Risultato della scansione Farbar Recovery Scan Tool (FRST) (x64) Versione: 08.11.2018
Gestito da Tom (ATTENZIONE: l'utente non è amministratore) su TOMDELL (10-11-2018 10:51:51)
Esegui da C: \ Users \ Tom \ Downloads
Profili installati: jl e Tom (profili correnti: jl e Tom)
Piattaforma: Windows 7 Professional Service Pack 1 (X64) Lingua: inglese (USA)
Internet Explorer Ver.11 (browser predefinito: FF)
Modalità di avvio: normale
Tutorial sullo strumento di scansione di ripristino Farbar:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processi (autorizzati) =================
(Se viene aggiunta una voce all'elenco delle correzioni, il processo viene chiuso. Il file non viene spostato.)
Impossibile accedere al processo -> smss.exe
Impossibile accedere al processo -> csrss.exe
Impossibile accedere al processo -> wininit.exe
Impossibile accedere al processo -> csrss.exe
Impossibile accedere al processo -> services.exe
Impossibile accedere al processo -> lsass.exe
Impossibile accedere al processo -> lsm.exe
Impossibile accedere al processo -> winlogon.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> MsMpEng.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> RtkAudioService64.exe
Impossibile accedere al processo -> RAVBg64.exe
Impossibile accedere al processo -> RAVBg64.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> WLTRYSVC.EXE
Impossibile accedere al processo -> BCMWLTRY.EXE
Impossibile accedere al processo -> spoolsv.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> armsvc.exe
Impossibile accedere al processo -> AERTSr64.exe
Impossibile accedere al processo -> btwdins.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> ijplmsvc.exe
Impossibile accedere al processo -> HeciServer.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> TeamViewer_Service.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> NisSrv.exe
(Realtek Semiconductor) C: \ Programmi \ Realtek \ Audio \ HDA \ RtkNGUI64.exe
(Realtek Semiconductor) C: \ Programmi \ Realtek \ Audio \ HDA \ RAVBg64.exe
(Realtek Semiconductor) C: \ Programmi \ Realtek \ Audio \ HDA \ RAVBg64.exe
(Synaptics Incorporated) C: \ Program Dosyaları \ Synaptics \ SynTP \ SynTPEnh.exe
(Dell Inc.) C: \ Programmi \ Dell \ DW WLAN Card \ WLTRAY.EXE
(Intel Corporation) C: \ Windows \ System32 \ igfxtray.exe
(Intel Corporation) C: \ Windows \ System32 \ hkcmd.exe
(Intel Corporation) C: \ Windows \ System32 \ igfxsrvc.exe
(Intel Corporation) C: \ Windows \ System32 \ igfxpers.exe
(Dell Inc.) C: \ Program Dosyaları \ Dell \ QuickSet \ quickset.exe
Impossibile accedere al processo -> WmiPrvSE.exe
(Microsoft Corporation) C: \ Programmi \ Microsoft Security Client \ msseces.exe
(iMesh Inc) C: \ Users \ Tom \ AppData \ Local \ Music Toolbar \ Datamngr \ sysctrl.exe
(iMesh Inc) C: \ Users \ Tom \ AppData \ Local \ Music Toolbar \ Datamngr \ x64 \ sysctrl.exe
Impossibile accedere al processo -> SearchIndexer.exe
(Synaptics Incorporated) C: \ Program Dosyaları \ Synaptics \ SynTP \ SynTPHelper.exe
(iMesh Inc) C: \ Users \ Tom \ AppData \ Local \ Music Toolbar \ Datamngr \ DatamngrCoordinator.exe
() C: \ Users \ Tom \ AppData \ Local \ WSE_Astromenda \ BRS \ brs.exe
(iMesh Inc) C: \ Users \ Tom \ AppData \ Local \ Music Toolbar \ Datamngr \ DatamngrCoordinator.exe
(Broadcom Corporation.) C: \ Programmi \ WIDCOMM \ Bluetooth Software \ BTTray.exe
(Intel Corporation) C: \ Programmi (x86) \ Intel \ Intel (R) USB 3.0 eXtensible Host Controller Driver \ Application \ iusb3mon.exe
(Creative Technology Ltd) C: \ Program Dosyaları (x86) \ Dell Webcam \ Dell Webcam Central \ WebcamDell2.exe
(CANON INC.) C: \ Program Dosyaları (x86) \ Canon \ Quick Menu \ CNQMMAIN.EXE
(Microsoft Corporation) C: \ Windows \ SysWOW64 \ rundll32.exe
(Broadcom Corporation.) C: \ Programmi \ WIDCOMM \ Bluetooth Software \ BTStackServer.exe
(Intel Corporation) C: \ Program Files \ Intel \ Intel (R) Rapid Storage Technology \ IAStorIcon.exe
(Microsoft Corporation) C: \ Windows \ splwow64.exe
Impossibile accedere al processo -> svchost.exe
(CANON INC.) C: \ Programmi (x86) \ Canon \ Quick Menu \ CNQMUPDT.EXE
(CANON INC.) C: \ Program Dosyaları (x86) \ Canon \ Quick Menu \ CNQMSWCS.EXE
Impossibile accedere al processo -> IAStorDataMgrSvc.exe
Impossibile accedere al processo -> Jhi_service.exe
Impossibile accedere al processo -> LMS.exe
Impossibile accedere al processo -> SftService.exe
Impossibile accedere al processo -> wmpnetwk.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> SeaPort.EXE
(Valve Corporation) C: \ Programmi (x86) \ Steam \ Steam.exe
(Valve Corporation) C: \ Program Dosyaları (x86) \ Steam \ bin \ cef \ cef.win7x64 \ steamwebhelper.exe
Impossibile accedere al processo -> SteamService.exe
(Valve Corporation) C: \ Program Dosyaları (x86) \ Steam \ bin \ cef \ cef.win7x64 \ steamwebhelper.exe
(Valve Corporation) C: \ Program Dosyaları (x86) \ Steam \ bin \ cef \ cef.win7x64 \ steamwebhelper.exe
(Valve Corporation) C: \ Program Dosyaları (x86) \ Steam \ bin \ cef \ cef.win7x64 \ steamwebhelper.exe
Impossibile accedere al processo -> rundll32.exe
Impossibile accedere al processo -> VSSVC.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> OSPPSVC.EXE
Impossibile accedere al processo -> dllhost.exe
(Adobe Systems Incorporated) C: \ Windows \ System32 \ Macromed \ Flash \ FlashUtil64_31_0_0_122_ActiveX.exe
(Oracle Corporation) C: \ Programmi (x86) \ Common Files \ Java \ Java Update \ jusched.exe
(Valve Corporation) C: \ Program Dosyaları (x86) \ Steam \ bin \ cef \ cef.win7x64 \ steamwebhelper.exe
Impossibile accedere al processo -> svchost.exe
Impossibile accedere al processo -> DbxSvc.exe
(Dropbox, Inc.) C: \ Program Dosyaları (x86) \ Dropbox \ Client \ Dropbox.exe
(Dropbox, Inc.) C: \ Program Dosyaları (x86) \ Dropbox \ Client \ Dropbox.exe
(Dropbox, Inc.) C: \ Program Dosyaları (x86) \ Dropbox \ Client \ Dropbox.exe
(Microsoft Corporation) C: \ Programmi \ Internet Explorer \ iexplore.exe
(Google) C: \ Users \ Tom \ AppData \ Local \ Google \ Google Talk Plugin \ googletalkplugin.exe
(Adobe Systems Incorporated) C: \ Program Dosyaları (x86) \ Adobe \ Reader 11.0 \ Reader \ AcroRd32.exe
(Adobe Systems Incorporated) C: \ Program Dosyaları (x86) \ Adobe \ Reader 11.0 \ Reader \ AcroRd32.exe
Impossibile accedere al processo -> wlanext.exe
Impossibile accedere al processo -> conhost.exe
Impossibile accedere al processo -> TrustedInstaller.exe
Impossibile accedere al processo -> SearchProtocolHost.exe
Impossibile accedere al processo -> SearchFilterHost.exe
Impossibile accedere al processo -> svchost.exe
==================== Registrazione (whitelist) ======================== == =
(Se una voce viene aggiunta all'elenco delle correzioni, l'elemento del registro viene ripristinato al valore predefinito o rimosso. Il file non viene spostato.)
HKLM \ ... \ Run: [RTHDVCPL] => C: \ Program Files \ Realtek \ Audio \ HDA \ RtkNGUI64.exe [7202520 2013-08-20] (Realtek Semiconductor)
HKLM \ ... \ Run: [RtHDVBg] => C: \ Program Files \ Realtek \ Audio \ HDA \ RAVBg64.exe [1321688 2013-08-08] (Realtek Semiconductor)
HKLM \ ... \ Run: [RtHDVBg_PushButton] => C: \ Program Files \ Realtek \ Audio \ HDA \ RAVBg64.exe [1321688 2013-08-08] (Realtek Semiconductor)
HKLM \ ... \ Run: [SynTPEnh] => C: \ Program Dosyaları \ Synaptics \ SynTP \ SynTPEnh.exe [2780400 2013-09-14] (Synaptics Incorporated)
HKLM \ ... \ Run: [Broadcom Wireless Manager user interface] => C: \ Program Files \ Dell \ DW WLAN Card \ WLTRAY.exe [8921600 2013-10-23] (Dell Inc.)
HKLM \ ... \ Run: [QuickSet] => c: \ Program Files \ Dell \ QuickSet \ QuickSet.exe [5774664 2013-09-11] (Dell Inc.)
HKLM \ ... \ Run: [IAStorIcon] => C: \ Program Files \ Intel \ Intel (R) Rapid Storage Technology \ IAStorIcon.exe [287592 2013-08-31] (Intel Corporation)
HKLM \ ... \ Run: [MSC] => c: \ Programmi \ Microsoft Security Client \ msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM \ ... \ Çalıştır: [Logitech Download Assistant] => C: \ Windows \ system32 \ rundll32.exe C: \ Windows \ System32 \ LogiLDA.dll, LogiFetch
HKLM-x32 \ ... \ Run: [USB3MON] => C: \ Program Files (x86) \ Intel \ Intel (R) USB 3.0 extensible Host Controller Driver \ Application \ iusb3mon.exe [292848 2013-09-05 ] (Intel Foundation)
HKLM-x32 \ ... \ Run: [Dell Webcam Central] => C: \ Programmi (x86) \ Dell Webcam \ Dell Webcam Central \ WebcamDell2.exe [577024 2012-03-07] (Creative Technology Ltd)
HKLM-x32 \ ... \ Run: [CanonQuickMenu] => C: \ Programmi (x86) \ Canon \ Quick Menu \ CNQMMAIN.EXE [1279120 2012-09-27] (CANON INC.)
HKLM-x32 \ ... \ Run: [RazerCortex] => C: \ Program Dosyaları (x86) \ Razer \ Razer Cortex \ RazerCortex.exe -autorun
HKLM-x32 \ ... \ Run: [Dropbox] => C: \ Programmi (x86) \ Dropbox \ Client \ Dropbox.exe [3785536 2018-11-06] (Dropbox, Inc.)
HKLM-x32 \ ... \ RunOnce: [GrpConv] => grpconv -o
Winlogon \ Notify \ igfxcui: C: \ Windows \ System32 \ igfxdev.dll (Intel Corporation)
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ ... \ Run: [sysctrl] => C: \ Users \ Tom \ AppData \ Local \ Music Toolbar \ Datamngr \ sysctrl.exe [ 70168 2014-06-25) (iMesh Inc)
HKU \ S-1-5-21-2528572-1064671646-1800406956-1001 \ ... \ Run: [sysctrl64] => C: \ Users \ Tom \ AppData \ Local \ Music Toolbar \ Datamngr \ x64 \ sysctrl. exe [82456 2014-06-25] (iMesh Inc)
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ ... \ Run: [sysctrlc] => C: \ Users \ Tom \ AppData \ Local \ Music Toolbar \ Datamngr \ DatamngrCoordinator.exe [ 3823128 2014-06-25] (iMesh Inc)
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ ... \ Run: [BRS] => C: \ Users \ Tom \ AppData \ Local \ WSE_Astromenda \ BRS \ brs.exe [1173504 2014 -08-08] ()
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ ... \ Run: [Google Update] => C: \ Users \ Tom \ AppData \ Local \ Google \ Update \ 1.3.33.17 \ GoogleUpdateCore .exe [601680 2018-05-19] (Google Inc.)
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ ... \ Run: [GoogleChromeAutoLaunch_5189939A0645355218FFECE1F1491836] => C: \ Users \ Tom \ AppData \ Local \ Chromium \ Application \ chrome.exe [663552 2015 -06-28] (autori di Chrome)
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ ... \ Run: [Steam] => C: \ Program Files (x86) \ Steam \ steam.exe [3208992 2018-10-11 ] (Valve Corporation)
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ ... \ Run: [World of Tanks] => "C: \ Games \ World_of_Tanks \ WargamingGameUpdater.exe"
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ ... \ Run: [KakaoTalk] => "C: \ Programmi (x86) \ Cocoa \ KakaoTalk \ KakaoTalk.exe" -bystartup
HKU \ S-1-5-18 \ ... \ RunOnce: [JavaInstallRetry] => RUNONCE = 1 SPONSOR = 0
Lsa: [Pacchetti di notifica] scecli c: \ Program Files \ WIDCOMM \ Bluetooth Software \ BtwProximityCP.dll
Avvio: C: \ ProgramData \ Microsoft \ Windows \ Start Menu \ Programs \ Startup \ Bluetooth.lnk [2014-03-14]
ShortcutTarget: Bluetooth.lnk -> C: \ Programmi \ WIDCOMM \ Bluetooth Software \ BTTray.exe (Broadcom Corporation.)
GroupPolicy: Restriction - Chrome <==== DİKKAT
GroupPolicy \ User: Restriction? <==== DİKKAT
GroupPolicyUsers \ S-1-5-21-252852572-1064671646-1800406956-1001 \ Utente: Limitazione <==== DİKKAT
CHR HKLM \ SOFTWARE \ Policies \ Google: restrizione <==== DİKKAT
==================== Internet (autorizzato) =====================
(Se un elemento è incluso nell'elenco delle correzioni, se è un elemento del registro, viene rimosso o ripristinato all'impostazione predefinita.)
Tcpip \ Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip \ .. \ Interfaces \ {D501FE14-C8C6-42EF-90C4-FD36AA6C8729}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Internet Explorer:
==================
HKLM \ Software \ Microsoft \ Internet Explorer \ Main, pagina iniziale = hxxp: //go.microsoft.com/fwlink/? LinkID = 617911 & ResetID = 131130558221447530 & GUID = DBCFEA2E-669E-4FEF-ADAA-0257FE0762CC
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ Software \ Microsoft \ Internet Explorer \ Main, pagina iniziale = hxxp: //go.microsoft.com/fwlink/? LinkID = 617911 e ResetID = 131802431285607286 & GUID = DBCFEA2E -669E-4FEF-ADAA-0257FE0762CC
HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = hxxp: //dell13.msn.com/? Pc = DCJB
URLSearchHook: [S-1-5-21-252852572-1064671646-1800406956-1000] ATTENZIONE => Manca URLSearchHook predefinito
Ambiti di ricerca: HKLM -> DefaultScope {747A2953-1CA8-48AC-B80F-BB0DB9E62138} URL = hxxp: //
www.bing.com/search?q={SearchTerms} formu = MSSEDF vedi pc = MSSE
Ambiti di ricerca: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Ambiti di ricerca: HKLM -> {747A2953-1CA8-48AC-B80F-BB0DB9E62138} URL = hxxp: //
www.bing.com/search?q={SearchTerms} formu = MSSEDF vedi pc = MSSE
Ambiti di ricerca: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> DefaultScope {747A2953-1CA8-48AC-B80F-BB0DB9E62138} URL = hxxp: //
www.bing.com/search?q={SearchTerms} formu = MSSEDF vedi pc = MSSE
SearchScopes: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> OldSearch URL = hxxp: //searchinterneat-a.akamaihd.net/s denk = U0EeE1xZE1oZB1ZEfQleBFpCGAYQbV0AAF9cFVcQchRaUVtBDA1BIVtcVFhFRVAQcB9aFQQTSEcFME0FCFwEURNNfWtdEkwdVUZrNVs = & q = {} searchTerms
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {1b31c9d2-7135-442b-bb93-7c002172adc6) URL = hxxp: //
www.bing.com/search?q={SearchTerms} formu = MSSEDF vedi pc = MSSE
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {295E555F-A5F0-42ED-917A-617F365F50E9} URL = hxxp: //search.yahoo.com/yhs/search? Hspart = DDC e hsimp = YHS-ddc_bd e tip = bl-a-dd__alt__ddc_dss_bd_com e p = {searchTerms}
Arama Kapsamları: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = hxxp: //rocket-find.com/results.php? F = 4 già q = {} searchTerms a = rckt_frmr_14_26_ff sono già cD = 2XzuyEtN2Y1L1Qzu0E0C0FyE0B0Bzz0DtB0FzyyByC0C0DtAtN0D0Tzu0SzytCtDtN1L2XzutBtFtBtCtFzztFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyB0Azz0E0F0E0C0DtGtCyDyEtBtG0B0AzzyBtGtDyC0E0DtGtDtA0EtDzz0AyByE0AyE0DyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyEzz0AyB0ByCtAtGzz0A0D0EtGyB0AtByCtG0A0B0FzytGtA0E0Azy0CtBtAzytA0EzzyE2Q ve CR = 1.797.486,999 mila già IR =
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {747A2953-1CA8-48AC-B80F-BB0DB9E62138} URL = hxxp: //
www.bing.com/search?q={SearchTerms} formu = MSSEDF vedi pc = MSSE
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp: //rocket-find.com/results.php? F = 4 e q = {} searchTerms a = rckt_frmr_14_26_ff e cd = 2xzuyetn2y1l1qzu0e0c0fye0b0bzz0dtb0fzyybyc0c0dtatn0d0tzu0szytctdtn1l2xzutbtftbtctftctctftdtn1l1czutcyetbzytdyd1v1ttn1l1g1b1v1n2y1l1qzu2std0bta0ayd0ctdyetg0aybybtatgzzyd0b0ctgyctc0e0ftgtc0btatd0f0bye0a0e0f0byd2qtn1m1f1b2z1v1n2y1l1qzu2stcyezz0ayb0byctatgzz0a0d0etgyb0atbyctg0a0b0fzytgta0e0azy0ctbtazyta0ezzye2q e IR e CR = 1.712.688,768 mila =
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {80c554b9-c7f8-4a21-9471-06d606da78a2) URL = hxxp: //
www.bing.com/search?q={SearchTerms} formu = MSSEDF vedi pc = MSSE
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2000} URL = hxxp: //dts.search.ask.com/sr? Src = IEB e GCT = ds & appid = & systemId = & v = a15946-1205 & apn_uid = 4431050210474885 & apn_dtid = IME001 e o = APN10653 e apn_ptnrs = AGE e q = {searchTerms}
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = hxxp: //dts.search.ask.com/sr? Src = IEB & GCT = ds & appid = 1066 & systemId = 1 & v = n13124-409 & apn_uid = 9434405932554208 & apn_dtid = IME001 & o = APN10653 & apn_ptnrs = AGE & q = {searchTerms}
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {a62abdee-78a2-4ddb-9355-1c334abd6e43) URL = hxxp: //searchinterneat-a.akamaihd.net/s? Eq = U0EeE1xZE1oZB1ZEfQleBFpCGAYQbV0AAF9cFVcQchRaUVtBDA1BIVtcVFhFRVAQcB9aFQQTSEcFME0FCFwEURNNfWtdEkwdVUZrNVs = ricerca q
Ambiti di ricerca: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> {f7bb050c-e116-44da-89c2-6f2b68c54836) URL = hxxp: //
www.bing.com/search?q={SearchTerms} formu = MSSEDF vedi pc = MSSE
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C: \ Program Dosyaları \ Canon \ Easy-WebPrint EX \ ewpexbho.dll [2014-07-07] (CANON INC. )
BHO: Gestore della cache dei documenti di Office -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C: \ Program Files \ Microsoft Office \ Office14 \ URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C: \ Program Dosyaları (x86) \ Canon \ Easy-WebPrint EX \ ewpexbho.dll [07/07/2014 ] (CANON INC.)
BHO-x32: Java (tm) Plug-in SSV Helper -> (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) -> C: \ Programmi (x86) \ Java \ jre7 \ bin \ ssv.dll (2014-08-11 ] (Oracle Corporation)
BHO-x32: gestore della cache dei documenti di Office -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C: \ Program Files (x86) \ Microsoft Office \ Office14 \ URLREDIR.DLL [2013-03-06] (Microsoft Corporation )
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C: \ Programmi (x86) \ Microsoft \ BingBar \ 7.1.362.0 \ BingExt.dll [2012-02-13] ( Azienda Microsoft.)
BHO-x32: Java (tm) Plugin 2 SSV Helper -> (DBC80044-A445-435b-BC74-9C25C1C588A9) -> C: \ Programmi (x86) \ Java \ jre7 \ bin \ jp2ssv.dll (2014-08- 11) (Oracle Corporation)
Barra degli strumenti: HKLM - Canon Easy WebPrint EX - (759D9886-0C6F-4498-BAB6-4A5F47C6C72F) - C: \ Programmi \ Canon \ Easy-WebPrint EX \ ewpexhlp.dll [07/07/2014] (CANON INC.)
Barra degli strumenti: HKLM-x32 - Canon Easy-WebPrint EX - (759D9886-0C6F-4498-BAB6-4A5F47C6C72F) - C: \ Programmi (x86) \ Canon \ Easy-WebPrint EX \ ewpexhlp.dll (07/07/2014 ] (CANON INC.)
Barra degli strumenti: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C: \ Programmi (x86) \ Microsoft \ BingBar \ 7.1.362.0 \ BingExt.dll [2012-02-13] ( Microsoft Corporation.)
Barra degli strumenti: HKU \ S-1-5-21-252852572-1064671646-1800406956-1001 -> Canon Easy-WebPrint EX - (759D9886-0C6F-4498-BAB6-4A5F47C6C72F) - C: \ Program Files \ Canon \ Easy- WebPrint EX \ ewpexhlp.dll [07/07/2014] (CANON INC.)
Gestore: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Nessun file
FireFox:
========
Percorso profilo FF: C: \ Users \ Tom \ AppData \ Roaming \ Mozilla \ Firefox \ Profiles \ 6mnczrhu.default-1509552401858 [2018-11-10]
FF Ana Sayfası: Mozilla \ Firefox \ Profiles \ 6mnczrhu.default-1509552401858 -> hxxps: //id.search.yahoo.com/yhs/web? Hspart = Elm & hsimp = YHS-001 & type = hdr_s_17_44_orgnl & param1 = 1 & param2 = f% 26% 3D% 3DFirefox% 26cc% 3Did% 26pa% 3Dhodor% 26cd% 3D2XzuyEtN2Y1L1Qzu0E0C0FyE0B0Bzz0DtB0FzyyByC0C0DtAtN0D0Tzu0StBtCtAyEtN1L2XzutAtFtAtBtFtCtFyCyDtN1L1Czu1M1Q1CtAtBtFtAtFtDtN1L1G1B1V1N2Y1L1Qzu2StB0BtC0EtD0F0EtAtGyB0AtC0CtG0CtAtByEtGyCzy0AtBtGtC0ByCzzyEzyzyyE0A0DtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0E0D0F0A0FtA0CzytGzy0EyDyCtGyE0CyDyEtGzztCtDtDtGyEzytC0DtCtD0E0FyByBtAyE2QtN0A0LzuyEtN0D0T0S1P1RzutCyDtDzyzzyEtDtBtCyB% 26cr% 3D1609883092% 26a% 3Dhdr_s_17_44_orgnl% 26os_ver% 3D6.1% 26os% 3DWindows% 2B7% 2BProfessional
Plugin di ricerca FF: C: \ Users \ Tom \ AppData \ Roaming \ Mozilla \ Firefox \ Profiles \ 6mnczrhu.default-1509552401858 \ searchplugins \ yhs.xml [2018-01-25]
FF HKLM-x32 \ ... \ Thunderbird \ Extensions: [msktbird@mcafee.com] - C: \ Program Files \ McAfee \ MSK => non trovato
Plugin FF: @ adobe.com / FlashPlayer -> C: \ Windows \ system32 \ Macromed \ Flash \ NPSWF64_31_0_0_122.dll [2018-10-10] ()
Plugin FF: @ microsoft.com / GENUINE -> disabilitato [Nessun file]
Plugin FF: @ Microsoft.com / NpCtrl, versione = 1.0 -> c: \ Program Files \ Microsoft Silverlight \ 5.1.50907.0 \ npctrl.dll [2017-05-03] (Microsoft Corporation)
Plugin FF: @ microsoft.com / OfficeAuthz, versione = 14.0 -> C: \ PROGRA ~ 1 \ MICROS ~ 1 \ Office14 \ NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Eklentisi-x32: @ adobe.com / FlashPlayer -> C: \ Windows \ SysWOW64 \ Macromed \ Flash \ NPSWF32_31_0_0_122.dll [2018-10-10] ()
FF Plugin-x32: @ canon.com / EPPEX -> C: \ Programmi (x86) \ Canon \ My Image Garden \ AddOn \ CIG \ npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @ intel-webapi.intel.com / Intel WebAPI ipt; versione = 3.5.29 -> C: \ Program Files (x86) \ Intel \ Intel (R) Management Engine Components \ IPT \ npIntelWebAPIIPT.dll [2013-06-01] (Intel Corporation)
FF Plugin-x32: @ intel-webapi.intel.com / Intel WebAPI updater -> C: \ Program Files (x86) \ Intel \ Intel (R) Management Engine Components \ IPT \ npIntelWebAPIUpdater.dll [2013-06-01] (Intel Foundation)
FF Plugin-x32: @ java.com / DTPlugin, versione = 10.67.2 -> C: \ Program Files (x86) \ Java \ jre7 \ bin \ dtplugin \ npDeployJava1.dll [2014-08-11] (Oracle Corporation)
FF Plugin-x32: @ java.com / JavaPlugin, versione = 10.67.2 -> C: \ Program Files (x86) \ Java \ jre7 \ bin \ plugin2 \ npjp2.dll [2014-08-11] (Oracle Corporation)
FF Plugin-x32: @ microsoft.com / GENUINE -> disabilitato [Nessun file]
FF Plugin-x32: @ Microsoft.com / NpCtrl, versione = 1.0 -> c: \ Program Files (x86) \ Microsoft Silverlight \ 5.1.50907.0 \ npctrl.dll [2017-05-03] (Microsoft Corporation)
FF Plugin-x32: @ microsoft.com / OfficeAuthz, versione = 14.0 -> C: \ PROGRA ~ 2 \ MICROS ~ 1 \ Office14 \ NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @ microsoft.com / SharePoint, versione = 14.0 -> C: \ PROGRA ~ 2 \ MICROS ~ 1 \ Office14 \ NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @ videolan.org / vlc, versione = 2.2.8 -> C: \ Program Files (x86) \ VideoLAN \ VLC \ npvlc.dll [2017-11-29] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C: \ Programmi (x86) \ Adobe \ Reader 11.0 \ Reader \ AIR \ nppdf32.dll [2017-11-01] (Adobe Systems Inc.)
FF Plugin HKU \ S-1-5-21-252852572-1064671646-1800406956-1001: @ talk.google.com / GoogleTalkPlugin -> C: \ Users \ Tom \ AppData \ Roaming \ Mozilla \ plugins \ npgoogletalk.dll [2015 -12-08] (Google)
FF Plugin HKU \ S-1-5-21-252852572-1064671646-1800406956-1001: @ talk.google.com / O1DPlugin -> C: \ Users \ Tom \ AppData \ Roaming \ Mozilla \ plugins \ npo1d.dll [2015 -12-08] (Google)
Plugin FF HKU \ S-1-5-21-252852572-1064671646-1800406956-1001: @ tools.google.com / Google Update; versione = 3 -> C: \ Users \ Tom \ AppData \ Local \ Google \ Update \ 1.3.33.17 \ npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
Plugin FF HKU \ S-1-5-21-252852572-1064671646-1800406956-1001: @ tools.google.com / Google Update; versione = 9 -> C: \ Users \ Tom \ AppData \ Local \ Google \ Update \ 1.3.33.17 \ npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin Program Files / Appdata: C: \ Users \ Tom \ AppData \ Roaming \ mozilla \ plugins \ npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles / Appdata: C: \ Users \ Tom \ AppData \ Roaming \ mozilla \ plugins \ npo1d.dll [2015-12-08] (Google)
==================== Servizi (autorizzati) ====================
(Se una voce viene aggiunta all'elenco delle correzioni, viene rimossa dal registro. Il file non verrà spostato a meno che non sia elencato separatamente).
S2 dbupdat; C: \ Program Dosyaları (x86) \ Dropbox \ Update \ DropboxUpdate.exe [143144 2018-11-09] (Dropbox, Inc.)
S3 dbupdatem; C: \ Program Dosyaları (x86) \ Dropbox \ Update \ DropboxUpdate.exe [143144 2018-11-09] (Dropbox, Inc.)
R2 DbxSvc; C: \ Windows \ system32 \ DbxSvc.exe [51024 2018-11-06] (Dropbox, Inc.)
R2 è IAStorDataMgrSvc; C: \ Programmi \ Intel \ Intel (R) Rapid Storage Technology \ IAStorDataMgrSvc.exe [15720 2013-08-31] (Intel Corporation)
R2 IJPLMSVC; C: \ Programmi (x86) \ Canon \ IJPLM \ IJPLMSVC.EXE [140936 2013-05-15] ()
Interfaccia del servizio di licenza di autorizzazione Intel® R2; c: \ Program Files \ Intel \ iCLS Client \ HeciServer.exe [733696 2013-05-12] (Intel (R) Corporation) [File non firmato]
Interfaccia TCP IP del servizio di licenza in primo piano S3 Intel (R); c: \ Programmi \ Intel \ iCLS Client \ SocketHeciServer.exe [822232 2013-05-12] (Intel (R) Corporation)
R2 jhi_service; C: \ Programmi (x86) \ Intel \ Intel (R) Management Engine Components \ DAL \ jhi_service.exe [169432 2013-06-01] (Intel Corporation)
R2 lmhostları; C: \ Windows \ system32 \ svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 lmhostları; C: \ Windows \ SysWOW64 \ svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MsMpSvc; c: \ Program Dosyaları \ Microsoft Security Client \ MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c: \ Programmi \ Microsoft Security Client \ NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NlaSvc; C: \ Windows \ System32 \ svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C: \ Windows \ SysWOW64 \ svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C: \ Windows \ system32 \ svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C: \ Windows \ SysWOW64 \ svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 RtkAudioService; C: \ Programmi \ Realtek \ Audio \ HDA \ RtkAudioService64.exe [246488 2013-06-19] (Realtek Semiconductor)
R2 SftService; C: \ Programmi (x86) \ Dell Backup and Recovery \ SftService.exe [1915920 2013-11-22] (SoftThinks SAS)
S3 WinDefend; C: \ Programmi \ Windows Defender \ mpsvc.dll [1011712 2014-03-14] (Microsoft Corporation)
R2 è wltrysvc; C: \ Programmi \ Dell \ DW Scheda WLAN \ bcmwltry.exe [6170624 2013-10-23] (Dell Inc.) [File non firmato]
===================== Driver (autorizzati) ======================
(Se una voce viene aggiunta all'elenco delle correzioni, viene rimossa dal registro. Il file non verrà spostato a meno che non sia elencato separatamente).
R0 iaStorF; C: \ Windows \ System32 \ drivers \ iaStorF.sys [28008 2013-08-29] (Intel Corporation)
R3 MEIx64; C: \ Windows \ System32 \ DRIVERS \ TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R0 MpFiltre; C: \ Windows \ System32 \ DRIVERS \ MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C: \ Windows \ System32 \ DRIVERS \ NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 PCDSRVC {D3412D80-CF3B4A27-06020200} _0; c: \ program dosyaları \ dell \ pcdsrvc_x64.pkms [25584 2013-08-10] (PC-Doctor, Inc.)
S3 SmbDrv; C: \ Windows \ system32 \ drivers \ Smb_driver_AMDASF.sys [30448 2013-09-14] (Synaptics Incorporated)
R3 SmbDrvl; C: \ Windows \ System32 \ DRIVERS \ Smb_driver_Intel.sys [34544 2013-09-14] (Synaptics Incorporated)
S1 mmaennbv; \ ?? \ C: \ Windows \ system32 \ drivers \ mmaennbv.sys [X]
S1 MpKs19b5e44a7; \ ?? \ c: \ ProgramData \ Microsoft \ Microsoft Anti-Malware \ Definition Updates \ {06717DA4-6C54-415D-AA4E-217CE011D206} \ MpKsl9b5e44a7.sys [X]
S1 niatpksbo; \ ?? \ C: \ Windows \ system32 \ drivers \ niatpxbo.sys [X]
S3 OATool; \ ?? \ C: \ Users \ ADMINI ~ 1 \ AppData \ Local \ Temp \ OAToolx64.sys [X] <==== DİKKAT
S1 spaltjok; \ ?? \ C: \ Windows \ system32 \ drivers \ spaltjok.sys [X]
S1 szftsrbn; \ ?? \ C: \ Windows \ system32 \ drivers \ szftsrbn.sys [X]
==================== NetSvcs (Whitelist) ===================
(Se una voce viene aggiunta all'elenco delle correzioni, viene rimossa dal registro. Il file non verrà spostato a meno che non sia elencato separatamente).
==================== File e cartelle creati in un mese ========
(Se una voce viene aggiunta all'elenco delle correzioni, il file / cartella verrà spostato.)
Errore (1) durante la lettura del file: "C: \ Users \ Tom \ Downloads \ Titanfall Rap, JT Machinima, THK e Borderline Disaster -"
10/11/2018 10:51 - 10/11/2018 10:54 - 000025461 _____ C: \ Users \ Tom \ Downloads \ FRST.txt
10/11/2018 10:47 - 10/11/2018 10:47 - 000000000 ____D C: \ Users \ Tom \ Downloads \ FRST-OlderVersion
10/11/2018 10:46 - 10/11/2018 10:51 - 000000000 ____D C: \ FRST
10/11/2018 10:45 - 10/11/2018 10:51 - 002415616 _____ (Farbar) C: \ Users \ Tom \ Downloads \ FRST64.exe
2018-11-09 18:08 - 2018-11-09 18:08 - 000000000 ____D C: \ ProgramData \ Microsoft \ Windows \ Menu Start \ Programmi \ Dropbox
09-11-2018 18:05 - 09-11-2018 18:05 - 000000000 ____D C: \ Users \ jl \ AppData \ Roaming \ Dropbox
2018-11-09 18:03 - 2018-11-10 10:08 - 000000900 _____ C: \ Windows \ Tasks \ DropboxUpdateTaskMachineUA.job
09-11-2018 18:03 - 09-11-2018 18:08 - 000000896 _____ C: \ Windows \ Tasks \ DropboxUpdateTaskMachineCore.job
09-11-2018 18:02 - 09-11-2018 18:09 - 000000000 ____D C: \ Programmi (x86) \ Dropbox
09-11-2018 17:44 - 09-11-2018 18:14 - 000000000 ____D C: \ Users \ Tom \ AppData \ Local \ Dropbox
09-11-2018 17:44 - 09-11-2018 18:02 - 000696608 _____ (Dropbox, Inc.) C: \ Users \ Tom \ Downloads \ DropboxInstaller.exe
09-11-2018 17:44 - 09-11-2018 17:44 - 000000000 ____D C: \ ProgramData \ Dropbox
06/11/2018 20:06 - 06/11/2018 20:06 - 000051024 _____ (Dropbox, Inc.) C: \ Windows \ system32 \ DbxSvc.exe
06/11/2018 20:06 - 06/11/2018 20:06 - 000047768 _____ (Dropbox, Inc.) C: \ Windows \ system32 \ Sürücüler \ dbx-dev.sys
06/11/2018 20:06 - 06/11/2018 20:06 - 000047768 _____ (Dropbox, Inc.) C: \ Windows \ system32 \ Sürücüler \ dbx-canary.sys
06/11/2018 20:06 - 06/11/2018 20:06 - 000045640 _____ (Dropbox, Inc.) C: \ Windows \ system32 \ Sürücüler \ dbx-stable.sys
12-10-2018 11:49 - 12-10-2018 11:49 - 000000020 _____ C: \ Users \ Tom \ Desktop \ SOUL.txt
==================== File e cartelle modificati per un mese ========
(Se una voce viene aggiunta all'elenco delle correzioni, il file / cartella verrà spostato.)
10/11/2018 10:42 - 05/11/2017 07:06 - 000000266 _____ C: \ Windows \ Tasks \ {58F8473A-A6D6-EB55-AF4D-772F0358E8D9} .job
10/11/2018 10:42 - 04/09/2015 18:04 - 000000000 ____D C: \ Kullanıcılar \ Tom \ AppData \ Local \ {357E0322-11D6-6F9A-7C4E-4A725826B6EA}
10/11/2018 10:24 - 14/07/2016 00:03 - 000000266 _____ C: \ Windows \ Tasks \ {1B7B29A5-081A-DBB0-79E4-101AD15B16AA} .job
10/11/2018 09:03 - 18/09/2016 09:25 - 000000266 _____ C: \ Windows \ Tasks \ {4B63B3D9-A905-B81E-883E-3B544CC01479} .job
10/11/2018 09:03 - 29/03/2016 20:03 - 000000262 _____ C: \ Windows \ Tasks \ Update_Task.job
10/11/2018 07:46 - 14/07/2009 10:20 - 000000000 ____D C: \ Windows \ system32 \ NDF
10/11/2018 05:26 - 19/11/2016 05:51 - 000000000 ____D C: \ Users \ Tom \ AppData \ LocalLow \ Mozilla
10/11/2018 05:26 - 15/07/2014 19:08 - 000000000 ____D C: \ ProgramData \ Datamngr
10/11/2018 05:11 - 25/01/2018 06:40 - 000000000 ____D C: \ Users \ Tom \ AppData \ Local \ Direc
09-11-2018 19:42 - 16-04-2014 10:12 - 000000000 ____D C: \ Programmi (x86) \ Servizio di manutenzione Mozilla
09-11-2018 19:41 - 04-12-2017 05:08 - 000000000 ____D C: \ Programmi (x86) \ Mozilla Firefox
09/11/2018 19:39 - 20/05/2014 17:23 - 000000000 ____D C: \ Users \ Tom \ AppData \ Local \ Unity
09/11/2018 19:37 - 29/06/2014 10:30 - 000000000 ____D C: \ Users \ Tom \ AppData \ Local \ Rocket
09-11-2018 17:39 - 16-04-2017 16:55 - 000000000 ____D C: \ Users \ Tom \ AppData \ Roaming \ Microsoft \ Windows \ Start Menu \ Programmi \ Steam
2018-11-09 15:10 - 2009-07-14 11:45 - 000030704 ____H C: \ Windows \ system32 \ 7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
09/11/2018 15:10 - 14/07/2009 11:45 - 000030704 ____H C: \ Windows \ system32 \ 7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
16-10-2018 04:48 - 21/11/2010 10:27 - 000559880 ____N (Microsoft Corporation) C: \ Windows \ system32 \ MpSigStub.exe
12/10/2018 16:33 - 06/11/2016 21:35 - 000000000 ____D C: \ Users \ Tom \ AppData \ Local \ CrossCode
12-10-2018 14:24 - 16-04-2017 12:44 - 000000000 ____D C: \ Programmi (x86) \ Steam
12-10-2018 07:20 - 14-03-2014 09:25 - 000000000 ____D C: \ Programmi (x86) \ Dell Backup and Recovery
2018-10-12 07:17 - 2009-07-14 12:08 - 000000006 ____H C: \ Windows \ Tasks \ SA.DAT
11-10-2018 18:50 - 14-07-2009 10:20 - 000000000 ____D C: \ Windows \ rescache
11-10-2018 08:43 - 16-04-2014 06:09 - 000000000 ____D C: \ Users \ jl
2018-10-11 03:51 - 2009-07-14 12:13 - 000783606 _____ C: \ Windows \ system32 \ PerfStringBackup.INI
2018-10-11 03:51 - 2009-07-14 10:20 - 000000000 ____D C: \ Windows \ inf
2018-10-11 03:44 - 2009-07-14 11:45 - 000342728 _____ C: \ Windows \ system32 \ FNTCACHE.DAT
11-10-2018 03:19 - 16-04-2014 06:42 - 000000000 ____D C: \ Windows \ system32 \ MRT
11-10-2018 03:13 - 16-04-2014 06:42 - 136745976 ____C (Microsoft Corporation) C: \ Windows \ system32 \ MRT.exe
11-10-2018 03:08 - 10-02-2011 21:33 - 000767916 _____ C: \ Windows \ SysWOW64 \ PerfStringBackup.INI
==================== File nella radice di alcune directory =======
12/03/2015 19:07 - 11/01/2015 19:07 - 000000032 ____R () C: \ ProgramData \ hash.dat
21-10-2016 18:39 - 21-10-2016 18:39 - 003187734 _____ () C: \ Users \ Tom \ AppData \ Roaming \ sb195.dat
13-12-2016 08:55 - 13-12-2016 08:55 - 003634196 _____ () C: \ Users \ Tom \ AppData \ Roaming \ sb476.dat
31/07/2014 08:47 - 09/09/2018 18:42 - 000000503 _____ () C: \ Users \ Tom \ AppData \ Roaming \ WB.CFG
02/12/2014 06:39 - 18/12/2014 00:39 - 000000001 _____ () C: \ Users \ Tom \ AppData \ Local \ DSI.DAT
02/12/2014 06:39 - 02/12/2014 06:39 - 000022528 _____ () C: \ Users \ Tom \ AppData \ Local \ dsisetup1488231282.exe
18/12/2014 00:39 - 18/12/2014 00:39 - 000022528 _____ () C: \ Users \ Tom \ AppData \ Local \ dsisetup3359250182.exe
25-03-2018 21:59 - 25-03-2018 21:59 - 000040960 _____ () C: \ Users \ Tom \ AppData \ Local \ Web Data
25-03-2018 21:59 - 25-03-2018 21:59 - 000000512 _____ () C: \ Users \ Tom \ AppData \ Local \ Web Data log
2017-12-13 02:46 - 2018-01-09 03:11 - 000000068 _____ () C: \ Users \ Tom \ AppData \ Local \ xdt9m2fvbr
File da spostare o eliminare:
====================
C: \ Windows \ Görevler \ {1B7B29A5-081A-DBB0-79E4-101AD15B16AA} .job
C: \ Windows \ Görevler \ {4B63B3D9-A905-B81E-883E-3B544CC01479} .job
C: \ Windows \ Tasks \ {58F8473A-A6D6-EB55-AF4D-772F0358E8D9} .job
Alcuni file in TEMP:
====================
22/05/2014 08:55 - 22/05/2014 08:55 - 002936832 _____ () C: \ Users \ Tom \ AppData \ Local \ Temp \ ffmpeg16.exe
29/05/2014 13:56 - 29/05/2014 13:57 - 017938608 _____ (Adobe Systems Incorporated) C: \ Users \ Tom \ AppData \ Local \ Temp \ fp_pl_pfs_installer-1.exe
24/05/2014 11:53 - 24/05/2014 11:54 - 017938608 _____ (Adobe Systems Incorporated) C: \ Users \ Tom \ AppData \ Local \ Temp \ fp_pl_pfs_installer.exe
16/05/2016 18:00 - 16/05/2016 18:01 - 000000000 _____ () C: \ Users \ Tom \ AppData \ Local \ Temp \ GUR280F.exe
23/01/2015 19:03 - 21/01/2015 06:32 - 002124520 _____ () C: \ Users \ Tom \ AppData \ Local \ Temp \ Helper.DLL
12/03/2015 19:08 - 12/03/2015 19:08 - 000058368 ____N () C: \ Users \ Tom \ AppData \ Local \ Temp \ jshortcut-3012483557483484761.dll
12/03/2015 19:40 - 12/03/2015 19:40 - 000058368 ____N () C: \ Users \ Tom \ AppData \ Local \ Temp \ jshortcut-7151043099465511510.dll
18/06/2013 23:53 - 18/06/2013 23:53 - 000865424 ____N (CANON INC.) C: \ Users \ Tom \ AppData \ Local \ Temp \ MSETUP4.EXE
11/04/2015 19:04 - 23/03/2015 07:33 - 001792744 _____ () C: \ Users \ Tom \ AppData \ Local \ Temp \ MusicAppHelper.DLL
10-03-2018 20:08 - 10-03-2018 20:08 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180310130822301.dll
10-03-2018 20:08 - 10-03-2018 20:08 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180310130823619.dll
10-03-2018 20:08 - 10-03-2018 20:08 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180310130824152.dll
10-03-2018 20:08 - 10-03-2018 20:08 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180310130824917.dll
10-03-2018 20:08 - 10-03-2018 20:08 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180310130832216.dll
10-03-2018 20:08 - 10-03-2018 20:08 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180310130835050.dll
10-03-2018 20:08 - 10-03-2018 20:08 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180310130851423.dll
11-03-2018 20:09 - 11-03-2018 20:09 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180311130926198.dll
2018-03-14 07:14 - 2018-03-14 07:14 - 001857024 _____ (Opera Software) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180314001435848.dll
15-03-2018 10:15 - 15-03-2018 10:15 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180315031541953.dll
15-03-2018 13:17 - 15-03-2018 13:17 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180315061702218.dll
2018-03-15 20:32 - 2018-03-15 20:32 - 001857024 _____ (Opera Software) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180315133218571.dll
16-03-2018 20:24 - 16-03-2018 20:24 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180316132440582.dll
2018-03-18 07:44 - 2018-03-18 07:44 - 001857024 _____ (Opera Software) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180318004447094.dll
2018-03-18 20:09 - 2018-03-18 20:09 - 001857024 _____ (Opera Software) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180318130924025.dll
21-03-2018 07:16 - 21-03-2018 07:16 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180321001604795.dll
21-03-2018 20:09 - 21-03-2018 20:09 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180321130925214.dll
22-03-2018 20:09 - 22-03-2018 20:09 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180322130924714.dll
2018-03-23 20:09 - 2018-03-23 20:09 - 001857024 _____ (Opera Software) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180323130924452.dll
24-03-2018 06:42 - 24-03-2018 06:42 - 001857024 _____ (Software Opera) C: \ Users \ Tom \ AppData \ Local \ Temp \ Opera_installer_180323234211738.dll
24-03-2018 20:09 - 24-03-2018 20:09 - 001857024 _____ (Software Opera)