O15 - HKU\S-1-5-21-2247004754-144406242-1316480937-1002\..Trusted Domains: localhost ([]http in Intranet locale)
O15 - HKU\S-1-5-21-2247004754-144406242-1316480937-1002\..Trusted Ranges: GD ([http] in Intranet locale)
O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} https://wmrm01.sistinf.it/dwa85W.cab (IBM Lotus iNotes 8.5 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{9E2CAAF8-4E6C-4FEC-A73A-C1E345331B16}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{FAB2DED7-A12D-491A-80EF-9DCB4E51D459}: DhcpNameServer = 10.0.0.2
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Anna\Desktop\gino stories\cellulare gino\2012-02-04 14.47.40.jpg
O24 - Desktop BackupWallPaper: C:\Users\Anna\Desktop\gino stories\cellulare gino\2012-02-04 14.47.40.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22.43.36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 60 Days ==========
[2015/11/18 22.17.03 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Anna\Desktop\OTL.com
[2015/11/06 22.26.59 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2015/10/17 09.08.52 | 000,000,000 | ---D | C] -- C:\Users\Anna\Desktop\stampare
[2012/01/15 23.31.16 | 000,568,847 | ---- | C] (Macromedia, Inc.) -- C:\Users\Anna\bowling.exe
[2012/01/15 23.31.15 | 000,482,609 | ---- | C] (Macromedia, Inc.) -- C:\Users\Anna\Climbo.exe
[2012/01/15 23.31.15 | 000,436,396 | ---- | C] (Macromedia, Inc.) -- C:\Users\Anna\crab-ball.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 60 Days ==========
[2015/11/18 22.27.01 | 000,001,156 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2247004754-144406242-1316480937-1002UA.job
[2015/11/18 22.26.01 | 000,001,138 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/11/18 22.21.07 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2015/11/18 22.21.07 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2015/11/18 22.17.06 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Anna\Desktop\OTL.com
[2015/11/18 22.00.00 | 000,000,338 | ---- | M] () -- C:\Windows\tasks\Recovery DVD Creator.job
[2015/11/18 22.00.00 | 000,000,338 | ---- | M] () -- C:\Windows\tasks\Garanzia estesa.job
[2015/11/18 21.57.00 | 000,000,288 | ---- | M] () -- C:\Windows\tasks\SaveSense.job
[2015/11/18 21.54.00 | 000,000,978 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/11/18 21.35.40 | 000,695,052 | ---- | M] () -- C:\Windows\System32\perfh010.dat
[2015/11/18 21.35.40 | 000,621,374 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2015/11/18 21.35.40 | 000,120,532 | ---- | M] () -- C:\Windows\System32\perfc010.dat
[2015/11/18 21.35.40 | 000,108,458 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2015/11/18 21.27.00 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2247004754-144406242-1316480937-1002Core.job
[2015/11/18 21.26.00 | 000,001,134 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/11/18 21.21.52 | 000,000,000 | -H-- | M] () -- C:\ProgramData\cm-lock
[2015/11/18 21.21.01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/11/18 21.20.58 | 2010,300,416 | -HS- | M] () -- C:\hiberfil.sys
[2015/11/16 22.36.18 | 000,225,280 | ---- | M] () -- C:\Users\Anna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2015/11/10 23.54.26 | 000,780,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2015/11/10 23.54.26 | 000,142,536 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2015/10/29 00.09.34 | 018,047,513 | ---- | M] () -- C:\Users\Anna\Desktop\cartaigienicaweb111.pdf
[2015/10/28 23.54.57 | 000,131,172 | ---- | M] () -- C:\Users\Anna\Desktop\Immagine ordine ibs rantolo.jpg
[2015/10/20 21.38.53 | 002,204,071 | ---- | M] () -- C:\Users\Anna\Desktop\cartella-stampa-rantolo3.pdf
[2015/10/15 22.34.53 | 005,043,545 | ---- | M] () -- C:\Users\Anna\Desktop\romantic piano, pianoforte romantico, musica new age pianoforte - Andromeda by Gabriele Tosi.mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015/11/18 21.21.52 | 000,000,000 | -H-- | C] () -- C:\ProgramData\cm-lock
[2015/10/29 00.09.28 | 018,047,513 | ---- | C] () -- C:\Users\Anna\Desktop\cartaigienicaweb111.pdf
[2015/10/28 23.54.56 | 000,131,172 | ---- | C] () -- C:\Users\Anna\Desktop\Immagine ordine ibs rantolo.jpg
[2015/10/20 21.38.53 | 002,204,071 | ---- | C] () -- C:\Users\Anna\Desktop\cartella-stampa-rantolo3.pdf
[2015/10/15 22.34.51 | 005,043,545 | ---- | C] () -- C:\Users\Anna\Desktop\romantic piano, pianoforte romantico, musica new age pianoforte - Andromeda by Gabriele Tosi.mp3
[2015/09/03 20.19.42 | 000,274,432 | R--- | C] () -- C:\Windows\System32\pt2500lm.dll
[2014/07/31 20.35.25 | 000,024,184 | ---- | C] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014/06/09 16.17.31 | 000,778,752 | ---- | C] () -- C:\Windows\System32\RGSS102E.dll
[2014/06/09 16.17.31 | 000,758,272 | ---- | C] () -- C:\Windows\System32\RGSS104E.dll
[2014/06/09 16.17.30 | 000,761,856 | ---- | C] () -- C:\Windows\System32\RGSS104J.dll
[2014/06/09 16.17.30 | 000,685,056 | ---- | C] () -- C:\Windows\System32\RGSS103J.dll
[2014/06/09 16.17.29 | 000,781,312 | ---- | C] () -- C:\Windows\System32\RGSS102J.dll
[2014/06/09 16.17.29 | 000,771,584 | ---- | C] () -- C:\Windows\System32\RGSS100J.dll
[2012/12/28 23.51.26 | 1171,645,578 | ---- | C] () -- C:\Users\Anna\FILM [DVX - Ita] - Orgoglio e pregiudizio - Joe Wright - 2005.avi
[2012/05/26 23.25.32 | 000,003,989 | ---- | C] () -- C:\Users\Anna\AppData\Local\unins000.dat
[2012/01/15 23.34.18 | 000,000,281 | ---- | C] () -- C:\Users\Anna\same.scr
[2012/01/15 23.31.15 | 000,049,152 | ---- | C] () -- C:\Users\Anna\SAME.EXE
[2009/10/29 14.03.48 | 000,318,369 | ---- | C] () -- C:\Users\Anna\HiJackThis.zip
[2009/08/24 17.31.30 | 000,000,680 | ---- | C] () -- C:\Users\Anna\AppData\Local\d3d9caps.dat
[2009/08/19 21.46.21 | 007,009,998 | ---- | C] () -- C:\Users\Anna\dateme una mano!.zip
[2009/01/26 20.59.11 | 000,205,760 | ---- | C] () -- C:\Users\Anna\07216353A9055F_A29.pdf
[2008/05/30 16.30.46 | 104,690,841 | ---- | C] () -- C:\Users\Anna\workspace.zip
[2007/12/28 22.39.09 | 000,225,280 | ---- | C] () -- C:\Users\Anna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/28 22.37.38 | 000,000,092 | ---- | C] () -- C:\Users\Anna\AppData\Local\fusioncache.dat
========== ZeroAccess Check ==========
[2006/11/02 13.54.22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc8 7-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009/01/03 02.02.57 | 011,315,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA 9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/03/03 05.16.12 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CD B-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2006/11/02 10.46.13 | 000,348,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014/06/09 15.59.12 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\.minecraft
[2013/10/23 21.23.14 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\AVAST Software
[2015/07/04 22.37.21 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\avidemux
[2012/05/26 23.31.58 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Convivea
[2012/11/24 13.02.51 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Delivery
[2015/07/04 21.49.15 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\DVDVideoSoft
[2012/12/10 22.14.50 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\EmoticoonsToolbar
[2013/11/17 19.06.21 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\GetRightToGo
[2013/12/15 23.57.29 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\ImgBurn
[2012/12/01 13.07.47 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Lite
[2013/11/16 23.57.15 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\OfficeRecovery
[2013/12/15 22.56.45 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\OpenCandy
[2008/05/03 18.48.57 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Packard Bell
[2015/09/03 20.21.06 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Pantum
[2014/04/19 23.01.39 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\PDF Architect
[2014/04/19 20.41.53 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\pdfforge
[2015/02/24 21.40.12 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\QuickScan
[2013/12/15 22.57.01 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\SaveSense
[2008/04/14 20.56.09 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\USBSafelyRemove
[2015/11/18 22.33.35 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\uTorrent
[2011/07/08 21.46.06 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Zylom
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:6DDED7D9
< End of report >

Rispondi quotando
