\SmarThru Office\LegacyLauncher.exe (Samsung Electronics Co., Ltd.)਍ഀ O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)਍ഀ O4 - HKU\S-1-5-21-2620673237-178762442-2695200228-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)਍ഀ O4 - HKU\S-1-5-21-2620673237-178762442-2695200228-1000..\Run: [FreeCT] C:\Program Files\FreeCountdownTimer\FreeCountdownTimer.exe (Comfort Software Group)਍ഀ O4 - HKU\S-1-5-21-2620673237-178762442-2695200228-1000..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)਍ഀ O4 - HKU\S-1-5-21-2620673237-178762442-2695200228-1000..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe (AMD)਍ഀ O4 - HKU\S-1-5-21-2620673237-178762442-2695200228-1000..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)਍ഀ O4 - HKU\S-1-5-21-2620673237-178762442-2695200228-1000..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)਍ഀ O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present਍ഀ O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0਍ഀ O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5਍ഀ O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3਍ഀ O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present਍ഀ O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present਍ഀ O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present਍ഀ O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present਍ഀ O7 - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present਍ഀ O7 - HKU\S-1-5-21-2620673237-178762442-2695200228-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0਍ഀ O8 - Extra context menu item: Apri client su monitor &1 - C:\Windows\web\AOpenClient.htm File not found਍ഀ O8 - Extra context menu item: Apri client su monitor &2 - C:\Windows\web\AOpenClient.htm File not found਍ഀ O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found਍ഀ O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found਍ഀ O9 - Extra Button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)਍ഀ O9 - Extra 'Tools' menuitem : I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)਍ഀ O9 - Extra Button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)਍ഀ O9 - Extra 'Tools' menuitem : &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)਍ഀ O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)਍ഀ O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.101.93.101 83.103.25.250਍ഀ O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{053469A9-5496-4338-9D85-825B7F9EBF7C}: DhcpNameServer = 192.168.1.1 192.168.1.1਍ഀ O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5436FFA0-9E38-42DC-8034-9F487AE5BF01}: DhcpNameServer = 62.101.93.101 83.103.25.250਍ഀ O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E50D697-C35C-4BFB-A222-98BDD2191985}: DhcpNameServer = 62.101.93.101 83.103.25.250਍ഀ O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F541ED0E-101E-4130-BBDE-DC13CA6655F5}: DhcpNameServer = 192.168.0.1਍ഀ O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)਍ഀ O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)਍ഀ O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)਍ഀ O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)਍ഀ O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)਍ഀ O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.਍ഀ O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)਍ഀ O32 - HKLM CDRom: AutoRun - 1਍ഀ O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]਍ഀ O34 - HKLM BootExecute: (autocheck autochk *)਍ഀ O35 - HKLM\..comfile [open] -- "%1" %*਍ഀ O35 - HKLM\..exefile [open] -- "%1" %*਍ഀ O37 - HKLM\...com [@ = ComFile] -- "%1" %*਍ഀ O37 - HKLM\...exe [@ = exefile] -- "%1" %*਍ഀ O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)਍ഀ O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)਍ഀ O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)਍ഀ ਍ഀ [color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]਍ഀ ਍ഀ [2013/08/27 00:26:00 | 000,000,000 | ---D | C] -- C:\Windows\temp਍ഀ [2013/08/27 00:18:22 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN਍ഀ [2013/08/26 23:52:48 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe਍ഀ [2013/08/26 23:52:48 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe਍ഀ [2013/08/26 23:52:48 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe਍ഀ [2013/08/26 23:50:30 | 000,000,000 | ---D | C] -- C:\Qoobox਍ഀ [2013/08/26 23:50:16 | 000,000,000 | ---D | C] -- C:\Windows\erdnt਍ഀ [2013/08/26 22:12:20 | 000,000,000 | ---D | C] -- C:\Config.Msi਍ഀ [2013/08/22 21:46:43 | 000,000,000 | ---D | C] -- C:\Programmi਍ഀ [2013/08/20 00:24:47 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT਍ഀ [2013/08/20 00:21:50 | 002,877,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll਍ഀ [2013/08/20 00:21:50 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb਍ഀ [2013/08/20 00:21:49 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll਍ഀ [2013/08/20 00:21:49 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll਍ഀ [2013/08/20 00:21:48 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll਍ഀ [2013/08/20 00:21:48 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll਍ഀ [2013/08/20 00:21:48 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe਍ഀ [2013/08/20 00:21:48 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe਍ഀ [2013/08/20 00:21:48 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll਍ഀ [2013/08/20 00:21:47 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll਍ഀ [2013/08/19 20:04:36 | 001,620,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL਍ഀ [2013/08/19 20:04:29 | 003,968,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe਍ഀ [2013/08/19 20:04:29 | 003,913,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe਍ഀ [2013/08/19 20:04:26 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll਍ഀ [2013/08/01 10:30:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BHO Scanner & Remover਍ഀ [2013/08/01 10:30:36 | 000,000,000 | ---D | C] -- C:\Program Files\BHO Scanner & Remover਍ഀ [2013/07/30 20:17:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth਍ഀ [2013/07/16 23:19:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive਍ഀ [2013/07/16 21:16:38 | 000,116,736 | ---- | C] (ZTE Corporation) -- C:\Windows\System32\drivers\ZTEusbnet.sys਍ഀ [2013/07/16 21:16:38 | 000,107,776 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbser6k.sys਍ഀ [2013/07/16 21:16:38 | 000,107,776 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbnmea.sys਍ഀ [2013/07/16 21:16:38 | 000,107,776 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys਍ഀ [2013/07/16 21:16:38 | 000,009,216 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\massfilter.sys਍ഀ [2013/07/16 21:16:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebPocket. 21.6਍ഀ [2013/07/16 21:16:15 | 000,000,000 | ---D | C] -- C:\Program Files\SupportAppCB਍ഀ [2013/07/16 21:16:13 | 000,000,000 | ---D | C] -- C:\Program Files\WebPocket. 21.6਍ഀ [2013/07/11 23:50:57 | 000,000,000 | ---D | C] -- C:\Users\Federico\AppData\Roaming\SketchUp਍ഀ [2013/07/11 23:48:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2013਍ഀ [2013/07/11 23:47:32 | 000,000,000 | ---D | C] -- C:\ProgramData\SketchUp਍ഀ [2013/07/11 23:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\SketchUp਍ഀ [2013/07/09 23:35:00 | 001,247,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll਍ഀ [2013/07/09 23:34:58 | 002,347,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys਍ഀ [2013/07/09 23:34:58 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll਍ഀ [2013/07/08 22:10:43 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe਍ഀ [2013/07/08 22:10:35 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe਍ഀ [2013/07/08 22:10:35 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe਍ഀ [2013/07/08 22:10:35 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll਍ഀ [2013/07/08 22:10:13 | 000,000,000 | ---D | C] -- C:\Program Files\Java਍ഀ [2013/07/08 10:52:14 | 000,000,000 | ---D | C] -- C:\Users\Federico\AppData\Roaming\PDF Architect਍ഀ [2013/07/08 10:48:53 | 000,000,000 | ---D | C] -- C:\Users\Federico\Documents\PDF Architect Files਍ഀ [2013/07/08 10:48:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect਍ഀ [2013/07/08 10:48:34 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}਍ഀ [2013/07/08 10:48:34 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files਍ഀ [2013/07/08 10:48:31 | 000,000,000 | ---D | C] -- C:\Program Files\PDF Architect਍ഀ [2013/07/08 10:47:59 | 000,000,000 | ---D | C] -- C:\Users\Federico\AppData\Roaming\pdfforge਍ഀ [2013/07/08 10:47:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator਍ഀ [2013/07/08 10:47:54 | 000,662,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCOMCT2.OCX਍ഀ [2013/07/08 10:47:54 | 000,095,416 | ---- | C] (pdfforge GmbH) -- C:\Windows\System32\pdfcmon.dll਍ഀ [2013/07/08 10:47:52 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCIT.DLL਍ഀ [2013/07/08 10:47:52 | 000,122,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6IT.DLL਍ഀ [2013/07/08 10:47:52 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCC2IT.DLL਍ഀ [2013/07/08 10:47:52 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPIDE.DLL਍ഀ [2013/07/08 10:47:52 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator਍ഀ [2013/07/04 23:37:11 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group਍ഀ [2013/07/04 23:37:11 | 000,000,000 | ---D | C] -- C:\Users\Federico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller਍ഀ [2013/07/04 23:24:56 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP਍ഀ [2013/07/04 23:20:43 | 000,000,000 | ---D | C] -- C:\Windows\AutoKMS਍ഀ [2013/07/04 23:18:42 | 000,000,000 | ---D | C] -- C:\ProgramData\StarApp਍ഀ [2013/07/04 23:17:45 | 000,000,000 | ---D | C] -- C:\Users\Federico\AppData\Roaming\SendSpace਍ഀ [2013/07/04 23:17:40 | 000,000,000 | ---D | C] -- C:\Program Files\WebSearch਍ഀ [2013/07/04 23:17:28 | 000,000,000 | ---D | C] -- C:\Users\Federico\AppData\Local\Programs਍ഀ [2013/07/04 23:17:11 | 000,000,000 | ---D | C] -- C:\Program Files\SafeSaver਍ഀ [2013/07/04 23:16:29 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate਍ഀ [2013/07/03 14:01:06 | 000,928,288 | ---- | C] (MyHeritage) -- C:\Windows\System32\FTBSaver.scr਍ഀ ਍ഀ [color=#E56717]========== Files - Modified Within 60 Days ==========[/color]਍ഀ ਍ഀ [2013/08/27 00:32:43 | 000,032,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0਍ഀ [2013/08/27 00:32:43 | 000,032,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0਍ഀ [2013/08/27 00:18:49 | 000,000,266 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job਍ഀ [2013/08/27 00:18:18 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts਍ഀ [2013/08/27 00:17:58 | 000,001,138 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job਍ഀ [2013/08/27 00:17:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat਍ഀ [2013/08/27 00:17:32 | 2559,877,120 | -HS- | M] () -- C:\hiberfil.sys਍ഀ [2013/08/27 00:10:00 | 000,001,172 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2620673237-178762442-2695200228-1000UA.job਍ഀ [2013/08/27 00:10:00 | 000,001,142 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job਍ഀ [2013/08/26 23:17:00 | 000,000,978 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job਍ഀ [2013/08/24 20:10:00 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2620673237-178762442-2695200228-1000Core.job਍ഀ [2013/08/23 20:10:53 | 003,923,048 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT਍ഀ [2013/08/20 22:17:47 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe਍ഀ [2013/08/20 22:17:46 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl਍ഀ [2013/08/20 00:23:27 | 000,739,004 | ---- | M] () -- C:\Windows\System32\perfh010.dat਍ഀ [2013/08/20 00:23:27 | 000,651,938 | ---- | M] () -- C:\Windows\System32\perfh009.dat਍ഀ [2013/08/20 00:23:27 | 000,146,076 | ---- | M] () -- C:\Windows\System32\perfc010.dat਍ഀ [2013/08/20 00:23:27 | 000,120,870 | ---- | M] () -- C:\Windows\System32\perfc009.dat਍ഀ [2013/08/01 10:30:36 | 000,000,947 | ---- | M] () -- C:\Users\Federico\Desktop\BHO Scanner & Remover.lnk਍ഀ [2013/07/26 05:13:37 | 000,042,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe਍ഀ [2013/07/26 05:12:22 | 000,493,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll਍ഀ [2013/07/26 05:12:05 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll਍ഀ [2013/07/26 05:12:04 | 002,877,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll਍ഀ [2013/07/26 05:12:00 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll਍ഀ [2013/07/26 05:12:00 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll਍ഀ [2013/07/26 05:12:00 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll਍ഀ [2013/07/26 05:11:59 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll਍ഀ [2013/07/26 04:49:14 | 002,706,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb਍ഀ [2013/07/26 03:59:38 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe਍ഀ [2013/07/25 10:57:27 | 001,620,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL਍ഀ [2013/07/19 03:41:01 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll਍ഀ [2013/07/17 00:41:49 | 000,000,701 | ---- | M] () -- C:\Users\Federico\Desktop\La Maddalena - collegamento.lnk਍ഀ [2013/07/17 00:41:41 | 000,000,701 | ---- | M] () -- C:\Users\Federico\Desktop\Mappe e Foto.lnk਍ഀ [2013/07/17 00:41:38 | 000,000,694 | ---- | M] () -- C:\Users\Federico\Desktop\Panzer-Lage - collegamento.lnk਍ഀ [2013/07/16 23:41:45 | 000,001,473 | ---- | M] () -- C:\Users\Federico\Desktop\Google Drive.lnk਍ഀ [2013/07/16 21:16:19 | 000,001,937 | ---- | M] () -- C:\Users\Public\Desktop\WebPocket. 21.6.lnk਍ഀ [2013/07/11 23:48:13 | 000,003,120 | ---- | M] () -- C:\Windows\System32\ALLFSAF13a.ocx਍ഀ [2013/07/11 23:48:06 | 000,002,158 | ---- | M] () -- C:\Users\Public\Desktop\Style Builder 2013.lnk਍ഀ [2013/07/11 23:48:06 | 000,002,072 | ---- | M] () -- C:\Users\Public\Desktop\LayOut 2013.lnk਍ഀ [2013/07/11 23:48:06 | 000,001,987 | ---- | M] () -- C:\Users\Public\Desktop\SketchUp 2013.lnk਍ഀ [2013/07/11 00:14:16 | 000,004,076 | ---- | M] () -- C:\Users\Federico\Desktop\Aerei Tedeschi.kmz਍ഀ [2013/07/09 07:03:34 | 003,968,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe਍ഀ [2013/07/09 07:03:34 | 003,913,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe਍ഀ [2013/07/08 22:10:26 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll਍ഀ [2013/07/08 22:10:21 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe਍ഀ [2013/07/08 22:10:21 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe਍ഀ [2013/07/08 22:10:20 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe਍ഀ [2013/07/08 22:10:18 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll਍ഀ [2013/07/08 22:10:18 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll਍ഀ [2013/07/08 22:08:24 | 000,001,079 | ---- | M] () -- C:\Users\Federico\Desktop\MyHeritage Family Tree Builder.lnk਍ഀ [2013/07/08 10:49:04 | 000,000,963 | ---- | M] () -- C:\Users\Federico\Desktop\PDF Architect.lnk਍ഀ [2013/07/08 10:48:00 | 000,000,989 | ---- | M] () -- C:\Users\Public\Desktop\PDFCreator.lnk਍ഀ [2013/07/04 22:52:23 | 000,114,622 | ---- | M] () -- C:\Users\Federico\Desktop\Città di LM Parco nazionale0001.tiff਍ഀ [2013/07/03 14:01:06 | 000,928,288 | ---- | M] (MyHeritage) -- C:\Windows\System32\FTBSaver.scr਍ഀ [2013/07/03 02:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\Quark Updater.job਍ഀ ਍ഀ [color=#E56717]========== Files Created - No Company Name ==========[/color]਍ഀ ਍ഀ [2013/08/26 23:52:48 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe਍ഀ [2013/08/26 23:52:48 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe਍ഀ [2013/08/26 23:52:48 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe਍ഀ [2013/08/26 23:52:48 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe਍ഀ [2013/08/26 23:52:48 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe਍ഀ [2013/08/01 10:30:36 | 000,000,947 | ---- | C] () -- C:\Users\Federico\Desktop\BHO Scanner & Remover.lnk਍ഀ [2013/07/16 23:41:45 | 000,001,473 | ---- | C] () -- C:\Users\Federico\Desktop\Google Drive.lnk਍ഀ [2013/07/16 21:16:19 | 000,001,937 | ---- | C] () -- C:\Users\Public\Desktop\WebPocket. 21.6.lnk਍ഀ [2013/07/11 23:48:13 | 000,003,120 | ---- | C] () -- C:\Windows\System32\ALLFSAF13a.ocx਍ഀ [2013/07/11 23:48:06 | 000,002,158 | ---- | C] () -- C:\Users\Public\Desktop\Style Builder 2013.lnk਍ഀ [2013/07/11 23:48:06 | 000,002,072 | ---- | C] () -- C:\Users\Public\Desktop\LayOut 2013.lnk਍ഀ [2013/07/11 23:48:06 | 000,001,987 | ---- | C] () -- C:\Users\Public\Desktop\SketchUp 2013.lnk਍ഀ [2013/07/11 00:14:16 | 000,004,076 | ---- | C] () -- C:\Users\Federico\Desktop\Aerei Tedeschi.kmz਍ഀ [2013/07/08 10:49:04 | 000,000,963 | ---- | C] () -- C:\Users\Federico\Desktop\PDF Architect.lnk਍ഀ [2013/07/08 10:48:00 | 000,000,989 | ---- | C] () -- C:\Users\Public\Desktop\PDFCreator.lnk਍ഀ [2013/07/04 23:20:43 | 000,000,266 | ---- | C] () -- C:\Windows\tasks\AutoKMS.job਍ഀ [2013/07/04 22:52:23 | 000,114,622 | ---- | C] () -- C:\Users\Federico\Desktop\Città di LM Parco nazionale0001.tiff਍ഀ [2012/12/05 10:26:06 | 000,950,585 | ---- | C] () -- C:\Windows\System32\libiconv-2.dll਍ഀ [2012/12/05 10:19:52 | 000,124,792 | ---- | C] () -- C:\Windows\Wiainst.exe਍ഀ [2012/12/05 10:19:13 | 000,024,064 | ---- | C] () -- C:\Windows\System32\ssm1mlm.dll਍ഀ [2012/05/26 13:50:52 | 000,110,592 | ---- | C] () -- C:\Windows\System32\usbr38.dll਍ഀ [2012/04/06 03:46:34 | 000,254,464 | ---- | C] () -- C:\Windows\System32\SUPDRun.exe਍ഀ [2012/04/06 03:46:16 | 000,310,272 | ---- | C] () -- C:\Windows\System32\UPDIO2.dll਍ഀ [2012/03/11 23:27:15 | 000,790,528 | ---- | C] () -- C:\Windows\System32\FreeImageX.dll਍ഀ [2012/01/26 23:09:58 | 000,007,666 | ---- | C] () -- C:\Users\Federico\AppData\Local\resmon.resmoncfg਍ഀ [2012/01/22 21:45:50 | 000,021,504 | ---- | C] () -- C:\Users\Federico\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini਍ഀ [2012/01/07 00:20:38 | 000,000,166 | ---- | C] () -- C:\Windows\MyHeritage.INI਍ഀ [2012/01/07 00:20:04 | 000,454,656 | ---- | C] () -- C:\Windows\System32\PaintX.dll਍ഀ [2012/01/05 21:31:14 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin਍ഀ [2012/01/05 21:29:23 | 000,003,113 | ---- | C] () -- C:\Windows\System32\atipblag.dat਍ഀ ਍ഀ [color=#E56717]========== ZeroAccess Check ==========[/color]਍ഀ ਍ഀ [2009/07/14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini਍ഀ ਍ഀ [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]਍ഀ ਍ഀ [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]਍ഀ ਍ഀ [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]਍ഀ "" = %SystemRoot%\system32\shell32.dll -- [2013/02/27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)਍ഀ "ThreadingModel" = Apartment਍ഀ ਍ഀ [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]਍ഀ "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)਍ഀ "ThreadingModel" = Free਍ഀ ਍ഀ [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]਍ഀ "" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)਍ഀ "ThreadingModel" = Both਍ഀ ਍ഀ [color=#E56717]========== LOP Check ==========[/color]਍ഀ ਍ഀ [2012/01/14 18:43:59 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\ACD Systems਍ഀ [2013/06/06 23:54:40 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\BitTorrent਍ഀ [2012/02/22 23:11:07 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1਍ഀ [2012/02/22 22:57:38 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\com.adobe.bridge.PublishPanel਍ഀ [2012/01/05 23:28:44 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\DAEMON Tools Lite਍ഀ [2012/09/07 21:19:27 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\MyHeritage਍ഀ [2012/01/06 20:05:55 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\Nitro PDF਍ഀ [2012/07/02 11:56:10 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\Nokia਍ഀ [2012/01/06 19:42:27 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\Nokia Suite਍ഀ [2012/04/23 11:53:39 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\NorthGates Systems਍ഀ [2013/07/08 10:47:52 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\OpenCandy਍ഀ [2013/04/19 20:16:30 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\PC Suite਍ഀ [2013/07/08 10:52:15 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\PDF Architect਍ഀ [2013/07/08 10:47:59 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\pdfforge਍ഀ [2012/02/20 00:56:33 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\Quark਍ഀ [2012/12/05 10:27:27 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\Samsung਍ഀ [2013/07/04 23:17:45 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\SendSpace਍ഀ [2013/07/11 23:50:57 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\SketchUp਍ഀ [2012/01/07 00:40:56 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\Subversion਍ഀ [2012/01/07 00:20:04 | 000,000,000 | ---D | M] -- C:\Users\Federico\AppData\Roaming\The Complete Genealogy Reporter - FTB਍ഀ ਍ഀ [color=#E56717]========== Purity Check ==========[/color]਍ഀ ਍ഀ ਍ഀ ਍ഀ < End of report >਍ഀ