Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

TR/Crypt.XPACK.Gen8 [Solved]


  • This topic is locked This topic is locked

#1
madimar

madimar

    Member

  • Member
  • PipPip
  • 13 posts
Dear all,
I just received an alert from Avira regarding this trojan. Doing some reasearch on the net I discovered your website and I hope you can help me to remove this malware. Up to now, I didn't notice any particular strange behavior apart yesterday when my system was suddenly stuck and I was forced to reboot to let it work decently.

This is the alert I received:

Virus or unwanted program 'TR/Crypt.XPACK.Gen8 [trojan]'
detected in file 'C:\Program Files (x86)\Common Files\microsoft shared\MSEnv\TextMgrP.dll.
Action performed: Deny access

Here below, OTL log:
OTL logfile created on: 06/02/2013 15:56:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\massimo\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

5,92 Gb Total Physical Memory | 1,31 Gb Available Physical Memory | 22,21% Memory free
11,83 Gb Paging File | 6,49 Gb Available in Paging File | 54,88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 363,00 Gb Total Space | 244,14 Gb Free Space | 67,26% Space Free | Partition Type: NTFS
Drive D: | 544,30 Gb Total Space | 426,67 Gb Free Space | 78,39% Space Free | Partition Type: NTFS

Computer Name: SAMSUNG | User Name: massimo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/02/06 15:52:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\massimo\Downloads\OTL.exe
PRC - [2013/01/24 09:06:40 | 011,184,480 | ---- | M] (SugarSync, Inc.) -- C:\Program Files (x86)\SugarSync\SugarSyncManager.exe
PRC - [2013/01/20 20:29:18 | 028,539,272 | ---- | M] (Dropbox, Inc.) -- C:\Users\massimo\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012/12/27 17:02:36 | 002,879,176 | ---- | M] (Samsung Electronics CO., LTD.) -- C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe
PRC - [2012/12/17 19:50:28 | 016,328,976 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe
PRC - [2012/12/14 16:49:28 | 000,824,232 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 16:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/12/13 14:26:20 | 003,290,896 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/12/05 15:40:02 | 000,597,880 | ---- | M] (BlueStack Systems, Inc.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe
PRC - [2012/12/05 15:39:26 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
PRC - [2012/12/05 15:39:08 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) -- C:\Program Files (x86)\BlueStacks\HD-Service.exe
PRC - [2012/12/05 15:39:04 | 000,366,456 | ---- | M] (BlueStack Systems) -- C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe
PRC - [2012/12/05 15:38:56 | 000,260,472 | ---- | M] (BlueStack Systems) -- C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe
PRC - [2012/12/05 15:38:54 | 000,375,672 | ---- | M] (BlueStack Systems) -- C:\Program Files (x86)\BlueStacks\HD-Network.exe
PRC - [2012/11/29 14:50:25 | 003,463,080 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012/10/30 10:03:54 | 004,471,416 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
PRC - [2012/08/08 09:30:05 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/05/30 19:55:26 | 001,112,968 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
PRC - [2012/05/08 09:34:32 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012/05/08 09:34:31 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012/05/02 07:03:44 | 002,279,304 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
PRC - [2012/04/25 12:18:10 | 000,784,264 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
PRC - [2012/02/13 14:02:24 | 000,031,624 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
PRC - [2012/01/31 14:56:48 | 001,640,328 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
PRC - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2011/09/02 19:08:34 | 000,410,911 | ---- | M] () -- C:\Program Files (x86)\BlueStacks\HD-Adb.exe
PRC - [2011/08/17 15:19:18 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2011/05/05 13:44:54 | 002,656,536 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/05/05 13:44:52 | 000,326,424 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2007/09/02 13:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe


========== Modules (No Company Name) ==========

MOD - [2013/02/06 08:41:32 | 001,024,616 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\windows._cacheinvalidation.pyd
MOD - [2013/02/06 08:41:32 | 000,792,576 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\wx._gdi_.pyd
MOD - [2013/02/06 08:41:32 | 000,571,392 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\pysqlite2._sqlite.pyd
MOD - [2013/02/06 08:41:32 | 000,354,304 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\pythoncom26.dll
MOD - [2013/02/06 08:41:32 | 000,263,168 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32com.shell.shell.pyd
MOD - [2013/02/06 08:41:32 | 000,153,088 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\pyexpat.pyd
MOD - [2013/02/06 08:41:32 | 000,096,256 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32api.pyd
MOD - [2013/02/06 08:41:32 | 000,086,016 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\_elementtree.pyd
MOD - [2013/02/06 08:41:32 | 000,073,728 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\_ctypes.pyd
MOD - [2013/02/06 08:41:32 | 000,070,656 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\wx._html2.pyd
MOD - [2013/02/06 08:41:32 | 000,040,448 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\_socket.pyd
MOD - [2013/02/06 08:41:32 | 000,023,040 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32ts.pyd
MOD - [2013/02/06 08:41:32 | 000,017,920 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32profile.pyd
MOD - [2013/02/06 08:41:32 | 000,011,776 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32crypt.pyd
MOD - [2013/02/06 08:41:31 | 001,169,408 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\wx._core_.pyd
MOD - [2013/02/06 08:41:31 | 001,056,256 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\wx._controls_.pyd
MOD - [2013/02/06 08:41:31 | 000,807,424 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\wx._windows_.pyd
MOD - [2013/02/06 08:41:31 | 000,731,136 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\wx._misc_.pyd
MOD - [2013/02/06 08:41:31 | 000,645,120 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\_ssl.pyd
MOD - [2013/02/06 08:41:31 | 000,585,728 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\unicodedata.pyd
MOD - [2013/02/06 08:41:31 | 000,311,808 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\_hashlib.pyd
MOD - [2013/02/06 08:41:31 | 000,121,856 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\wx._wizard.pyd
MOD - [2013/02/06 08:41:31 | 000,111,104 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32file.pyd
MOD - [2013/02/06 08:41:31 | 000,110,592 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32security.pyd
MOD - [2013/02/06 08:41:31 | 000,110,592 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\pywintypes26.dll
MOD - [2013/02/06 08:41:31 | 000,039,424 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32inet.pyd
MOD - [2013/02/06 08:41:31 | 000,036,352 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32process.pyd
MOD - [2013/02/06 08:41:31 | 000,022,528 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32pdh.pyd
MOD - [2013/02/06 08:41:31 | 000,017,920 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\win32event.pyd
MOD - [2013/02/06 08:41:31 | 000,011,776 | ---- | M] () -- C:\Users\massimo\AppData\Local\Temp\_MEI42922\select.pyd
MOD - [2013/02/03 23:58:47 | 012,459,888 | ---- | M] () -- C:\Users\massimo\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.138\pepflashplayer.dll
MOD - [2013/01/26 03:35:06 | 000,460,240 | ---- | M] () -- C:\Users\massimo\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
MOD - [2013/01/26 03:35:04 | 004,012,496 | ---- | M] () -- C:\Users\massimo\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
MOD - [2013/01/26 03:34:19 | 000,597,968 | ---- | M] () -- C:\Users\massimo\AppData\Local\Google\Chrome\Application\24.0.1312.57\libglesv2.dll
MOD - [2013/01/26 03:34:18 | 000,124,368 | ---- | M] () -- C:\Users\massimo\AppData\Local\Google\Chrome\Application\24.0.1312.57\libegl.dll
MOD - [2013/01/26 03:34:16 | 001,552,848 | ---- | M] () -- C:\Users\massimo\AppData\Local\Google\Chrome\Application\24.0.1312.57\ffmpegsumo.dll
MOD - [2013/01/24 16:13:27 | 000,643,072 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\HD-Agent\93a86e2f9e5a785454a51696aab41220\HD-Agent.ni.exe
MOD - [2013/01/24 16:13:25 | 000,155,136 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\JSON\bfe1111ccd8ba885611c06bfadb43908\JSON.ni.dll
MOD - [2013/01/09 23:05:36 | 000,212,992 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\68f617caf670fefc0be769a294dc4ffd\System.ServiceProcess.ni.dll
MOD - [2013/01/09 23:05:15 | 011,833,344 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\0ac577a8ad6528ff03b50db5eeeac8be\System.Web.ni.dll
MOD - [2013/01/09 23:03:58 | 012,436,480 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\865d2bf19a7af7fab8660a42d92550fe\System.Windows.Forms.ni.dll
MOD - [2013/01/09 23:03:42 | 001,592,832 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013/01/09 23:02:50 | 005,453,312 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013/01/09 23:02:39 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013/01/09 23:02:35 | 007,989,760 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013/01/09 22:50:20 | 011,493,376 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012/08/27 21:33:32 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/08/27 21:33:08 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/10/26 01:08:06 | 000,204,800 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
MOD - [2011/09/08 19:40:10 | 001,645,056 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
MOD - [2011/09/02 19:08:34 | 000,410,911 | ---- | M] () -- C:\Program Files (x86)\BlueStacks\HD-Adb.exe
MOD - [2011/02/17 00:03:20 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll
MOD - [2010/11/13 00:50:53 | 000,307,200 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
MOD - [2007/09/02 13:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe
MOD - [2007/09/02 13:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.dll
MOD - [2006/08/12 11:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/04/18 05:58:54 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/12/02 12:12:12 | 000,165,456 | ---- | M] (Samsung Electronics) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc2.exe -- (Samsung UPD Service2)
SRV:64bit: - [2011/09/23 07:20:42 | 000,079,664 | ---- | M] (Diskeeper Corporation) [Auto | Running] -- C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe -- (ExpressCache)
SRV:64bit: - [2011/05/10 14:12:52 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2010/09/22 10:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/07/07 02:43:14 | 000,048,128 | ---- | M] (Broadcom Corporation) [Auto | Running] -- C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE -- (wltrysvc)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2013/01/20 08:56:09 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/10 16:50:36 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/08 12:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/12/27 17:02:36 | 002,879,176 | ---- | M] (Samsung Electronics CO., LTD.) [Auto | Running] -- C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe -- (SWUpdateService)
SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/12/13 14:26:20 | 003,290,896 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/12/05 15:39:26 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
SRV - [2012/12/05 15:39:08 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2012/11/29 14:50:25 | 003,463,080 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2012/05/08 09:34:32 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012/05/08 09:34:31 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012/02/13 14:02:24 | 000,031,624 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe -- (SamsungDeviceConfigurationWinService)
SRV - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011/05/05 13:44:54 | 002,656,536 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/05/05 13:44:52 | 000,326,424 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/12/31 07:39:54 | 008,133,120 | ---- | M] () [On_Demand | Stopped] -- D:\Dropbox\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe -- (wampmysqld)
SRV - [2010/12/31 07:39:42 | 000,020,549 | ---- | M] (Apache Software Foundation) [On_Demand | Stopped] -- D:\Dropbox\wamp\bin\apache\Apache2.2.17\bin\httpd.exe -- (wampapache)
SRV - [2010/08/10 21:37:08 | 000,334,848 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\Printer Utilities\UsbService64.exe -- (UsbService)
SRV - [2010/06/25 18:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/09/02 13:07:14 | 000,783,360 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Generic\USB Server\NPW\NPWService.exe -- (NPWService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/23 00:55:30 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/09/25 06:20:33 | 000,293,712 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/05/08 09:34:32 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012/05/08 09:34:32 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012/04/18 06:18:34 | 010,857,984 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/04/18 04:57:26 | 000,328,704 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/10 15:28:16 | 012,311,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
DRV:64bit: - [2012/01/10 15:28:16 | 012,311,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/11/03 10:10:42 | 000,395,752 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV:64bit: - [2011/11/03 10:10:42 | 000,130,536 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV:64bit: - [2011/09/23 07:20:50 | 000,080,688 | ---- | M] (Diskeeper Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\excsd.sys -- (excsd)
DRV:64bit: - [2011/09/23 07:20:50 | 000,023,344 | ---- | M] (Diskeeper Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\excfs.sys -- (excfs)
DRV:64bit: - [2011/09/22 06:39:44 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
DRV:64bit: - [2011/09/16 15:09:16 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011/08/23 02:12:56 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2011/08/17 15:19:38 | 000,031,216 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2011/07/05 12:55:30 | 004,745,280 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2011/05/17 07:55:28 | 000,533,096 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/04/11 11:55:24 | 000,007,680 | ---- | M] (Phoenix Technologies Ltd.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\SGDrv64.sys -- (SGDrv)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/18 00:11:54 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/02/16 00:35:54 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011/01/25 01:29:46 | 000,107,560 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011/01/11 00:15:08 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/20 14:34:04 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010/11/20 14:34:04 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010/11/20 12:35:34 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010/11/20 12:35:26 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcuxd.sys -- (vpcuxd)
DRV:64bit: - [2010/11/20 12:35:22 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010/10/20 17:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/09/14 23:59:16 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010/09/14 23:59:10 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/07/07 02:43:14 | 000,022,592 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
DRV:64bit: - [2010/06/25 16:08:10 | 000,036,928 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2009/11/09 17:30:08 | 000,030,208 | ---- | M] (Elite Silicon Technology Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NUS_Bus.sys -- (NUS_Bus)
DRV:64bit: - [2009/11/04 15:59:36 | 000,133,632 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet)
DRV:64bit: - [2009/11/04 15:59:36 | 000,117,120 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2009/11/04 15:59:36 | 000,114,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbfake.sys -- (hwusbfake)
DRV:64bit: - [2009/11/02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009/10/06 10:11:38 | 000,199,168 | ---- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GenHC.sys -- (EST_Server)
DRV:64bit: - [2009/10/06 10:11:30 | 000,029,696 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GenBus.sys -- (EST_BusEnum)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/07/14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009/07/14 01:00:24 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\acpials.sys -- (acpials)
DRV:64bit: - [2009/07/14 00:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/12/17 10:25:14 | 000,047,616 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vuhub.sys -- (vuhub)
DRV:64bit: - [2007/02/06 04:17:48 | 000,033,280 | ---- | M] (Castles Technology Co.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ezusb64.sys -- (EZUSB)
DRV - [2012/12/05 15:39:18 | 000,071,032 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://samsung.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://samsung.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://samsung.msn.com
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: 2020Player_IKEA%402020Technologies.com:5.0.94.0
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.15
FF - prefs.js..extensions.enabledAddons: %7Be3f6c2cc-d8db-498c-af6c-499fb211db97%7D:1.12.9.1
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0037-ABCDEFFEDCBA%7D:6.0.37
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - prefs.js..keyword.URL: "http://search.condui...rchSource=2&q="
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\massimo\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\massimo\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/20 08:56:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/01/20 08:56:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/20 08:56:09 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/01/20 08:56:05 | 000,000,000 | ---D | M]

[2012/01/28 14:40:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\massimo\AppData\Roaming\mozilla\Extensions
[2012/12/13 16:21:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\massimo\AppData\Roaming\mozilla\Firefox\Profiles\l6cbdwrn.default\extensions
[2012/09/04 16:54:46 | 000,000,000 | ---D | M] (Page Speed) -- C:\Users\massimo\AppData\Roaming\mozilla\Firefox\Profiles\l6cbdwrn.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2012/09/14 16:12:53 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Users\massimo\AppData\Roaming\mozilla\Firefox\Profiles\l6cbdwrn.default\extensions\[email protected]
[2012/12/13 16:21:11 | 002,151,598 | ---- | M] () (No name found) -- C:\Users\massimo\AppData\Roaming\mozilla\firefox\profiles\l6cbdwrn.default\extensions\[email protected]
[2012/09/14 16:10:02 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\massimo\AppData\Roaming\mozilla\firefox\profiles\l6cbdwrn.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013/01/20 08:56:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/01/20 08:56:04 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/01/20 08:56:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/01/20 08:56:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/01/20 08:56:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/01/20 08:56:09 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[1999/12/31 16:00:00 | 000,170,080 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2012/12/05 15:30:23 | 000,001,606 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-it.xml
[2012/11/09 00:26:57 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/12/05 15:30:23 | 000,000,957 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-it.xml
[2012/12/05 15:30:23 | 000,001,030 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\hoepli.xml
[2012/12/05 15:30:23 | 000,001,395 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-it.xml
[2012/12/05 15:30:23 | 000,001,166 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-it.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\massimo\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\massimo\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\massimo\AppData\Local\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\massimo\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: Entanglement = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Web Developer = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm\0.4.3_0\
CHR - Extension: Chrome Professional - Theme = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhapfjmmbkceacadabpamlhofapnhhcd\1.3_0\
CHR - Extension: YouTube = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Firebug Lite for Google Chrome\u2122 = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench\1.4.0.11967_0\
CHR - Extension: Ricerca Google = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Xdebug helper = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\eadndfjplgieldjbigjakmdgkmoaaaoc\1.3.0_0\
CHR - Extension: Gmail Offline = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk\1.19_0\
CHR - Extension: Pendule = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkffbkamcejhkcaocmkdeiiccpmjfdi\1.0.0_0\
CHR - Extension: Chrome Sniffer = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\homgcnaoacgigpkkljjjekpignblkeae\0.2.13_0\
CHR - Extension: Poppit = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Google Chrome to Phone Extension = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.1_0\
CHR - Extension: Gmail = C:\Users\massimo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/05/24 22:36:53 | 000,000,885 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 192.168.1.10 ANNA01
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 127.0.0.1
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Samsung BHO Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [BoxSyncHelper] C:\Program Files\Box Sync\BoxSyncHelper.exe (Box, Inc.)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe (Broadcom Corporation)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Seagull Drivers] C:\windows\ssdal_nc.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [Jitsi] C:\Program Files\Jitsi\run.exe (jitsi.org)
O4 - HKCU..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\massimo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\massimo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DelayedDesktopSwitchTimeout = 0
O8:64bit: - Extra context menu item: Invia immagine alla periferica &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Invia pagina alla periferica &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Invia a Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Invia a periferica &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files (x86)\Generic\USB Server\NPW\NPWprint.dll (Elite Silicon Technology Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000011 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: samsungsetup.com ([www] http in Siti attendibili)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {877E14A6-0ACF-4509-8CF3-E4A0F4ED46F4} http://supportsiss.l...onents/pdlc.cab (Postazione di Lavoro del Cittadino 3.0)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {F39F6F0B-170B-4A3A-AF1D-11D89CFD9ED9} http://95.227.33.6/VideoX.CAB (VideoSafe - VS Viewer)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FCA4A7A0-1B0F-4FF5-98B8-5447B2FBE3B4}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{a16e1f8c-d974-11e1-99fb-9eaad6e681ad}\Shell - "" = AutoRun
O33 - MountPoints2\{a16e1f8c-d974-11e1-99fb-9eaad6e681ad}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{b4f2fe20-c8ef-11e1-8b18-862556c7fede}\Shell - "" = AutoRun
O33 - MountPoints2\{b4f2fe20-c8ef-11e1-8b18-862556c7fede}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{b4f2fe31-c8ef-11e1-8b18-862556c7fede}\Shell - "" = AutoRun
O33 - MountPoints2\{b4f2fe31-c8ef-11e1-8b18-862556c7fede}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/06 15:16:16 | 000,000,000 | ---D | C] -- C:\Users\massimo\AppData\Roaming\Malwarebytes
[2013/02/06 15:15:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/06 15:15:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/02/06 15:15:48 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2013/02/06 15:15:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/02/06 15:13:33 | 000,000,000 | ---D | C] -- C:\Users\massimo\AppData\Local\Programs
[2013/02/06 10:27:24 | 000,000,000 | ---D | C] -- C:\Users\massimo\Documents\FormatFactory
[2013/02/05 22:46:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/02/05 22:46:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2013/02/05 22:46:50 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013/02/04 08:48:13 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\BarTender
[2013/02/03 14:41:59 | 000,000,000 | ---D | C] -- C:\Users\massimo\AppData\Roaming\PotPlayerMini
[2013/02/03 14:41:59 | 000,000,000 | ---D | C] -- C:\Users\massimo\AppData\Local\Daum
[2013/02/03 14:41:28 | 000,000,000 | ---D | C] -- C:\Users\massimo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Daum
[2013/02/03 14:41:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum
[2013/02/03 14:41:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Daum
[2013/02/03 14:35:23 | 000,000,000 | ---D | C] -- C:\Users\massimo\AppData\Local\{14684081-B7F5-4588-BFDD-E55CB4A87DB6}
[2013/02/01 20:30:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2013/01/28 19:19:02 | 000,000,000 | ---D | C] -- C:\Users\massimo\.netbeans
[2013/01/28 19:18:54 | 000,000,000 | ---D | C] -- C:\Users\massimo\.ireport
[2013/01/28 19:18:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jaspersoft
[2013/01/28 19:18:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Jaspersoft
[2013/01/25 19:46:55 | 000,000,000 | ---D | C] -- C:\Users\massimo\Desktop\Agenti
[2013/01/25 19:46:54 | 000,000,000 | ---D | C] -- C:\Users\massimo\Desktop\Analisi
[2013/01/24 16:11:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
[2013/01/24 16:11:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BlueStacks
[2013/01/24 16:11:08 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacksSetup
[2013/01/24 16:11:07 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacks
[2013/01/24 07:27:53 | 000,000,000 | ---D | C] -- C:\Users\massimo\Desktop\tests
[2013/01/20 08:56:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/01/19 10:37:05 | 000,120,320 | ---- | C] (Oki Data Corporation) -- C:\windows\SysNative\opnetext.dll
[2013/01/19 10:37:05 | 000,000,000 | ---D | C] -- C:\Program Files\Okidata
[2013/01/19 10:36:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Okidata
[2013/01/18 17:31:51 | 000,027,648 | ---- | C] (Oki Data Corporation) -- C:\windows\SysNative\OKLMON64.DLL
[2013/01/17 17:00:52 | 000,000,000 | ---D | C] -- C:\Users\massimo\Documents\Adobe
[2013/01/09 01:59:17 | 000,000,000 | ---D | C] -- C:\Users\massimo\AppData\Roaming\CLYii
[2013/01/09 01:59:17 | 000,000,000 | ---D | C] -- C:\Users\massimo\AppData\Roaming\CLSMySQL
[2011/10/07 17:05:50 | 000,934,496 | ---- | C] (dotPDN LLC) -- C:\Program Files\PaintDotNet.exe
[2011/10/07 17:05:50 | 000,544,256 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wiaaut.dll
[2011/10/07 17:05:50 | 000,366,176 | ---- | C] (dotPDN LLC) -- C:\Program Files\PaintDotNet.Resources.dll
[2011/10/07 17:05:50 | 000,339,552 | ---- | C] (dotPDN LLC) -- C:\Program Files\PaintDotNet.Core.dll
[2011/10/07 17:05:50 | 000,329,824 | ---- | C] (dotPDN LLC) -- C:\Program Files\PaintDotNet.SystemLayer.dll
[2011/10/07 17:05:50 | 000,208,480 | ---- | C] (dotPDN LLC) -- C:\Program Files\PaintDotNet.Effects.dll
[2011/10/07 17:05:50 | 000,200,704 | ---- | C] (ICSharpCode.net) -- C:\Program Files\ICSharpCode.SharpZipLib.dll
[2011/10/07 17:05:50 | 000,174,688 | ---- | C] (dotPDN LLC) -- C:\Program Files\PaintDotNet.Base.dll
[2011/10/07 17:05:50 | 000,163,936 | ---- | C] (dotPDN LLC) -- C:\Program Files\PaintDotNet.Data.dll
[2011/10/07 17:05:50 | 000,028,768 | ---- | C] (dotPDN LLC) -- C:\Program Files\SetupNgen.exe
[2011/10/07 17:05:50 | 000,019,040 | ---- | C] (dotPDN LLC) -- C:\Program Files\WiaProxy32.exe
[2011/10/07 17:05:50 | 000,015,456 | ---- | C] (dotPDN LLC) -- C:\Program Files\UpdateMonitor.exe
[2011/10/07 17:05:50 | 000,014,432 | ---- | C] (dotPDN LLC) -- C:\Program Files\PdnRepair.exe

========== Files - Modified Within 30 Days ==========

[2013/02/06 16:02:00 | 000,000,900 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/06 16:01:00 | 000,000,260 | ---- | M] () -- C:\windows\tasks\HP Photo Creations Messager.job
[2013/02/06 15:50:01 | 000,000,978 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013/02/06 15:41:00 | 000,001,168 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3742788777-4055952478-938898431-1000UA.job
[2013/02/06 15:19:43 | 000,000,000 | -HS- | M] () -- C:\DkHyperbootSync
[2013/02/06 15:03:39 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/02/06 13:02:02 | 000,000,896 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/06 11:38:11 | 000,159,752 | ---- | M] () -- C:\Users\massimo\AppData\Local\recently-used.xbel
[2013/02/06 09:41:00 | 000,001,116 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3742788777-4055952478-938898431-1000Core.job
[2013/02/06 08:46:02 | 000,021,200 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/06 08:46:02 | 000,021,200 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/06 08:38:38 | 2056,830,975 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/05 23:27:02 | 000,002,245 | ---- | M] () -- C:\Users\massimo\Desktop\us_tax_v0_3 for greg.sql
[2013/02/04 08:58:09 | 000,000,034 | -H-- | M] () -- C:\windows\hdr443
[2013/02/04 08:55:18 | 001,544,538 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2013/02/04 08:55:18 | 000,701,510 | ---- | M] () -- C:\windows\SysNative\perfh010.dat
[2013/02/04 08:55:18 | 000,617,716 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2013/02/04 08:55:18 | 000,129,062 | ---- | M] () -- C:\windows\SysNative\perfc010.dat
[2013/02/04 08:55:18 | 000,107,600 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2013/02/03 14:36:05 | 000,003,584 | ---- | M] () -- C:\Users\massimo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/02 19:12:30 | 022,749,592 | ---- | M] () -- C:\Users\massimo\AppData\Local\Racing.swf
[2013/02/02 19:12:30 | 000,000,526 | ---- | M] () -- C:\Users\massimo\AppData\Local\scrcfg.ini
[2013/01/29 23:30:39 | 000,107,974 | ---- | M] () -- C:\Users\massimo\Desktop\battcar.pdf
[2013/01/29 23:30:14 | 000,102,842 | ---- | M] () -- C:\Users\massimo\battcar.pdf
[2013/01/29 23:30:13 | 000,040,824 | ---- | M] () -- C:\Users\massimo\battcar.jasper
[2013/01/29 23:29:58 | 000,528,495 | ---- | M] () -- C:\Users\massimo\Documents\battcar.jrprint
[2013/01/29 23:26:14 | 000,005,068 | ---- | M] () -- C:\Users\massimo\battcar.jrxml
[2013/01/29 21:57:43 | 000,004,836 | ---- | M] () -- C:\Users\massimo\Desktop\battcar.php
[2013/01/29 21:46:07 | 000,126,055 | ---- | M] () -- C:\Users\massimo\Desktop\Listino_completo_sintetico.pdf
[2013/01/29 21:45:31 | 000,119,348 | ---- | M] () -- C:\Users\massimo\report1.pdf
[2013/01/29 21:45:29 | 000,039,394 | ---- | M] () -- C:\Users\massimo\report1.jasper
[2013/01/29 21:44:44 | 000,895,024 | ---- | M] () -- C:\Users\massimo\Documents\ListinoSemplice.jrprint
[2013/01/29 21:41:40 | 000,004,608 | ---- | M] () -- C:\Users\massimo\report1.jrxml
[2013/01/29 20:56:03 | 000,004,268 | ---- | M] () -- C:\Users\massimo\Desktop\carebpricelist.php
[2013/01/29 15:28:00 | 000,041,847 | ---- | M] () -- C:\Users\massimo\Listino_Dejavu.jasper
[2013/01/29 15:28:00 | 000,006,951 | ---- | M] () -- C:\Users\massimo\Listino_Dejavu.jrxml
[2013/01/28 19:18:36 | 000,001,224 | ---- | M] () -- C:\Users\Public\Desktop\iReport-5.0.1.lnk
[2013/01/28 18:51:20 | 000,084,417 | ---- | M] () -- C:\Users\massimo\Desktop\carebsrl_dejavu.csv
[2013/01/25 00:11:58 | 000,001,050 | ---- | M] () -- C:\Users\massimo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/01/20 12:16:51 | 000,000,600 | ---- | M] () -- C:\Users\massimo\AppData\Local\PUTTY.RND
[2013/01/09 22:48:52 | 005,136,576 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2013/02/06 15:19:43 | 000,000,000 | -HS- | C] () -- C:\DkHyperbootSync
[2013/02/06 11:38:11 | 000,159,752 | ---- | C] () -- C:\Users\massimo\AppData\Local\recently-used.xbel
[2013/02/05 23:25:20 | 000,002,245 | ---- | C] () -- C:\Users\massimo\Desktop\us_tax_v0_3 for greg.sql
[2013/02/03 14:36:05 | 000,003,584 | ---- | C] () -- C:\Users\massimo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/02 19:12:30 | 000,000,526 | ---- | C] () -- C:\Users\massimo\AppData\Local\scrcfg.ini
[2013/02/02 19:12:29 | 022,749,592 | ---- | C] () -- C:\Users\massimo\AppData\Local\Racing.swf
[2013/02/01 20:30:37 | 000,001,837 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
[2013/01/29 23:30:39 | 000,107,974 | ---- | C] () -- C:\Users\massimo\Desktop\battcar.pdf
[2013/01/29 23:30:14 | 000,102,842 | ---- | C] () -- C:\Users\massimo\battcar.pdf
[2013/01/29 23:29:58 | 000,528,495 | ---- | C] () -- C:\Users\massimo\Documents\battcar.jrprint
[2013/01/29 22:13:23 | 000,040,824 | ---- | C] () -- C:\Users\massimo\battcar.jasper
[2013/01/29 22:09:38 | 000,005,068 | ---- | C] () -- C:\Users\massimo\battcar.jrxml
[2013/01/29 21:57:12 | 000,004,836 | ---- | C] () -- C:\Users\massimo\Desktop\battcar.php
[2013/01/29 21:46:07 | 000,126,055 | ---- | C] () -- C:\Users\massimo\Desktop\Listino_completo_sintetico.pdf
[2013/01/29 21:45:30 | 000,119,348 | ---- | C] () -- C:\Users\massimo\report1.pdf
[2013/01/29 21:09:36 | 000,895,024 | ---- | C] () -- C:\Users\massimo\Documents\ListinoSemplice.jrprint
[2013/01/29 20:52:21 | 000,004,268 | ---- | C] () -- C:\Users\massimo\Desktop\carebpricelist.php
[2013/01/29 15:48:18 | 000,039,394 | ---- | C] () -- C:\Users\massimo\report1.jasper
[2013/01/29 15:48:06 | 000,004,608 | ---- | C] () -- C:\Users\massimo\report1.jrxml
[2013/01/29 15:07:38 | 000,041,847 | ---- | C] () -- C:\Users\massimo\Listino_Dejavu.jasper
[2013/01/29 15:03:50 | 000,006,951 | ---- | C] () -- C:\Users\massimo\Listino_Dejavu.jrxml
[2013/01/28 19:18:36 | 000,001,224 | ---- | C] () -- C:\Users\Public\Desktop\iReport-5.0.1.lnk
[2013/01/28 18:51:18 | 000,084,417 | ---- | C] () -- C:\Users\massimo\Desktop\carebsrl_dejavu.csv
[2013/01/19 10:37:05 | 000,003,868 | ---- | C] () -- C:\windows\SysNative\opnedef.str
[2013/01/19 10:37:05 | 000,000,044 | ---- | C] () -- C:\windows\SysNative\opnetext.ver
[2013/01/19 10:37:05 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\opnetext.gid
[2013/01/19 10:37:05 | 000,000,000 | ---- | C] () -- C:\windows\SysNative\OPNETEXT.GID
[2012/12/31 13:17:37 | 000,032,256 | ---- | C] () -- C:\windows\SysWow64\AVSredirect.dll
[2012/12/31 13:13:56 | 000,107,520 | RHS- | C] () -- C:\windows\SysWow64\TAKDSDecoder.dll
[2012/12/22 20:59:43 | 000,149,880 | ---- | C] () -- C:\windows\wiainst64.exe
[2012/10/10 11:35:23 | 000,000,000 | ---- | C] () -- C:\windows\BarTend.INI
[2012/10/10 11:35:21 | 001,572,964 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/09/07 09:33:53 | 000,000,600 | ---- | C] () -- C:\Users\massimo\AppData\Roaming\winscp.rnd
[2012/08/28 10:04:14 | 000,003,917 | ---- | C] () -- C:\windows\SysWow64\atipblup.dat
[2012/08/13 22:26:42 | 000,063,488 | ---- | C] () -- C:\windows\ssdal_nc.exe
[2012/08/08 12:17:35 | 000,064,239 | ---- | C] () -- C:\Users\massimo\dejavu_banner.svg
[2012/07/06 12:39:26 | 000,017,408 | ---- | C] () -- C:\windows\SysWow64\Delphimm.dll
[2012/05/21 16:04:08 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2012/05/15 12:00:30 | 000,020,747 | ---- | C] () -- C:\Users\massimo\drawing.svg
[2012/05/14 11:01:39 | 000,000,600 | ---- | C] () -- C:\Users\massimo\AppData\Local\PUTTY.RND
[2012/05/02 11:29:39 | 000,001,006 | ---- | C] () -- C:\windows\Brpfx04a.ini
[2012/05/02 11:29:39 | 000,000,162 | ---- | C] () -- C:\windows\brpcfx.ini
[2012/05/02 11:28:16 | 000,000,000 | ---- | C] () -- C:\windows\brdfxspd.dat
[2012/05/02 11:28:12 | 000,045,056 | ---- | C] () -- C:\windows\SysWow64\BRTCPCON.DLL
[2012/05/02 11:28:11 | 000,000,114 | ---- | C] () -- C:\windows\SysWow64\BRLMW03A.INI
[2012/04/27 08:46:08 | 000,000,141 | ---- | C] () -- C:\windows\ODBC.INI
[2012/04/27 08:44:26 | 000,000,232 | ---- | C] () -- C:\windows\ODBCINST.INI
[2012/04/18 06:14:24 | 000,054,784 | ---- | C] () -- C:\windows\SysWow64\OVDecode.dll
[2012/04/18 05:16:54 | 000,204,952 | ---- | C] () -- C:\windows\SysWow64\ativvsvl.dat
[2012/04/18 05:16:54 | 000,157,144 | ---- | C] () -- C:\windows\SysWow64\ativvsva.dat
[2012/02/27 23:18:58 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2012/01/10 15:27:24 | 000,963,884 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2012/01/10 15:27:24 | 000,221,264 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2012/01/10 15:16:52 | 000,056,832 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2012/01/10 14:29:52 | 013,904,384 | ---- | C] () -- C:\windows\SysWow64\ig4icd32.dll
[2011/12/02 12:12:10 | 000,260,688 | ---- | C] () -- C:\windows\SUPDRun.exe
[2011/10/25 00:57:01 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2011/10/25 00:23:51 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2011/10/24 23:47:04 | 000,010,126 | ---- | C] () -- C:\windows\HotFixList.ini
[2011/10/07 17:05:50 | 002,072,064 | ---- | C] () -- C:\Program Files\PaintDotNet.pdb
[2011/10/07 17:05:50 | 001,076,736 | ---- | C] () -- C:\Program Files\PaintDotNet.Core.pdb
[2011/10/07 17:05:50 | 000,654,848 | ---- | C] () -- C:\Program Files\PaintDotNet.Base.pdb
[2011/10/07 17:05:50 | 000,529,920 | ---- | C] () -- C:\Program Files\PaintDotNet.Effects.pdb
[2011/10/07 17:05:50 | 000,419,328 | ---- | C] () -- C:\Program Files\PaintDotNet.Data.pdb
[2011/10/07 17:05:50 | 000,394,752 | ---- | C] () -- C:\Program Files\PaintDotNet.SystemLayer.pdb
[2011/10/07 17:05:50 | 000,147,794 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.RU.resources
[2011/10/07 17:05:50 | 000,132,995 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.JA.resources
[2011/10/07 17:05:50 | 000,127,947 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.KO.resources
[2011/10/07 17:05:50 | 000,127,882 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.FR.resources
[2011/10/07 17:05:50 | 000,126,062 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.DE.resources
[2011/10/07 17:05:50 | 000,125,452 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.ES.resources
[2011/10/07 17:05:50 | 000,124,621 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.PT-BR.resources
[2011/10/07 17:05:50 | 000,124,003 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.it.resources
[2011/10/07 17:05:50 | 000,118,960 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.resources
[2011/10/07 17:05:50 | 000,115,690 | R--- | C] () -- C:\Program Files\PaintDotNet.Strings.3.ZH-CHS.resources
[2011/10/07 17:05:50 | 000,085,600 | ---- | C] () -- C:\Program Files\PaintDotNet.SystemLayer.Native.x64.dll
[2011/10/07 17:05:50 | 000,082,016 | ---- | C] () -- C:\Program Files\PaintDotNet.SystemLayer.Native.x86.dll
[2011/10/07 17:05:50 | 000,049,152 | ---- | C] ( ) -- C:\Program Files\Interop.WIA.dll
[2011/10/07 17:05:50 | 000,040,448 | ---- | C] () -- C:\Program Files\PaintDotNet.Resources.pdb
[2011/10/07 17:05:50 | 000,026,112 | ---- | C] () -- C:\Program Files\SetupNgen.pdb
[2011/10/07 17:05:50 | 000,023,648 | ---- | C] () -- C:\Program Files\ShellExtension_x64.dll
[2011/10/07 17:05:50 | 000,021,600 | ---- | C] () -- C:\Program Files\ShellExtension_x86.dll
[2011/10/07 17:05:50 | 000,013,824 | ---- | C] () -- C:\Program Files\WiaProxy32.pdb
[2011/10/07 17:05:50 | 000,013,824 | ---- | C] () -- C:\Program Files\UpdateMonitor.pdb
[2011/10/07 17:05:50 | 000,013,824 | ---- | C] () -- C:\Program Files\PdnRepair.pdb
[2011/10/07 17:05:50 | 000,000,354 | ---- | C] () -- C:\Program Files\SetupNgen.exe.config
[2011/10/07 17:05:50 | 000,000,351 | ---- | C] () -- C:\Program Files\WiaProxy32.exe.config
[2011/10/07 17:05:50 | 000,000,351 | ---- | C] () -- C:\Program Files\UpdateMonitor.exe.config
[2011/10/07 17:05:50 | 000,000,351 | ---- | C] () -- C:\Program Files\PdnRepair.exe.config
[2011/10/07 17:05:50 | 000,000,351 | ---- | C] () -- C:\Program Files\PaintDotNet.exe.config
[2011/09/12 17:06:18 | 000,003,917 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2011/05/20 10:16:50 | 000,974,848 | ---- | C] () -- C:\windows\SysWow64\cis-2.4.dll
[2011/05/20 10:16:50 | 000,081,920 | ---- | C] () -- C:\windows\SysWow64\issacapi_bs-2.3.dll
[2011/05/20 10:16:50 | 000,065,536 | ---- | C] () -- C:\windows\SysWow64\issacapi_pe-2.3.dll
[2011/05/20 10:16:50 | 000,057,344 | ---- | C] () -- C:\windows\SysWow64\issacapi_se-2.3.dll
[2011/04/05 00:07:00 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin

========== ZeroAccess Check ==========

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/01/30 07:43:39 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Advanced Find and Replace 6
[2012/11/29 19:07:20 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Azureus
[2012/12/18 15:49:26 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\BarTender
[2012/10/29 23:42:32 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Box Desktop
[2013/02/06 08:43:31 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Box Sync
[2013/01/06 11:17:49 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\calibre
[2012/10/12 10:11:14 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/01/30 07:55:36 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLCakePHP
[2012/01/30 07:55:36 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLCodeIgniter
[2012/01/30 07:55:37 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLDrupal
[2012/01/30 07:55:37 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLFacebook
[2012/01/30 07:55:37 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLJoomla
[2012/01/30 07:55:37 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLJQuery
[2012/01/30 07:55:58 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\ClPhpEd
[2012/01/30 07:55:37 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLSmarty
[2013/01/09 01:59:17 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLSMySQL
[2012/01/30 07:55:37 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLSymphony
[2012/01/30 07:55:37 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLWordPress
[2013/01/09 01:59:17 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CLYii
[2012/01/30 07:55:38 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\CodeLobster Php Edition PRO
[2012/10/05 17:24:49 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/12/29 00:18:34 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Convivea
[2013/02/06 10:31:19 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Dropbox
[2012/05/11 15:36:59 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\EurekaLog
[2012/01/30 07:59:50 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\FileZilla
[2012/05/07 17:11:16 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\HeidiSQL
[2012/10/26 22:50:42 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\iFunbox_UserCache
[2012/04/26 08:30:14 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\ImgBurn
[2012/05/15 11:28:12 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\inkscape
[2013/02/06 15:10:50 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Jitsi
[2012/02/20 01:38:33 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\KeePass
[2012/04/27 08:31:23 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Livecare
[2012/04/19 09:24:19 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Lombardia Integrata
[2012/05/11 09:08:52 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\MySQL
[2012/01/28 23:51:08 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Notepad++
[2012/10/22 16:36:04 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\ObviousIdea
[2012/03/27 14:03:25 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Overlook
[2012/10/31 10:04:50 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\PC-FAX TX
[2012/10/06 18:39:28 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\PDAppFlex
[2012/07/02 15:40:02 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Pelikan Software KFT
[2012/02/23 00:42:31 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\picpick
[2013/02/03 14:41:59 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\PotPlayerMini
[2013/01/28 10:53:44 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\PrimoPDF
[2012/10/17 12:02:06 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Quest Software
[2012/01/28 14:16:49 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Samsung
[2012/08/03 11:26:54 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Scribus
[2012/10/10 11:53:44 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Seagull
[2012/06/14 11:08:58 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Spark
[2012/10/06 18:42:13 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/03/09 13:07:06 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\TeamViewer
[2012/03/30 11:34:03 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Tracker Software
[2012/06/13 09:42:48 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Unigraphics Solutions
[2012/11/29 19:07:20 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\uTorrent
[2012/07/08 12:41:59 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Vodafone
[2012/03/13 10:40:22 | 000,000,000 | ---D | M] -- C:\Users\massimo\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



< End of report >


Any suggestion or new steps?

Many thanks in advance.

Regards,

M
  • 0

Advertisements


#2
Render

Render

    Trusted Helper

  • Malware Removal
  • 4,195 posts
Hi and welcome to GeeksToGo! Please make sure you read all of the instructions and fixes thoroughly before continuing with them. If you have any queries or you are unsure about anything, just say and I'll help you out :)

It may well be worth you printing/saving the instructions throughout the fix, so you have them to hand just in case you are unable to access this site.

Please note:
  • Remember to post your logs, not attach them. So, any logs from any programs we run, should be just 'copied & pasted' into your reply.
  • Please only run the tools that I request. I know malware can be frustrating but running other tools in the meantime and between posts, only makes it harder for us to analyse and fix your PC in the long run.
  • Please subscribe to this topic if you have not already done so. Please check back just in case, as the email system can fail at times.
  • Just because your machine is running better does not mean it is completely cleaned. Please wait for the 'all clear' from me to say when we are done.
  • Please reply within 3 days to be fair to other people asking for help.
  • Please tell me if you have your original Windows CD/DVD available
  • When in doubt, please stop and ask first. There's no harm in asking questions!

  • Please download aswMBR.exe to your desktop.
  • Double click the aswMBR.exe to run it.

    Posted Image
  • When asked if you want to download Avast's virus definitions please select Yes.
    Note: If avast! antivirus is already installed, just do the next step.
  • Click the Scan button to start scan.

    Posted Image
  • On completion of the scan click Save log, save it to your desktop and post in your next reply.
  • Also on Desktop there should be a file called MBR.dat after that. Please attach it here.

How to add an attachment to a new topic or reply
  • 0

#3
madimar

madimar

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Some comments inline!

Hi and welcome to GeeksToGo! Please make sure you read all of the instructions and fixes thoroughly before continuing with them. If you have any queries or you are unsure about anything, just say and I'll help you out :)

It may well be worth you printing/saving the instructions throughout the fix, so you have them to hand just in case you are unable to access this site.

Please note:

  • Remember to post your logs, not attach them. So, any logs from any programs we run, should be just 'copied & pasted' into your reply.
  • Please only run the tools that I request. I know malware can be frustrating but running other tools in the meantime and between posts, only makes it harder for us to analyse and fix your PC in the long run.


hmmm.... you are really right... I was so frustated that I did something... I hope nothing terrible... I executed combofix and ccleaner.... I'm really sorry for that, I will strictly follow your instructions now

  • Please subscribe to this topic if you have not already done so. Please check back just in case, as the email system can fail at times.
  • Just because your machine is running better does not mean it is completely cleaned. Please wait for the 'all clear' from me to say when we are done.
  • Please reply within 3 days to be fair to other people asking for help.
  • Please tell me if you have your original Windows CD/DVD available

  • Well, I'm on a Samsung laptop with native genuine Windows 7 Home Edition.I don't have CD available but I suppose I have a recovery partition with my OS on the hard drive.

  • When in doubt, please stop and ask first. There's no harm in asking questions!

    • Please download aswMBR.exe to your desktop.
    • Double click the aswMBR.exe to run it.

      Posted Image
    • When asked if you want to download Avast's virus definitions please select Yes.
      Note: If avast! antivirus is already installed, just do the next step.
    • Click the Scan button to start scan.

      Posted Image


    I followed your instructions but aswMBR, after around 25 minutes of scan, freezed and after a while also Windows Explorer. I was so forced to reboot. I tried again with aswMBR with the same result... I just was able to get a picture of the frozen aswMBR window (attached). Error box is in italian but it just says:
    "avast! Antirootkit stopped to work
    Windows: A problem has occurred not allowing this program to work properly.
    If a solution is available, the program will be closed and an automatic notification will be sent."




  • On completion of the scan click Save log, save it to your desktop and post in your next reply.
  • Also on Desktop there should be a file called MBR.dat after that. Please attach it here.

  • How to add an attachment to a new topic or reply


    Please let me know, what I can do now... Many thanks again for your help.

    M
    aswMBR_freeze.jpg
    • 0

    #4
    Render

    Render

      Trusted Helper

    • Malware Removal
    • 4,195 posts
    Hi,

    No problem. Please post Cobofix log if you run it. You can find a CF log here: C:\Combofix.txt.
    • 0

    #5
    madimar

    madimar

      Member

    • Topic Starter
    • Member
    • PipPip
    • 13 posts
    ComboFix 13-02-06.01 - massimo 06/02/2013 23:05:38.1.4 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.6058.2448 [GMT 1:00]
    Eseguito da: c:\users\massimo\Desktop\combofix.exe
    Opzioni usate :: /killall
    AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
    SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files (x86)\INSTALL.LOG
    c:\programdata\Samsung
    c:\programdata\Samsung\DeleteOOBEWPP.exe
    c:\programdata\Samsung\Device Error Recovery\derlog-0.log
    c:\programdata\Samsung\Device Error Recovery\derlog-1.log
    c:\programdata\Samsung\Easy Display Manager\2.0\dmlg.log
    c:\programdata\Samsung\Easy Software Manager\ADD_ADDSW_IMG6128A36-I00107.XML
    c:\programdata\Samsung\Easy Software Manager\ADD_ADDSW_IMG6128A36-I00108.XML
    c:\programdata\Samsung\Easy Software Manager\ADD_ADDSW_IMG6128A36-I00109.XML
    c:\programdata\Samsung\Easy Software Manager\ADD_ADDSW_IMG6128A36-I00110.XML
    c:\programdata\Samsung\Easy Software Manager\ADD_ADDSW_IMG6128A36-I00111.XML
    c:\programdata\Samsung\Easy Software Manager\ADD_ADDSW_IMG6128A36-I00112.XML
    c:\programdata\Samsung\Easy Software Manager\ADD_ADDSW_IMG6128A36-I00113.XML
    c:\programdata\Samsung\Easy Software Manager\ADD_ADDSW_IMG6128A36-I00114.XML
    c:\programdata\Samsung\Easy Software Manager\ADDSW_ADDSW_IMG6128A36-I001_14.XML
    c:\programdata\Samsung\Easy Software Manager\ADDSW_ADDSW_IMG6128A46-I001_01.XML
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x0404.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x0407.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x0409.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x040a.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x040c.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x0410.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x0411.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x0412.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x0804.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\0x1004.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\1028.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\1031.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\1033.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\1034.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\1036.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\1040.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\1041.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\1042.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\2052.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\4100.mst
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\AddUvcFlags.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Autorun.inf
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Chain_Install.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Chain_Install.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\CPUlist.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Custom.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Cyberlink.MD5
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Data1.cab
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\DEFAULT.REG
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\DEFAULT_LITE.REG
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Define.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\DeviceList.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\DeviceProperty.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\info.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ISSetup.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Product.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\setup.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\Setup.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\setup.isn
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\setup.iss
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\SetUvcFlags.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\conversionProfile_PiP.xml
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\EffectExtractor.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\EffectExtractor.exe.manifest
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\ara\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\bgr\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\chs\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\cht\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\csy\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\dan\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\deu\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\ell\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\eng\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\enu\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\esp\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\eti\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\fin\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\fra\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\frc\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\heb\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\hrv\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\hun\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\ita\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\jpn\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\kor\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\lth\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\lvi\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\nld\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\nor\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\plk\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\ptb\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\ptg\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\rom\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\rus\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\sky\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\slv\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\srl\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\sve\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ShareFiles\Share\language\trk\EffectExtractor.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\SKUtil.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\SKUtil2008.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\SWDesc.txt
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\uninstall.iss
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\ureg.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\vcredist_x86.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\WebcamChecker.dll
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\WMFDist.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\YouCam.ico
    c:\programdata\Samsung\Easy Software Manager\BASW-12147A\YouCam.msi
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\32Win7\KB2482122\Windows6.1-KB2482122-x86.msu
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\32Win7\KB2496820\Windows6.1-KB2496820-x86.msu
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\32Win7\KB2505454\Windows6.1-KB2505454-x86.msu
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\32Win7\KB2510636\Windows6.1-KB2510636-x86.msu
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\32Win7\SetLCDStretch\DisplayPatchReg.cmd
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\32Win7\SetLCDStretch\LCDStretchMode.xml
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\32Win7\SetLCDStretch\SetLCDStretchMode.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\64Win7\KB2482122\Windows6.1-KB2482122-x64.msu
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\64Win7\KB2496820\Windows6.1-KB2496820-x64.msu
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\64Win7\KB2505454\Windows6.1-KB2505454-x64.msu
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\64Win7\KB2510636\Windows6.1-KB2510636-x64.msu
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\64Win7\SetLCDStretch\DisplayPatchReg.cmd
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\64Win7\SetLCDStretch\LCDStretchMode.xml
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\64Win7\SetLCDStretch\SetLCDStretchMode.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\Disable.vbs
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\Enable.vbs
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\QHotfix.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\QHotfix.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-13311A05\SWDesc.txt
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2393802\WINDOWS6.1-KB2393802-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2425227\WINDOWS6.1-KB2425227-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2479943\WINDOWS6.1-KB2479943-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2484033\WINDOWS6.1-KB2484033-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2488113\WINDOWS6.1-KB2488113-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2491683\WINDOWS6.1-KB2491683-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2492386\WINDOWS6.1-KB2492386-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2503665\WINDOWS6.1-KB2503665-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2505438\WINDOWS6.1-KB2505438-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2506212\WINDOWS6.1-KB2506212-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2506928\WINDOWS6.1-KB2506928-V2-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2507618\WINDOWS6.1-KB2507618-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2509553\WINDOWS6.1-KB2509553-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2511250\WINDOWS6.1-KB2511250-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2515325\WINDOWS6.1-KB2515325-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2529073\WINDOWS6.1-KB2529073-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2532531\WINDOWS6.1-KB2532531-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2536275\WINDOWS6.1-KB2536275-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2536276\WINDOWS6.1-KB2536276-V2-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2541014\WINDOWS6.1-KB2541014-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2544893\WINDOWS6.1-KB2544893-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2545698\WINDOWS6.1-KB2545698-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2547666\WINDOWS6.1-KB2547666-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2552343\WINDOWS6.1-KB2552343-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2560656\WINDOWS6.1-KB2560656-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2563227\WINDOWS6.1-KB2563227-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2564958\WINDOWS6.1-KB2564958-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2567680\WINDOWS6.1-KB2567680-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2570947\WINDOWS6.1-KB2570947-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2579686\WINDOWS6.1-KB2579686-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2588516\WINDOWS6.1-KB2588516-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2607576\WINDOWS6.1-KB2607576-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2618444\IE9-WINDOWS6.1-KB2618444-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2618451\WINDOWS6.1-KB2618451-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2619339\WINDOWS6.1-KB2619339-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2620712\WINDOWS6.1-KB2620712-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2633171\WINDOWS6.1-KB2633171-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2633952\WINDOWS6.1-KB2633952-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2639417\WINDOWS6.1-KB2639417-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB2641690\WINDOWS6.1-KB2641690-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\32Win7\KB982018\WINDOWS6.1-KB982018-V3-X86.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2393802\WINDOWS6.1-KB2393802-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2425227\WINDOWS6.1-KB2425227-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2479943\WINDOWS6.1-KB2479943-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2484033\WINDOWS6.1-KB2484033-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2488113\WINDOWS6.1-KB2488113-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2491683\WINDOWS6.1-KB2491683-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2492386\WINDOWS6.1-KB2492386-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2503665\WINDOWS6.1-KB2503665-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2505438\WINDOWS6.1-KB2505438-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2506014\WINDOWS6.1-KB2506014-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2506212\WINDOWS6.1-KB2506212-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2506928\WINDOWS6.1-KB2506928-V2-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2507618\WINDOWS6.1-KB2507618-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2509553\WINDOWS6.1-KB2509553-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2511250\WINDOWS6.1-KB2511250-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2515325\WINDOWS6.1-KB2515325-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2529073\WINDOWS6.1-KB2529073-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2532531\WINDOWS6.1-KB2532531-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2536275\WINDOWS6.1-KB2536275-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2536276\WINDOWS6.1-KB2536276-V2-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2541014\WINDOWS6.1-KB2541014-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2544893\WINDOWS6.1-KB2544893-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2545698\WINDOWS6.1-KB2545698-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2547666\WINDOWS6.1-KB2547666-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2552343\WINDOWS6.1-KB2552343-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2560656\WINDOWS6.1-KB2560656-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2563227\WINDOWS6.1-KB2563227-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2564958\WINDOWS6.1-KB2564958-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2567680\WINDOWS6.1-KB2567680-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2570947\WINDOWS6.1-KB2570947-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2579686\WINDOWS6.1-KB2579686-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2588516\WINDOWS6.1-KB2588516-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2607576\WINDOWS6.1-KB2607576-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2618444\IE9-WINDOWS6.1-KB2618444-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2618451\WINDOWS6.1-KB2618451-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2619339\WINDOWS6.1-KB2619339-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2620712\WINDOWS6.1-KB2620712-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2633952\WINDOWS6.1-KB2633952-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2639417\WINDOWS6.1-KB2639417-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB2641690\WINDOWS6.1-KB2641690-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\64Win7\KB982018\WINDOWS6.1-KB982018-V3-X64.MSU
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\Disable.vbs
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\Enable.vbs
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\HotfixChecker.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\QHotfix.exe
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\QHotfix.ini
    c:\programdata\Samsung\Easy Software Manager\BASW-13353A12\SWDesc.txt
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I001_21.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00102.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00103.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00104.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00106.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00108.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00109.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00114.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00116.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00117.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00118.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00120.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A36-I00121.XML
    c:\programdata\Samsung\Easy Software Manager\HDM_IMG6128A46-I001_01.XML
    c:\programdata\Samsung\Easy Software Manager\IMG\BASW-01576A36_thumb.png
    c:\programdata\Samsung\Easy Software Manager\IMG\BASW-01584A24_thumb.png
    c:\programdata\Samsung\Easy Software Manager\IMG\BASW-12147A23_thumb.png
    c:\programdata\Samsung\Easy Software Manager\IMG\BASW-12168A08_thumb.png
    c:\programdata\Samsung\Easy Software Manager\IMG\BASW-13674A02_thumb.png
    c:\programdata\Samsung\Easy Software Manager\IMG6128A34-I001.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I001_39.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00102.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00103.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00104.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00106.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00107.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00108.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00109.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00111.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00112.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00113.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00114.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00115.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00116.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00118.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00120.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00121.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00125.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00126.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00127.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00129.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00130.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00131.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00132.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00134.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00138.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A36-I00139.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A46-I001_01.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A46-I001_02.XML
    c:\programdata\Samsung\Easy Software Manager\PATCH_PATCH_IMG6128A46-I001_03.XML
    c:\programdata\Samsung\Easy Software Manager\SelfUpdate.XML
    c:\programdata\Samsung\Easy Software Manager\SelfUpdate\SWM_Setup.exe
    c:\programdata\Samsung\Easy Software Manager\SWMData.db
    c:\programdata\Samsung\Easy Software Manager\SWMLogging.db
    c:\programdata\Samsung\Easy Support Center\Log.txt
    c:\programdata\Samsung\Easy Support Center\MBR.dat
    c:\programdata\Samsung\Easy Support Center\SamoyedDB.db3
    c:\programdata\Samsung\EasySpeedUpManager\Dropbox.lnk
    c:\programdata\Samsung\Printer\ssb7mAM.ini
    c:\programdata\Samsung\SW Update\IMG\BASW-01472A16_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-01576A36_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-01584A24_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11828A13_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11828A13_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11828A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11828A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11830A17_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11830A17_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11830A17_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11830A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11830A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11830A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11831A10_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11831A10_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11831A10_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11831A10_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11831A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11831A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11831A99_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11831A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11856A11_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11856A11_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11856A11_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11856A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11856A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11856A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11859A14_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11859A14_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11897A19_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11897A19_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11897A19_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11897A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11897A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11897A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11987A12_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11987A12_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-11987A12_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12037A25_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12037A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12147A23_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12147A23_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12147A23_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12168A08_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12168A08_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12168A08_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12185A22_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12185A22_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12185A22_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12185A22_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12185A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12185A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12185A99_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12185A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12188A17_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12188A17_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-12188A17_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13171A22_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13171A22_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13171A22_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13171A22_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13177A44_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13177A44_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13177A44_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13177A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13177A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13177A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13478A16_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13478A16_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13478A16_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13478A16_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13478A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13478A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13478A99_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13478A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13479A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13479A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13479A99_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13479A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13498A08_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13498A08_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13498A08_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13525A19_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13525A19_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13525A19_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13525A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13525A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13525A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13544A34_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13544A34_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13544A34_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13544A34_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13544A35_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13544A35_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13544A35_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13544A35_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13582A25_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13582A25_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13582A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13582A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13588A09_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13588A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13596A13_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13596A13_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13596A13_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13596A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13596A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13596A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13637A08_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13637A08_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13642A05_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13642A05_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13642A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13642A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13674A02_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13674A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13676A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-13676A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-83138A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-83138A99_scr2.png
    c:\programdata\Samsung\SW Update\IMG\BASW-83138A99_scr3.png
    c:\programdata\Samsung\SW Update\IMG\BASW-83138A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-83288A99_scr1.png
    c:\programdata\Samsung\SW Update\IMG\BASW-83288A99_thumb.png
    c:\programdata\Samsung\SW Update\IMG\BASW-83512A99_thumb.png
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-01472A25_1.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-01472A25_2.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-11828A15_1.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-11828A15_2.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-11828A15_3.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-11830A18_2.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-11831A10_1.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-11831A10_2.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-11831A10_3.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-13479A37_1.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-13479A37_2.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-13479A37_3.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-13674A02_2.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-13674A02_3.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-83317A08_2.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-83317A08_3.XML
    c:\programdata\Samsung\SW Update\ORCA_ADD_BASW-83317A08_4.XML
    c:\programdata\Samsung\SW Update\ORCA_HDM_MAX_MAX6128A46.XML
    c:\programdata\Samsung\SW Update\ORCA_HDM_SGL_SGL6128A46-C01-R006-S0001.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-11570A65_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-11570A65_2.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-11850A45_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-11897A39_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-12037A70_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-13099A45_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-13427A12_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-13525A36_3.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-13525A36_4.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-13659A24_2.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-83138A37_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-83288A01_3.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-83288A01_4.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-83319A04_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-83512A12_2.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_BASW-84013A01_7.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_ORCA-10025P01_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_ORCA-10079P01_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_ORCA-10106P01_1.XML
    c:\programdata\Samsung\SW Update\ORCA_PATCH_ORCA-10109P01_1.XML
    c:\programdata\Samsung\SW Update\ORCA_SELF_BASW-20000A55_INT_2.XML
    c:\programdata\Samsung\SW Update\ORCA_SELF_BASW-20000A61_INT_1.XML
    c:\programdata\Samsung\SW Update\ORCA_SELF_BASW-20000A62_2.XML
    c:\programdata\Samsung\SW Update\ORCA_SELF_BASW-20000A62_INT_1.XML
    c:\programdata\Samsung\SW Update\SHelperIcon\Icon.png
    c:\programdata\Samsung\SW Update\SRS_HDM_IMG_IMG6128A34-I001.XML
    c:\programdata\Samsung\SW Update\SWMCacheData_2.1.0.0.db
    c:\programdata\Samsung\SW Update\SWMCacheData_2.1.5.0.db
    c:\programdata\Samsung\UPD_Samsung Universal Print Driver\UPD.ini
    c:\users\massimo\AppData\Local\Temp\_MEI44402\_ctypes.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\_elementtree.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\_hashlib.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\_socket.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\_ssl.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\pyexpat.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\pysqlite2._sqlite.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\python26.dll
    c:\users\massimo\AppData\Local\Temp\_MEI44402\pythoncom26.dll
    c:\users\massimo\AppData\Local\Temp\_MEI44402\PyWinTypes26.dll
    c:\users\massimo\AppData\Local\Temp\_MEI44402\select.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\unicodedata.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32api.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32com.shell.shell.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32crypt.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32event.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32file.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32inet.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32pdh.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32process.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32profile.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32security.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\win32ts.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\windows._cacheinvalidation.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wx._controls_.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wx._core_.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wx._gdi_.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wx._html2.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wx._misc_.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wx._windows_.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wx._wizard.pyd
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wxbase293u_net_vc.dll
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wxbase293u_vc.dll
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wxmsw293u_adv_vc.dll
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wxmsw293u_core_vc.dll
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wxmsw293u_html_vc.dll
    c:\users\massimo\AppData\Local\Temp\_MEI44402\wxmsw293u_webview_vc.dll
    c:\users\massimo\AppData\Local\TempDIR
    c:\users\massimo\AppData\Local\TempDIR\BetterInstaller.exe
    c:\users\massimo\AppData\Roaming\Samsung
    c:\users\massimo\AppData\Roaming\Samsung\Kies\Log_Exception.log
    c:\users\massimo\AppData\Roaming\Samsung\Kies\MSDB.db
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateList.txt
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\GongSolutions.Wpf.DragDrop.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Interop.ConnectionManagerLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Interop.DevFileServiceLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Interop.DeviceDataServiceLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Interop.DeviceManagerLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Interop.DeviceServiceModelDBLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Interop.MP3FileInfoCOMLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DBManager.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceService.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceServiceLib.DeviceDataService.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceServiceLib.DeviceManagement.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceServiceLib.FileService.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.Common.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceServiceLib.Interface.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.MainUI.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.MediaDB.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.Multimedia.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.Pims.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.StoreManager.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.Util.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Interface.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Common\Kies.Test.Pims.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\AdminCmdAgent.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\CmdAgent2.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\ConnectionManager.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DataConversion.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DataParser.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DataType.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAATCDMA.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAATOBEX.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCACDMAVIA.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCACHINAHSP.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCADU.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAGM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAKOREAMITSOBEX.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAMITSOBEX.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAOBEX.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAPARAGONATOBEX.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAPARAGONGM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAPARAGONOBEX.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCASW.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCASYM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCAWM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DCInterface.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DevFileService.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceCommunication.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceDataService.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceManager.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceSearch.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceServiceCBT.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceServiceCore.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceServiceHSPAgent.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceServiceModelDB.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\HSPConnection.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\Kies_Tutorial.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\MObexDll.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\SyncService.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\UPNPDevice_Kies.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AdminCmdAgent.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\ar-AE\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\bg-BG\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\CmdAgent.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\CommonModule.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\cs-CZ\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\da-DK\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\de-DE\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\el-GR\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\en-GB\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\es-ES\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\es-MX\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\et-EE\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\fi-FI\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\FirmwareUpdate.MVVM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\FirmwareUpdateAgent.Common.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\FirmwareUpdateAgent.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\fr-CA\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\fr-FR\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\FusCipherUtil.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\he-IL\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\hi-IN\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\hr-HR\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\hu-HU\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\id-ID\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\Interop.CmdAgentLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\IPCClient.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\IPCServer.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\ISharedIPCInterface.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\it-IT\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\ja-JP\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\KiesPDLR.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\ko-KR\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\lt-LT\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\lv-LV\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\ms-MY\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\nb-NO\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\nl-NL\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\pl-PL\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\pt-BR\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\pt-PT\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\ro-RO\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\ru-RU\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\sk-SK\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\sv-SE\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\th-TH\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\tr-TR\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\uk-UA\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\vi-VN\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\zh-CN\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\zh-HK\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\zh-TW\CommonModule.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\GongSolutions.Wpf.DragDrop.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\KiesService_SCPD.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\AStoreMarshal.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\id3lib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\LDBCShConv.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\LDBCShGen.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\LDBCShSrch.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\MP3FileInfoCOM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\MyFreeCodecPack.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MP3HDEncoder.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\Ookii.Dialogs.Wpf.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\TransModules\TG_MOVIE.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\TransModules\TG_PVTR.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\VideoConverterLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\GongSolutions.Wpf.DragDrop.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Interop.DeviceSearchLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Kies.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Kies.exe.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesDriverInstaller.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesTrayAgent.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesVersion.txt
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\ar-AE\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\bg-BG\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\cs-CZ\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\da-Dk\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\de-DE\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\el-GR\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\en-GB\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\es-ES\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\es-MX\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\et-EE\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\fi-FI\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\fr-CA\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\fr-FR\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\he-IL\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\hi-IN\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\hr-HR\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\hu-HU\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\id-ID\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\it-IT\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\ja-JP\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\Kies.Locale.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\ko-KR\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\lt-LT\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\lv-LV\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\ms-MY\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\nb-NO\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\nl-NL\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\pl-PL\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\pt-BR\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\pt-PT\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\ro-RO\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\ru-RU\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\sk-SK\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\sv-SE\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\th-TH\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\tr-TR\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\uk-UA\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\vi-VN\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\zh-CN\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\zh-HK\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Locale\zh-TW\Kies.Locale.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\MMSCore.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\MVVM\Kies.MVVM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\AStore\AStorePlugin.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\AStore\AStorePlugin.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\AStore\AStorePlugin.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\AStore\Interop.AStoreMarshalLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\ContentsManagerLib\Kies.Plugin.ContentsManagerLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\ContentsManagerLib\Kies.Plugin.ContentsManagerLib.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceCommonLib\DeviceCommonLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceEbook\DeviceEbook.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceEbook\DeviceEbook.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceHost\CrashBrokerForServer.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceHost\DeviceHost.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceHost\DeviceHost.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceHost\DeviceHost.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceHost\Interop.DeviceDataServiceLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceHost\Kies.Plugin.MDGLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceHost\Ookii.Dialogs.Wpf.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceHost\SyncProvider.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceMusic\DeviceMusic.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceMusic\DeviceMusic.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DevicePhoto\DevicePhoto.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DevicePhoto\DevicePhoto.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DevicePodcast\DevicePodcast.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DevicePodcast\DevicePodcast.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceVideo\DeviceVideo.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DeviceVideo\DeviceVideo.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DiscRipping\DiscRipping.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\DiscRipping\DiscRipping.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\EBookManager\EBookManager.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\EBookManager\EBookManager.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\MusicManager\MusicManager.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\MusicManager\MusicManager.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\MusicStore\CPKTMusicPlugin.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\MusicStore\CPSevenDigitalPlugin.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\MusicStore\KTMusicStorePlugin.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\MusicStore\MusicStore.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\MusicStore\MusicStore.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\Phonebook\Phonebook.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\Phonebook\Phonebook.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\Phonebook\Phonebook.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\PhotoManager\PhotoManager.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\PhotoManager\PhotoManager.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\StoreLib\StoreLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\VideoManager\VideoManager.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Plugins\VideoManager\VideoManager.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Theme\Kies.Theme.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\UI\Kies.UI.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\ar-AE\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\bg-BG\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\cs-CZ\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\da-DK\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\de-DE\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\el-GR\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\en-GB\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\es-ES\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\es-MX\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\fi-FI\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\fr-CA\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\fr-FR\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\he-IL\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\hi-IN\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\hr-HR\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\hu-HU\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\id-ID\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\it-IT\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\ja-JP\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\ko-KR\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\ms-MY\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\nb-NO\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\nl-NL\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\pl-PL\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\pt-BR\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\pt-PT\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\ro-RO\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\ru-RU\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\sk-SK\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\sv-SE\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\th-TH\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\tr-TR\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\uk-UA\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\vi-VN\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\zh-CN\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\zh-HK\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Updater\zh-TW\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Download\EULA.txt.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\MS_Update_Main.xml
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\GongSolutions.Wpf.DragDrop.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Interop.ConnectionManagerLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Interop.DevFileServiceLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Interop.DeviceDataServiceLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Interop.DeviceManagerLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Interop.DeviceServiceModelDBLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Interop.MP3FileInfoCOMLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Interop.PRPLAYERCORELib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Ionic.Zip.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DBManager.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceService.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceServiceLib.DeviceDataService.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceServiceLib.DeviceManagement.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceServiceLib.FileService.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.Common.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceServiceLib.Interface.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.MainUI.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.MediaDB.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.Multimedia.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.Pims.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.StoreManager.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.Util.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Interface.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Test.Pims.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-I9000M\Device.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P1000R\Device.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7500\Contents.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7510\Calendar.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7510\Contents.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7510\Device.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7510\Memo.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7510\Message.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7510\Phonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7510\Phonebook_com.android.exchange.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\GT-P7510\Phonebook_com.google.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SCH-M710\Contents.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SCH-M710\Phonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SCH-M715\Contents.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SCH-M715\Phonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SCH-M720\Contents.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SCH-M720\Phonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SGH-I896\Device.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SGH-T959D\Device.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SHW-M380K\Contents.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SHW-M380S\Contents.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SHW-M380W\Contents.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SPH-M7200\Phonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SPH-M7350\Phonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\DeviceProfile\Static\SPH-M8400\Phonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\CommonAppData\Samsung\Kies\SamsungModelDB.dat.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\config\Kies.exe.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\config\Kies_3.5.exe.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\config\Kies_4.0.exe.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\EULAVer.txt.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\AdminCmdAgent.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\CabLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\CmdAgent2.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\ConnectionManager.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DataConversion.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DataParser.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DataType.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAATCDMA.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAATOBEX.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCACDMAVIA.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCACHINAHSP.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCADU.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAGM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAKOREAMITSOBEX.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAMITSOBEX.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAOBEX.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAPARAGONATOBEX.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAPARAGONGM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAPARAGONOBEX.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCASW.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCASYM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCAWM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DCInterface.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DevFileService.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DeviceCommunication.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DeviceDataService.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DeviceManager.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DeviceSearch.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DeviceServiceCBT.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DeviceServiceCore.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DeviceServiceHSPAgent.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\DeviceServiceModelDB.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\ErrorReport.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\HSPConnection.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\Kies_Tutorial.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\MObexDll.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\SyncService.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\DeviceModules\UPNPDevice_Kies.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\AdminCmdAgent.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\AgentInstaller.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\AgentInstaller.exe.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\AgentUpdate.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\AgentUpdate.exe.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\AgentVer.txt.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\ar-AE\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\bg-BG\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\BinaryLoaderMgr.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\CmdAgent.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\CommonModule.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\cs-CZ\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\da-DK\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\de-DE\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\el-GR\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\en-GB\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\es-ES\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\es-MX\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\et-EE\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\fi-FI\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\FirmwareUpdate.MVVM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\FirmwareUpdateAgent.Common.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\FirmwareUpdateAgent.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\fr-CA\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\fr-FR\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\FusCipherUtil.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\he-IL\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\hi-IN\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\hr-HR\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\hu-HU\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\id-ID\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\Interop.CmdAgentLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\IPCClient.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\IPCServer.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\ISharedIPCInterface.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\it-IT\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\ja-JP\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\KiesPDLR.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\ko-KR\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\lt-LT\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\lv-LV\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\ms-MY\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\nb-NO\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\nl-NL\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\pl-PL\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\pt-BR\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\pt-PT\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\ro-RO\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\ru-RU\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\sk-SK\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\sv-SE\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\th-TH\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\tr-TR\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\uk-UA\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\vi-VN\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\zh-CN\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\zh-HK\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\zh-TW\CommonModule.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\GongSolutions.Wpf.DragDrop.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\KiesService_SCPD.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MediaModules\AStoreMarshal.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MediaModules\id3lib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MediaModules\LDBCShConv.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MediaModules\LDBCShGen.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MediaModules\LDBCShSrch.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MediaModules\MP3FileInfoCOM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MediaModules\MyFreeCodecPack.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MediaModules\zxing.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\MP3HDEncoder.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\msvcm90.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\Ookii.Dialogs.Wpf.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\PRPlayerCore.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\TransModules\TG_MOVIE.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\TransModules\TG_PVTR.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\VideoConverterLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\WindowsAPICodePack\Microsoft.WindowsAPICodePack.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\External\WindowsAPICodePack\Microsoft.WindowsAPICodePack.Shell.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\GongSolutions.Wpf.DragDrop.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Interop.DeviceSearchLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Kies.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Kies.exe.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\KiesDriverInstaller.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\KiesLogger.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\KiesSilentUpdateAgent.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\KiesTrayAgent.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\KiesVersion.txt.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\ar-AE\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\bg-BG\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\cs-CZ\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\da-Dk\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\de-DE\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\el-GR\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\en-GB\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\es-ES\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\es-MX\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\et-EE\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\fi-FI\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\fr-CA\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\fr-FR\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\he-IL\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\hi-IN\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\hr-HR\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\hu-HU\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\id-ID\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\it-IT\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\ja-JP\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\Kies.Locale.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\ko-KR\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\lt-LT\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\lv-LV\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\ms-MY\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\nb-NO\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\nl-NL\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\pl-PL\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\pt-BR\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\pt-PT\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\ro-RO\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\ru-RU\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\sk-SK\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\sv-SE\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\th-TH\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\tr-TR\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\uk-UA\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\vi-VN\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\zh-CN\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\zh-HK\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Locale\zh-TW\Kies.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Microsoft.WindowsAPICodePack.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Microsoft.WindowsAPICodePack.Shell.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\MMSCore.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\MVVM\Kies.MVVM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\OsDependent\Vista\ceutil.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\OsDependent\Vista\rapi.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\AStore\AStorePlugin.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\AStore\AStorePlugin.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\AStore\AStorePlugin.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\AStore\Interop.AStoreMarshalLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\BATPlugin\BATPlugin.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\BATPlugin\BATPlugin.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\BATPlugin\BATPlugin.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ContentsManagerLib\Interop.PRPLAYERCORELib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ContentsManagerLib\Kies.Plugin.ContentsManagerLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ContentsManagerLib\Kies.Plugin.ContentsManagerLib.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\CrashBrokerForServer\CrashBrokerForServer.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\CrashBrokerForTarget_Android\CrashBrokerForTarget_Android.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\CrashBrokerForTarget_Bada\CrashBrokerForTarget_Bada.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\CrashBrokerForTarget_SLP\CrashBrokerForTarget_SLP.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceCommonLib\DeviceCommonLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceEbook\DeviceEbook.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceEbook\DeviceEbook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceHost\CrashBrokerForServer.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceHost\DeviceHost.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceHost\DeviceHost.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceHost\DeviceHost.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceHost\Interop.DeviceDataServiceLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceHost\Kies.Plugin.MDGLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceHost\Ookii.Dialogs.Wpf.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceHost\SyncProvider.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceMusic\DeviceMusic.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceMusic\DeviceMusic.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DevicePhoto\DevicePhoto.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DevicePhoto\DevicePhoto.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DevicePodcast\DevicePodcast.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DevicePodcast\DevicePodcast.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceVideo\DeviceVideo.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DeviceVideo\DeviceVideo.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DiscRipping\DiscRipping.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\DiscRipping\DiscRipping.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\EBookManager\EBookManager.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\EBookManager\EBookManager.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\MusicManager\MusicManager.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\MusicManager\MusicManager.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\MusicStore\CPKTMusicPlugin.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\MusicStore\CPSevenDigitalPlugin.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\MusicStore\KTMusicStorePlugin.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\MusicStore\MusicStore.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\MusicStore\MusicStore.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\Phonebook\LocalPhonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\Phonebook\Phonebook.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\Phonebook\Phonebook.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\Phonebook\Phonebook.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\PhotoManager\PhotoManager.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\PhotoManager\PhotoManager.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\Podcaster\Podcaster.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\Podcaster\Podcaster.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\Podcaster\Podcaster.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\PodcastService\PodcastService.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\PodcastService\PodcastService.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\PodcastService\PodcastService.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ReadersHub\ReadersHubModel.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ReadersHub\ReadersHubPlugin.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ReadersHub\ReadersHubPlugin.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ReadersHub\ReadersHubPlugin.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ReadersHub\ReadersHubView.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\ReadersHub\ReadersHubViewModel.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\Interop.AStoreMarshalLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\ko-KR\Pado.Locale.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\Pado.Locale.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\PadoControlsCore.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\PadoCore.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\PadoFramework.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\PadoFramework.dll.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\PadoInterface.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\PadoUI.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\StoreLib\StoreLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\VideoManager\VideoManager.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Plugins\VideoManager\VideoManager.xml.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\3DAudio.ax.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\avrt.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\cis-2.4.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\issacapi_bs-2.3.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\issacapi_pe-2.3.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\issacapi_se-2.3.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MACXMLProto.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MaDRM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MaJGUILib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MAMACExtract.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MASetupCleaner.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MaXMLProto.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\mfplat.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MK_Lyric.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MSCLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MSFLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MSLUR71.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\msvcp60.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MTTELECHIP.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\MTXSYNCICON.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzaf1.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzapp.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzapp.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzdecode.ax.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzeffect.ax.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzmp4sp.ax.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzmpgsp.ax.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzoggsp.ax.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\muzwmts.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\System32\psapi.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Theme\Kies.Theme.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\UI\Kies.UI.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\ar-AE\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\bg-BG\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\CabLib.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\cs-CZ\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\da-DK\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\de-DE\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\el-GR\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\en-GB\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\es-ES\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\es-MX\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\fi-FI\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\fr-CA\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\fr-FR\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\he-IL\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\hi-IN\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\hr-HR\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\hu-HU\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\id-ID\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\it-IT\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\ja-JP\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\Kies.MVVM.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\Kies.UI.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\Kies.Update.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\Kies.Update.exe.config.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\Kies.Update.Util.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\ko-KR\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\Microsoft.VC90.CRT.manifest.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\ms-MY\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\msvcm90.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\msvcr90.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\nb-NO\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\nl-NL\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\pl-PL\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\pt-BR\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\pt-PT\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\ro-RO\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\ru-RU\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\sk-SK\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\sv-SE\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\th-TH\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\tr-TR\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\uk-UA\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\vi-VN\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\zh-CN\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\zh-HK\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\Updater\zh-TW\Kies.Update.resources.dll.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\CabFile\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe.cab
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\AdminCmdAgent.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\CabLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\CabLib_35.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\CabLib_40.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\GongSolutions.Wpf.DragDrop.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Interop.CmdAgentLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\it-IT\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.Interface.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.MainUpdate.Util.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.MainUpdate.Util.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.MVVM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.UI.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.Update.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.Update.exe.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.Update.Util.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.Update.Util.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.Update_3.5.exe.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.Update_4.0.exe.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\msvcr100.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\AdminCmdAgent.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\CabLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\CabLib_35.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\CabLib_40.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\GongSolutions.Wpf.DragDrop.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Interop.CmdAgentLib.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\it-IT\EULA.txt
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\it-IT\Kies.Update.resources.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Interface.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.MainUpdate.Util.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.MainUpdate.Util.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.MVVM.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.UI.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.Util.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.Util.dll.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update_3.5.exe.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update_4.0.exe.config
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Microsoft.VC90.CRT.manifest
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\msvcm90.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\msvcr100.dll
    c:\users\massimo\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\msvcr90.dll
    c:\windows\SysWow64\muzapp.exe
    c:\windows\SysWow64\System32\MASetupCleaner.exe
    c:\windows\SysWow64\System32\muzapp.exe
    .
    .
    ((((((((((((((((((((((((( Files Creati Da 2013-01-06 al 2013-02-06 )))))))))))))))))))))))))))))))))))
    .
    .
    2013-02-06 22:29 . 2013-02-06 22:29 -------- d-----w- c:\users\Default\AppData\Local\temp
    2013-02-06 22:24 . 2013-02-06 22:24 -------- d-----w- c:\programdata\Samsung
    2013-02-06 14:16 . 2013-02-06 14:16 -------- d-----w- c:\users\massimo\AppData\Roaming\Malwarebytes
    2013-02-06 14:15 . 2013-02-06 14:15 -------- d-----w- c:\programdata\Malwarebytes
    2013-02-06 14:15 . 2013-02-06 14:15 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2013-02-06 14:15 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
    2013-02-06 14:13 . 2013-02-06 14:13 -------- d-----w- c:\users\massimo\AppData\Local\Programs
    2013-02-05 21:46 . 2013-02-05 21:46 -------- d-----w- c:\program files (x86)\Common Files\Skype
    2013-02-05 08:45 . 2013-02-05 08:45 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{51EA4DEC-5F72-4517-854D-E0C7C764345E}\offreg.dll
    2013-02-05 07:59 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{51EA4DEC-5F72-4517-854D-E0C7C764345E}\mpengine.dll
    2013-02-03 13:41 . 2013-02-03 13:41 -------- d-----w- c:\users\massimo\AppData\Roaming\PotPlayerMini
    2013-02-03 13:41 . 2013-02-03 13:41 -------- d-----w- c:\users\massimo\AppData\Local\Daum
    2013-02-03 13:41 . 2013-02-03 13:41 -------- d-----w- c:\program files (x86)\Daum
    2013-01-28 18:19 . 2013-01-28 18:19 -------- d-----w- c:\users\massimo\.netbeans
    2013-01-28 18:18 . 2013-01-28 18:18 -------- d-----w- c:\users\massimo\.ireport
    2013-01-28 18:18 . 2013-01-28 18:18 -------- d-----w- c:\program files (x86)\Jaspersoft
    2013-01-24 15:11 . 2013-01-24 15:11 -------- d-----w- c:\program files (x86)\BlueStacks
    2013-01-24 15:11 . 2013-01-24 15:11 -------- d-----w- c:\programdata\BlueStacks
    2013-01-19 09:37 . 2013-01-19 09:37 -------- d-----w- c:\program files\Okidata
    2013-01-19 09:37 . 2011-04-08 13:21 120320 ----a-w- c:\windows\system32\opnetext.dll
    2013-01-19 09:36 . 2013-01-19 09:36 -------- d-----w- c:\programdata\Okidata
    2013-01-19 09:36 . 2011-02-23 03:37 40960 ----a-w- c:\windows\system32\Spool\prtprocs\x64\OPATPP3.DLL
    2013-01-18 16:31 . 2009-06-25 09:00 27648 ----a-w- c:\windows\system32\OKLMON64.DLL
    2013-01-16 10:03 . 2013-01-16 10:03 -------- d-----w- c:\users\Default\AppData\Local\Google
    2013-01-09 14:13 . 2012-11-09 05:45 750592 ----a-w- c:\windows\system32\win32spl.dll
    2013-01-09 14:13 . 2012-11-09 04:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
    2013-01-09 14:13 . 2012-11-01 05:43 2002432 ----a-w- c:\windows\system32\msxml6.dll
    2013-01-09 14:13 . 2012-11-01 05:43 1882624 ----a-w- c:\windows\system32\msxml3.dll
    2013-01-09 14:13 . 2012-11-01 04:47 1389568 ----a-w- c:\windows\SysWow64\msxml6.dll
    2013-01-09 14:13 . 2012-11-01 04:47 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
    2013-01-09 14:13 . 2012-11-22 05:44 800768 ----a-w- c:\windows\system32\usp10.dll
    2013-01-09 14:13 . 2012-11-20 05:48 307200 ----a-w- c:\windows\system32\ncrypt.dll
    2013-01-09 14:13 . 2012-11-20 04:51 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll
    2013-01-09 14:13 . 2012-11-22 04:45 626688 ----a-w- c:\windows\SysWow64\usp10.dll
    2013-01-09 14:04 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe
    2013-01-09 14:04 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys
    2013-01-09 00:59 . 2013-01-09 00:59 -------- d-----w- c:\users\massimo\AppData\Roaming\CLYii
    2013-01-09 00:59 . 2013-01-09 00:59 -------- d-----w- c:\users\massimo\AppData\Roaming\CLSMySQL
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-01-17 00:28 . 2010-11-21 03:27 273840 ------w- c:\windows\system32\MpSigStub.exe
    2013-01-10 15:50 . 2012-05-10 07:16 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2013-01-10 15:50 . 2012-01-28 16:53 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-01-09 18:42 . 2012-01-28 19:07 67599240 ----a-w- c:\windows\system32\MRT.exe
    2012-12-22 23:55 . 2010-06-25 17:07 35344 ----a-w- c:\windows\system32\drivers\npf.sys
    2012-12-16 17:11 . 2012-12-21 16:16 46080 ----a-w- c:\windows\system32\atmlib.dll
    2012-12-16 14:45 . 2012-12-21 16:16 367616 ----a-w- c:\windows\system32\atmfd.dll
    2012-12-16 14:13 . 2012-12-21 16:16 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
    2012-12-16 14:13 . 2012-12-21 16:16 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
    2012-11-30 04:45 . 2013-01-09 14:15 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    2012-11-14 07:06 . 2012-12-13 18:14 17811968 ----a-w- c:\windows\system32\mshtml.dll
    2012-11-14 06:32 . 2012-12-13 18:14 10925568 ----a-w- c:\windows\system32\ieframe.dll
    2012-11-14 06:11 . 2012-12-13 18:14 2312704 ----a-w- c:\windows\system32\jscript9.dll
    2012-11-14 06:04 . 2012-12-13 18:14 1346048 ----a-w- c:\windows\system32\urlmon.dll
    2012-11-14 06:04 . 2012-12-13 18:14 1392128 ----a-w- c:\windows\system32\wininet.dll
    2012-11-14 06:02 . 2012-12-13 18:14 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
    2012-11-14 06:02 . 2012-12-13 18:14 237056 ----a-w- c:\windows\system32\url.dll
    2012-11-14 05:59 . 2012-12-13 18:14 85504 ----a-w- c:\windows\system32\jsproxy.dll
    2012-11-14 05:58 . 2012-12-13 18:14 816640 ----a-w- c:\windows\system32\jscript.dll
    2012-11-14 05:57 . 2012-12-13 18:14 599040 ----a-w- c:\windows\system32\vbscript.dll
    2012-11-14 05:57 . 2012-12-13 18:14 173056 ----a-w- c:\windows\system32\ieUnatt.exe
    2012-11-14 05:55 . 2012-12-13 18:14 2144768 ----a-w- c:\windows\system32\iertutil.dll
    2012-11-14 05:55 . 2012-12-13 18:14 729088 ----a-w- c:\windows\system32\msfeeds.dll
    2012-11-14 05:53 . 2012-12-13 18:14 96768 ----a-w- c:\windows\system32\mshtmled.dll
    2012-11-14 05:52 . 2012-12-13 18:14 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2012-11-14 05:46 . 2012-12-13 18:14 248320 ----a-w- c:\windows\system32\ieui.dll
    2012-11-14 02:09 . 2012-12-13 18:14 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
    2012-11-14 01:58 . 2012-12-13 18:14 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
    2012-11-14 01:57 . 2012-12-13 18:14 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
    2012-11-14 01:49 . 2012-12-13 18:14 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
    2012-11-14 01:48 . 2012-12-13 18:14 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
    2012-11-14 01:44 . 2012-12-13 18:14 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
    2012-11-09 05:45 . 2012-12-13 07:15 2048 ----a-w- c:\windows\system32\tzres.dll
    2012-11-09 04:42 . 2012-12-13 07:15 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2011-10-07 16:05 . 2011-10-07 16:05 934496 ----a-w- c:\program files\PaintDotNet.exe
    2011-10-07 16:05 . 2011-10-07 16:05 85600 ----a-w- c:\program files\PaintDotNet.SystemLayer.Native.x64.dll
    2011-10-07 16:05 . 2011-10-07 16:05 82016 ----a-w- c:\program files\PaintDotNet.SystemLayer.Native.x86.dll
    2011-10-07 16:05 . 2011-10-07 16:05 544256 ----a-w- c:\program files\wiaaut.dll
    2011-10-07 16:05 . 2011-10-07 16:05 49152 ----a-w- c:\program files\Interop.WIA.dll
    2011-10-07 16:05 . 2011-10-07 16:05 366176 ----a-w- c:\program files\PaintDotNet.Resources.dll
    2011-10-07 16:05 . 2011-10-07 16:05 339552 ----a-w- c:\program files\PaintDotNet.Core.dll
    2011-10-07 16:05 . 2011-10-07 16:05 329824 ----a-w- c:\program files\PaintDotNet.SystemLayer.dll
    2011-10-07 16:05 . 2011-10-07 16:05 28768 ----a-w- c:\program files\SetupNgen.exe
    2011-10-07 16:05 . 2011-10-07 16:05 23648 ----a-w- c:\program files\ShellExtension_x64.dll
    2011-10-07 16:05 . 2011-10-07 16:05 21600 ----a-w- c:\program files\ShellExtension_x86.dll
    2011-10-07 16:05 . 2011-10-07 16:05 208480 ----a-w- c:\program files\PaintDotNet.Effects.dll
    2011-10-07 16:05 . 2011-10-07 16:05 200704 ----a-w- c:\program files\ICSharpCode.SharpZipLib.dll
    2011-10-07 16:05 . 2011-10-07 16:05 19040 ----a-w- c:\program files\WiaProxy32.exe
    2011-10-07 16:05 . 2011-10-07 16:05 174688 ----a-w- c:\program files\PaintDotNet.Base.dll
    2011-10-07 16:05 . 2011-10-07 16:05 163936 ----a-w- c:\program files\PaintDotNet.Data.dll
    2011-10-07 16:05 . 2011-10-07 16:05 15456 ----a-w- c:\program files\UpdateMonitor.exe
    2011-10-07 16:05 . 2011-10-07 16:05 14432 ----a-w- c:\program files\PdnRepair.exe
    2006-05-03 10:06 163328 --sha-r- c:\windows\SysWOW64\flvDX.dll
    2007-02-21 11:47 31232 --sha-r- c:\windows\SysWOW64\msfDX.dll
    2008-03-16 13:30 216064 --sha-r- c:\windows\SysWOW64\nbDX.dll
    2010-01-06 23:00 107520 --sha-r- c:\windows\SysWOW64\TAKDSDecoder.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* i valori vuoti & legittimi/default non sono visualizzati.
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 129272 ----a-w- c:\users\massimo\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 129272 ----a-w- c:\users\massimo\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 129272 ----a-w- c:\users\massimo\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
    "Jitsi"="c:\program files\Jitsi\run.exe" [2012-03-30 403208]
    "GoogleChromeAutoLaunch_319EFFFFBE2DF4A122E8144DBF2C1DEA"="c:\users\massimo\AppData\Local\Google\Chrome\Application\chrome.exe" [2013-01-26 1248208]
    "GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2012-12-17 16328976]
    "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-01-08 18705664]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
    "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-18 636032]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-09 421776]
    "BlueStacks Agent"="c:\program files (x86)\BlueStacks\HD-Agent.exe" [2012-12-05 597880]
    .
    c:\users\massimo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\massimo\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-5-10 1131296]
    Box Sync.lnk - c:\program files\Box Sync\BoxSync.exe [2012-12-19 8706560]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "DelayedDesktopSwitchTimeout"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
    R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2011-01-10 349736]
    R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-02-15 39464]
    R3 EST_Server;Network USB Device;c:\windows\system32\DRIVERS\GenHC.sys [2009-10-06 199168]
    R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-11-04 133632]
    R3 EZUSB;EZUSB PC/SC Smart Card Reader;c:\windows\system32\DRIVERS\ezusb64.sys [2007-02-06 33280]
    R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
    R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
    R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2009-11-04 114304]
    R3 Samsung UPD Service2;Samsung UPD Service2;c:\windows\System32\SUPDSvc2.exe [2011-12-02 165456]
    R3 SBIOSIO;SBIOSIO;c:\users\massimo\AppData\Local\Temp\__Samsung_Update\SBIOSIO64.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
    R3 vpcuxd;Servizio stub virtualizzazione USB;c:\windows\system32\DRIVERS\vpcuxd.sys [2010-11-20 16384]
    R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-28 1255736]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
    S0 excsd;ExpressCache Storage Filter Driver;c:\windows\system32\DRIVERS\excsd.sys [2011-09-23 80688]
    S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-09-16 27760]
    S1 excfs;ExpressCache File System Filter Driver;c:\windows\system32\DRIVERS\excfs.sys [2011-09-23 23344]
    S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2011-09-22 13824]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-04-18 235520]
    S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-08 86224]
    S2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
    S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2012-12-05 71032]
    S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [2012-12-05 384888]
    S2 ExpressCache;ExpressCache;c:\program files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [2011-09-23 79664]
    S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
    S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2012-12-22 35344]
    S2 NPWService;NPWService;c:\program files (x86)\Generic\USB Server\NPW\NPWService.exe [2009-09-02 783360]
    S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-09-15 88576]
    S2 SamsungDeviceConfigurationWinService;SamsungDeviceConfiguration;c:\program files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [2012-02-13 31624]
    S2 SGDrv;SGDrv;c:\windows\system32\DRIVERS\SGdrv64.sys [2011-04-11 7680]
    S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-01-31 3289208]
    S2 SWUpdateService;SW Update Service;c:\program files (x86)\Samsung\SW Update\SWMAgent.exe [2012-12-27 2879176]
    S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-11-29 3463080]
    S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-05-05 2656536]
    S2 UsbService;ASUS Virtual MFP Service;c:\program files (x86)\ASUS\Printer Utilities\UsbService64.exe [2010-08-10 334848]
    S3 acpials;ALS Sensor Filter;c:\windows\system32\DRIVERS\acpials.sys [2009-07-14 9728]
    S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2011-11-03 130536]
    S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2011-11-03 395752]
    S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2011-08-17 31216]
    S3 EST_BusEnum;Network USB Device Bus;c:\windows\system32\DRIVERS\GenBus.sys [2009-10-06 29696]
    S3 ETD;Samsung PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2012-09-25 293712]
    S3 IntcDAud;Audio schermo Intel®;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-08-23 317440]
    S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2012-01-10 12311904]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
    S3 NUS_Bus;Network USB Server Bus for E2868;c:\windows\system32\DRIVERS\NUS_Bus.sys [2009-11-09 30208]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-05-17 533096]
    S3 vuhub;Virtual Usb Hub;c:\windows\system32\DRIVERS\vuhub.sys [2007-12-17 47616]
    .
    .
    --- Altri Servizi/Drivers In Memoria ---
    .
    *NewlyCreated* - WS2IFSL
    .
    Contenuto della cartella 'Scheduled Tasks'
    .
    2013-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 15:50]
    .
    2013-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-04 11:57]
    .
    2013-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-04 11:57]
    .
    2013-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3742788777-4055952478-938898431-1000Core.job
    - c:\users\massimo\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-05 18:44]
    .
    2013-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3742788777-4055952478-938898431-1000UA.job
    - c:\users\massimo\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-05 18:44]
    .
    2013-02-06 c:\windows\Tasks\HP Photo Creations Messager.job
    - c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopFileLocked]
    @="{C253B817-3A00-475f-A5A3-6F2DD704B48D}"
    [HKEY_CLASSES_ROOT\CLSID\{C253B817-3A00-475f-A5A3-6F2DD704B48D}]
    2010-11-21 03:23 444752 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopNotSynced]
    @="{19ACC806-F7AA-46AA-A80A-726A07CA6637}"
    [HKEY_CLASSES_ROOT\CLSID\{19ACC806-F7AA-46AA-A80A-726A07CA6637}]
    2010-11-21 03:23 444752 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopNotSyncedCollabs]
    @="{337D9DE0-3F8B-4430-AF0F-FFC24A95AE8F}"
    [HKEY_CLASSES_ROOT\CLSID\{337D9DE0-3F8B-4430-AF0F-FFC24A95AE8F}]
    2010-11-21 03:23 444752 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopSynced]
    @="{B7AC9C6D-F15B-4B1A-A88D-F518D13861D9}"
    [HKEY_CLASSES_ROOT\CLSID\{B7AC9C6D-F15B-4B1A-A88D-F518D13861D9}]
    2010-11-21 03:23 444752 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopSyncedCollab]
    @="{9E48C232-F601-4E41-BB3E-16CBAF317AA4}"
    [HKEY_CLASSES_ROOT\CLSID\{9E48C232-F601-4E41-BB3E-16CBAF317AA4}]
    2010-11-21 03:23 444752 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 162552 ----a-w- c:\users\massimo\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 162552 ----a-w- c:\users\massimo\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 162552 ----a-w- c:\users\massimo\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 162552 ----a-w- c:\users\massimo\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
    2012-12-17 18:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
    2012-12-17 18:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
    2012-12-17 18:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
    2012-12-17 18:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
    @="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
    [HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
    2013-01-24 07:48 482144 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
    @="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
    [HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
    2013-01-24 07:48 482144 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
    @="{A759AFF6-5851-457D-A540-F4ECED148351}"
    [HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
    2013-01-24 07:48 482144 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
    @="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
    [HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
    2013-01-24 07:48 482144 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Seagull Drivers"="ssdal_nc.exe startup" [X]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-10 167704]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-10 392984]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-10 417560]
    "BoxSyncHelper"="c:\program files\Box Sync\BoxSyncHelper.exe" [2012-12-19 393216]
    "Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe" [2010-07-07 5392896]
    .
    ------- Scansione supplementare -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://samsung.msn.com
    mStart Page = hxxp://samsung.msn.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: I&nvia a OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
    IE: Invia immagine alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Invia pagina alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    Trusted Zone: samsungsetup.com\www
    TCP: DhcpNameServer = 192.160.1.1
    DPF: {877E14A6-0ACF-4509-8CF3-E4A0F4ED46F4} - hxxp://supportsiss.lispa.it/components/pdlc.cab
    DPF: {F39F6F0B-170B-4A3A-AF1D-11D89CFD9ED9} - hxxp://95.227.33.6/VideoX.CAB
    FF - ProfilePath - c:\users\massimo\AppData\Roaming\Mozilla\Firefox\Profiles\l6cbdwrn.default\
    FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=2&q=
    .
    - - - - CHIAVI ORFANE RIMOSSE - - - -
    .
    URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
    Toolbar-Locked - (no file)
    Toolbar-Locked - (no file)
    HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
    .
    .
    .
    --------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
    "value"="?\02\00\1a\13\0e\06O"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    @Denied: (A) (Everyone)
    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    @Denied: (A) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    "Key"="ActionsPane3"
    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Altri processi in esecuzione ------------------------
    .
    c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\BlueStacks\HD-Service.exe
    c:\program files (x86)\BlueStacks\HD-Network.exe
    c:\program files (x86)\BlueStacks\HD-BlockDevice.exe
    c:\program files (x86)\BlueStacks\HD-SharedFolder.exe
    c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
    c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe
    c:\program files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
    .
    **************************************************************************
    .
    Ora fine scansione: 2013-02-06 23:48:50 - Il pc č stato riavviato
    ComboFix-quarantined-files.txt 2013-02-06 22:48
    .
    Pre-Run: 263.806.066.688 byte disponibili
    Post-Run: 263.043.080.192 byte disponibili
    .
    - - End Of File - - ED604664E80B4D85BA6222E2508341B3
    • 0

    #6
    Render

    Render

      Trusted Helper

    • Malware Removal
    • 4,195 posts
    Hi,

    It looks like CF don't like Samsung's applications for your smart phone. So if you want to use these software further, reinstall Kies and Easy Software Manager once again. But, please, do this after I give you the final all clean post.

    Please proceed now with these steps:

    Step 1

    • Make sure to use Internet Explorer for this
    • Please go to VirSCAN.org FREE on-line scan service
    • Click on the Browse button near "Suspicious files to scan" box on the top of the page and navigate to the file below:
      • C:\Program Files (x86)\Common Files\microsoft shared\MSEnv\TextMgrP.dll
    • Click on Open and then on the Upload button
    • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
    • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
    • Paste the contents of the Clipboard in your next reply.

    Step 2

    Posted Image Malwarebytes' Anti-Malware

    I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

    • Open Malwarebytes' Anti-Malware.
    • Select the Update tab.
    • Click on Check for Updates button.
    • Click on OK.
    • Select the Scanner tab.
    • Select Perform quick scan, then click on Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the entire report in your next reply.

    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
    • 0

    #7
    madimar

    madimar

      Member

    • Topic Starter
    • Member
    • PipPip
    • 13 posts
    Step 1:
    VirSCAN.org Scanned Report :
    Scanned time : 2013/02/10 18:53:06 (CET)
    Scanner results: Scanners did not find malware!
    File Name : TextMgrP.dll
    File Size : 76800 byte
    File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
    MD5 : 8831a7163fc7229ac6ac5d9a44e86109
    SHA1 : bc62fe3ee56f929148df11042e68c8dbd2f50a5a
    Online report : http://r.virscan.org...8b1b2812ceb934b

    Scanner Engine Ver Sig Ver Sig Date Time Scan result
    a-squared 5.1.0.4 20130211012523 2013-02-11 0.00 -
    AhnLab V3 2013.02.11.00 2013.02.11 2013-02-11 0.00 -
    AntiVir 8.2.10.202 7.11.50.58 2012-11-16 0.19 -
    Antiy 2.0.18 2.0.18. 0002-18-00 0.30 -
    Arcavir 2011 201302040221 2013-02-04 5.17 -
    Authentium 5.1.1 201302091225 2013-02-09 1.59 -
    AVAST! 4.7.4 130210-0 2013-02-10 0.18 -
    AVG 12.0.1794 2639/5593 2013-02-09 0.27 -
    BitDefender 7.90123.8739683 7.45353 2013-02-10 4.66 -
    ClamAV 0.97.5 16655 2013-02-10 0.27 -
    Comodo 5.1 15219 2013-02-10 0.00 -
    CP Secure 1.3.0.5 2013.02.11 2013-02-11 0.21 -
    Dr.Web 7.0.4.9250 2013.02.09 2013-02-09 16.94 -
    F-Prot 4.6.2.117 20130201 2013-02-01 0.84 -
    F-Secure 7.02.73807 2013.02.10.04 2013-02-10 2.81 -
    Fortinet 4.3.392 16.549 2012-10-17 0.00 -
    GData 22.7862 20130210 2013-02-10 0.00 -
    ViRobot 20130208 2013.02.08 2013-02-08 0.00 -
    Ikarus T3.1.32.20.0 2013.02.10.83415 2013-02-10 7.12 -
    JiangMin 16.0.100 2013.02.09 2013-02-09 0.00 -
    Kaspersky 5.5.10 2013.02.10 2013-02-10 0.33 -
    KingSoft 2009.2.5.15 2013.2.10.9 2013-02-10 0.00 -
    McAfee 5400.1158 6981 2013-02-09 10.62 -
    Microsoft 1.9103 2013.02.10 2013-02-10 0.00 -
    NOD32 3.0.21 7951 2013-01-30 0.16 -
    Norman 6.8.3 201208311030 2012-08-31 0.00 -
    Panda 9.05.01 2013.02.09 2013-02-09 0.00 -
    Trend Micro 9.500-1005 9.674.06 2013-01-22 0.19 -
    Quick Heal 11.00 2013.02.08 2013-02-08 0.00 -
    Rising 20.0 24.48.00.04 2013-02-04 0.00 -
    Sophos 3.39.0 4.85 2013-02-10 6.29 -
    Sunbelt 3.9.2558.2 15472 2013-02-10 0.00 -
    Symantec 1.3.0.24 20130209.009 2013-02-09 0.16 -
    nProtect 20130209.01 13585888 2013-02-09 0.00 -
    The Hacker 6.8.0.0 v00189 2013-02-07 0.00 -
    VBA32 3.12.20.2 20130208.0718 2013-02-08 4.31 -
    VirusBuster 5.5.2.13 15.0.344.0/108766782013-02-10 0.27 -

    Step 2 on going
    • 0

    #8
    madimar

    madimar

      Member

    • Topic Starter
    • Member
    • PipPip
    • 13 posts
    Step 2:

    Malwarebytes Anti-Malware (Trial) 1.70.0.1100
    www.malwarebytes.org

    Database version: v2013.02.10.06

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    massimo :: SAMSUNG [administrator]

    Protection: Enabled

    10/02/2013 19:00:39
    mbam-log-2013-02-10 (19-00-39).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 220775
    Time elapsed: 9 minute(s), 15 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
    • 0

    #9
    madimar

    madimar

      Member

    • Topic Starter
    • Member
    • PipPip
    • 13 posts
    Sorry for this post: what does this mean? Was it a flase positive since the beginning? Why Avira detected it and no other antivirus (online) find anything?
    I'm a bit worried yet because I really experienced these strange behaviors in the last days, as I explained in my first post: system stuck and slow without doing anything.

    Do you have any further advice?

    My best thanks, regards,

    M
    • 0

    #10
    Render

    Render

      Trusted Helper

    • Malware Removal
    • 4,195 posts
    Yes. It seems false positive.

    What version of Avira are you running? Is virus definition file up to date?

    We should proceed with general antimalware scan which can take quite a long time so please be patient.

    Download Virus Removal Tool (VRT) from Here to your desktop
    (You have to enter your e-mail address and click on Submit Form button. Please download latest English version of this tool)

    Run the programme you have just downloaded to your desktop (it will be randomly named )

    First we will run a virus scan

    Click the cog in the upper right
    Posted Image


    Select down to and including your main drive, once done select the Automatic scan tab and press Start Scan
    (Please be patient as this scan can take a few hours)
    Posted Image

    Allow VRT to delete all infections found
    Once it has finished select report tab (last tab)
    Select Detected threads report from the left and press Save button
    Save it to your desktop and attach to your next post


    Now the Analysis

    Rerun VRT and select the Manual Disinfection tab and press Start Gathering System Information

    Posted Image

    On completion click on Report sending and then the link avptool sysinfo.zip (open the file manager) to locate the zip file to upload and attach to your next post

    Posted Image
    • 0

    Advertisements


    #11
    madimar

    madimar

      Member

    • Topic Starter
    • Member
    • PipPip
    • 13 posts
    Thank you Render.
    My Avira Antivir is "Avira Free Antivir" version 12.1.9.1236, with updated definition files. Now I'm also trying a full scan with Antivir to see what happens.
    Anyway I will now download VRT and I will follow your instructions. I'llletyou know soon.

    Regards,

    M
    • 0

    #12
    madimar

    madimar

      Member

    • Topic Starter
    • Member
    • PipPip
    • 13 posts
    MAn, I'm not able to download the tool. It tells me 404 Not found on kasperksy site (after inserting my email)
    • 0

    #13
    madimar

    madimar

      Member

    • Topic Starter
    • Member
    • PipPip
    • 13 posts
    I'm able to download only version 10 (not last version 11). I'm so selecting italian language.
    • 0

    #14
    Render

    Render

      Trusted Helper

    • Malware Removal
    • 4,195 posts
    I see. Link is currently down. Please try to download it tomorrow or if you can't wait chose version 10.
    • 0

    #15
    madimar

    madimar

      Member

    • Topic Starter
    • Member
    • PipPip
    • 13 posts
    I'll try to run version 10 this evening/night and tomorrow I will try again to download version 11.

    I'll let you know.

    Thanks

    M
    • 0






    Similar Topics

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP