This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows update

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here the OTL scan results
The setting are the same used in the first scan
One more info. I have removed my McAfee antivirus because it cause continuous mulfuction aftar any restart. (System very slow and frequent stop)

OTL logfile created on: 07/11/2010 14.57.34 - Run 2
OTL by OldTimer - Version 3.2.17.2 Folder = C:\Users\marco\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 87,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 94,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 228,01 Gb Total Space | 54,27 Gb Free Space | 23,80% Space Free | Partition Type: NTFS
Drive D: | 227,98 Gb Total Space | 69,41 Gb Free Space | 30,45% Space Free | Partition Type: NTFS
Drive F: | 7,45 Gb Total Space | 0,68 Gb Free Space | 9,12% Space Free | Partition Type: FAT32

Computer Name: PC-MARCO | User Name: marco | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
PRC - [2009/04/11 07.27.36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
MOD - [2010/08/31 16.43.52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - File not found [Unknown | Stopped] – C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe – (McShield)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2010/09/29 15.00.56 | 001,145,304 | —- | M] (PC Tools) [Auto | Stopped] – C:\Program Files\PC Tools Security\pctsSvc.exe – (sdCoreService)
SRV - [2010/09/24 11.19.06 | 000,235,472 | —- | M] (Threat Expert Ltd.) [Auto | Stopped] – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2010/08/26 11.39.46 | 000,070,928 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files\PC Tools Security\TFEngine\TFService.exe – (ThreatFire)
SRV - [2010/08/24 14.57.38 | 000,141,792 | —- | M] (McAfee, Inc.) [Unknown | Stopped] – C:\Windows\System32\mfevtps.exe – (mfevtp)
SRV - [2010/08/24 10.38.18 | 000,092,008 | —- | M] (TomTom) [Auto | Stopped] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2010/06/14 14.07.14 | 000,615,936 | —- | M] (Nokia) [On_Demand | Stopped] – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer)
SRV - [2010/04/01 13.53.28 | 000,135,288 | —- | M] (PGP Corporation) [Auto | Stopped] – C:\Windows\System32\PGPserv.exe – (PGPserv)
SRV - [2010/03/15 13.02.36 | 000,366,840 | —- | M] (PC Tools) [Auto | Stopped] – C:\Program Files\PC Tools Security\pctsAuxs.exe – (sdAuxService)
SRV - [2009/09/25 02.27.04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009/04/21 10.48.16 | 000,425,988 | —- | M] () [Auto | Stopped] – C:\Program Files\NCH Software\Eyeline\eyeline.exe – (EyelineService)
SRV - [2009/04/21 10.47.27 | 000,368,644 | —- | M] () [Auto | Stopped] – C:\Program Files\NCH Software\BroadCam\broadCam.exe – (BroadCamService)
SRV - [2009/01/26 14.31.10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Stopped] – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/05/14 17.05.30 | 000,500,784 | —- | M] (Egis Incorporated) [Auto | Stopped] – C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe – (eDataSecurity Service)
SRV - [2008/04/06 21.42.24 | 000,050,424 | —- | M] (NewTech InfoSystems, Inc.) [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe – (NTIBackupSvc)
SRV - [2008/04/04 02.03.14 | 000,131,072 | —- | M] () [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe – (NTISchedulerSvc)
SRV - [2008/03/21 12.22.52 | 000,024,576 | —- | M] () [Auto | Stopped] – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe – (ETService)
SRV - [2008/03/18 20.27.12 | 000,013,312 | —- | M] (Agere Systems) [Auto | Stopped] – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio)
SRV - [2008/03/03 12.11.14 | 000,016,384 | —- | M] (NewTech Infosystems, Inc.) [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe – (BUNAgentSvc)
SRV - [2008/01/21 03.23.32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2008/01/16 17.35.02 | 000,081,504 | —- | M] () [Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe – (CLHNService)
SRV - [2007/12/06 16.15.28 | 000,110,592 | —- | M] () [Disabled | Stopped] – C:\Acer\Mobility Center\MobilityService.exe – (MobilityService)
SRV - [2007/11/06 21.22.26 | 000,092,792 | —- | M] (CACE Technologies) [On_Demand | Stopped] – C:\Program Files\WinPcap\rpcapd.exe – (rpcapd) Remote Packet Capture Protocol v.0 (experimental)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | System | Stopped] – C:\Windows\System32\drivers\mfewfpk.sys – (mfewfpk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mferkdet.sys – (mferkdet)
DRV - File not found [Kernel | System | Stopped] – C:\Windows\System32\DRIVERS\mfenlfk.sys – (mfenlfk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfefirek.sys – (mfefirek)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\cfwids.sys – (cfwids)
DRV - [2010/10/05 10.10.56 | 000,249,616 | —- | M] (PC Tools) [Kernel | System | Stopped] – C:\Windows\System32\drivers\pctgntdi.sys – (pctgntdi)
DRV - [2010/08/27 08.26.40 | 000,070,536 | —- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\pctplsg.sys – (pctplsg)
DRV - [2010/08/26 11.39.46 | 000,068,880 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\TfSysMon.sys – (TfSysMon)
DRV - [2010/08/26 11.39.46 | 000,051,984 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\TfFsMon.sys – (TfFsMon)
DRV - [2010/08/26 11.39.46 | 000,033,552 | –S- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TfNetMon.sys – (TfNetMon)
DRV - [2010/08/24 14.57.38 | 000,386,712 | —- | M] (McAfee, Inc.) [Kernel | Boot | Stopped] – C:\Windows\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2010/08/24 14.57.38 | 000,095,600 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2010/08/18 12.51.26 | 000,237,632 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2010/07/16 13.59.54 | 000,656,320 | —- | M] (PC Tools) [File_System | Boot | Running] – C:\Windows\system32\drivers\pctEFA.sys – (pctEFA)
DRV - [2010/07/16 13.59.54 | 000,338,880 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\pctDS.sys – (pctDS)
DRV - [2010/04/01 13.53.28 | 000,266,360 | —- | M] (PGP Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\PGPwded.sys – (PGPwded)
DRV - [2010/04/01 13.53.28 | 000,243,832 | —- | M] (PGP Corporation) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PGPdisk.sys – (PGPdisk)
DRV - [2010/04/01 13.53.28 | 000,040,568 | —- | M] (PGP Corporation) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PGPsdk.sys – (PGPsdkDriver)
DRV - [2010/04/01 13.53.26 | 000,136,312 | —- | M] (PGP Corporation) [File_System | Boot | Running] – C:\Windows\System32\Drivers\PGPfsfd.sys – (pgpfs)
DRV - [2010/04/01 13.53.26 | 000,013,432 | —- | M] (PGP Corporation) [File_System | Boot | Running] – C:\Windows\system32\DRIVERS\Pgpwdefs.sys – (Pgpwdefs)
DRV - [2010/02/05 04.16.10 | 000,028,048 | —- | M] (CSR, plc) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BthAvrcp.sys – (BthAvrcp)
DRV - [2009/09/30 06.53.12 | 001,184,768 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2009/08/15 15.09.58 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2008/08/26 09.26.12 | 000,018,816 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\pccsmcfd.sys – (pccsmcfd)
DRV - [2008/08/12 13.33.38 | 000,061,440 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\RTSTOR.sys – (RTSTOR)
DRV - [2008/07/11 19.20.10 | 002,381,312 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\igdkmd32.sys – (igfx)
DRV - [2008/06/14 02.10.08 | 002,152,344 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/05/14 17.05.44 | 000,060,464 | —- | M] (Egis Incorporated) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PSDVdisk.sys – (psdvdisk)
DRV - [2008/05/14 17.05.42 | 000,018,992 | —- | M] (Egis Incorporated) [File_System | Boot | Running] – C:\Windows\system32\DRIVERS\psdfilter.sys – (PSDFilter)
DRV - [2008/05/14 17.05.42 | 000,016,944 | —- | M] (Egis Incorporated) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PSDNServ.sys – (PSDNServ)
DRV - [2008/04/25 19.08.42 | 000,199,472 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2008/04/18 14.01.24 | 000,061,424 | —- | M] (Cyberlink Corp.) [Kernel | Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl – ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796})
DRV - [2008/03/21 09.48.24 | 000,015,392 | —- | M] (Acer, Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\int15.sys – (int15)
DRV - [2008/03/01 00.13.38 | 001,202,560 | —- | M] (Agere Systems) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2008/02/21 10.55.00 | 000,299,008 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\yk60x86.sys – (yukonwlh)
DRV - [2008/02/18 15.55.20 | 000,101,376 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ewusbmdm.sys – (hwdatacard)
DRV - [2008/01/31 02.52.06 | 000,014,848 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\NTIDrvr.sys – (NTIDrvr)
DRV - [2008/01/31 02.51.50 | 000,013,824 | —- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\UBHelper.sys – (UBHelper)
DRV - [2008/01/21 03.23.27 | 000,386,616 | —- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasr.sys – (MegaSR)
DRV - [2008/01/21 03.23.27 | 000,149,560 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2008/01/21 03.23.27 | 000,031,288 | —- | M] (LSI Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2008/01/21 03.23.26 | 000,101,432 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2008/01/21 03.23.26 | 000,074,808 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2008/01/21 03.23.26 | 000,040,504 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2008/01/21 03.23.25 | 000,300,600 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2008/01/21 03.23.25 | 000,089,656 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2008/01/21 03.23.24 | 001,122,360 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2008/01/21 03.23.24 | 000,118,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2008/01/21 03.23.24 | 000,079,928 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2008/01/21 03.23.23 | 000,654,336 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTCNXT3.SYS – (winachsf)
DRV - [2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2008/01/21 03.23.23 | 000,130,616 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2008/01/21 03.23.23 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2008/01/21 03.23.23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2008/01/21 03.23.23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2008/01/21 03.23.23 | 000,079,416 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2008/01/21 03.23.23 | 000,030,720 | —- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nscirda.sys – (NSCIRDA)
DRV - [2008/01/21 03.23.22 | 000,987,648 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTDPV3.SYS – (HSF_DPV)
DRV - [2008/01/21 03.23.22 | 000,342,584 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2008/01/21 03.23.22 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2008/01/21 03.23.21 | 000,422,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2008/01/21 03.23.21 | 000,102,968 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2008/01/21 03.23.20 | 000,238,648 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2008/01/21 03.23.20 | 000,179,712 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\b57nd60x.sys – (b57nd60x)
DRV - [2008/01/21 03.23.00 | 000,020,024 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2008/01/21 03.23.00 | 000,019,000 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2008/01/21 03.23.00 | 000,017,464 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2008/01/16 17.35.08 | 000,122,368 | —- | M] (Cyberlink Corp.) [Kernel | Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys – (NTIPPKernel)
DRV - [2007/11/06 21.22.06 | 000,034,064 | —- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\npf.sys – (NPF)
DRV - [2007/03/08 09.53.44 | 000,099,584 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZTEusbser.sys – (qcusbser)
DRV - [2006/11/03 06.29.36 | 000,021,264 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\DKbFltr.sys – (DKbFltr)
DRV - [2006/11/02 10.50.35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 10.50.35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 10.50.19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 10.50.17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 10.50.11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 10.50.09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 10.50.07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 10.50.05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 10.50.03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 10.49.59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 10.49.56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 09.25.24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 09.24.47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 09.24.46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 09.24.45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 09.24.44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 09.24.44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 08.36.50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2004/01/26 16.36.35 | 000,095,552 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\Windows\System32\drivers\prohlp02.sys – (prohlp02)
DRV - [2004/01/26 16.01.28 | 000,052,224 | —- | M] (Protection Technology) [Kernel | System | Stopped] – C:\Windows\System32\drivers\prodrv06.sys – (prodrv06)
DRV - [2003/12/01 16.20.52 | 000,004,832 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\Windows\System32\drivers\sfhlp01.sys – (sfhlp01)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "NCH Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2117678&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.startup.homepage: "http://homepage.acer.com/rdr.aspx?b=ACAW&l;=0410&s;=2&o;=vp32&d;=1208&m;=aspire_5735"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}:5.0.16
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.732
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.50
FF - prefs.js..network.proxy.http: "192.168.0.1"
FF - prefs.js..network.proxy.type: 4


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/16 21.39.47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2010/10/29 05.30.59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/31 07.03.23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 05.09.56 | 000,000,000 | —D | M]

[2009/12/24 07.44.43 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Extensions
[2009/12/24 07.44.43 | 000,000,000 | —D | M] (No name found) – C:\Users\marco\AppData\Roaming\mozilla\Extensions\{2f1e6a90-e99e-11dd-ba2f-0800200c9a66}
[2009/04/18 08.35.01 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Extensions\[removed]
[2010/11/06 16.30.02 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions
[2010/10/16 04.46.40 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/11/04 18.55.55 | 000,000,000 | —D | M] (No name found) – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2009/04/21 10.48.03 | 000,000,868 | —- | M] () – C:\Users\marco\AppData\Roaming\Mozilla\FireFox\Profiles\pttb29kf.default\searchplugins\conduit.xml
[2009/08/15 15.32.53 | 000,002,395 | —- | M] () – C:\Users\marco\AppData\Roaming\Mozilla\FireFox\Profiles\pttb29kf.default\searchplugins\daemon-search.xml
[2010/11/06 16.30.02 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/03 01.52.16 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/04/05 08.57.45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}
[2006/06/16 10.16.04 | 000,205,312 | —- | M] (NETDIMENSION CORPORATION) – C:\Program Files\Mozilla Firefox\plugins\NPMXENG.DLL
[2009/08/21 22.20.57 | 000,001,412 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\demauro.xml
[2010/03/14 07.10.28 | 000,000,744 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-it.xml
[2010/03/14 07.10.28 | 000,000,825 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\hoepli.xml
[2010/03/14 07.10.28 | 000,001,182 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-it.xml
[2010/03/14 07.10.28 | 000,000,953 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-it.xml

O1 HOSTS File: ([2006/09/18 22.41.32 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101031070323.dll File not found
O2 - BHO: (DownloadStudio IE Add-on) - {8170D7DC-BDD6-461e-88EB-F047257898C9} - C:\Program Files\Conceiva\DownloadStudio\DLMonitr.dll (Conceiva Pty Ltd)
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (no name) - {B99F805C-F0B1-48EA-8C8B-753BFCBED913} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DetectDatacard] C:\Program Files\AliceEntry\DetectDatacard.exe (ONDA)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe File not found
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [ProductReg] C:\Program Files\Acer\WR_PopUp\ProductReg.exe (Acer)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Inserisci &blog; in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: carige.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: directline.it ([www] * in Siti attendibili)
O15 - HKCU\..Trusted Domains: fineco.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: internet ([]about in Siti attendibili)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Siti attendibili)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Siti attendibili)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Siti attendibili)
O15 - HKCU\..Trusted Domains: tim.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: vxsbill.com ([secure] https in Siti attendibili)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Siti attendibili)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…144/mcfscan.cab (McFreeScan Class)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\Windows\system32\hzofypl.dll) - C:\Windows\System32\hzofypl.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Acer01.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22.43.36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/10/26 08.21.46 | 000,000,219 | —- | M] () - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/11/06 18.51.55 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/11/06 18.51.55 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Local\temp
[2010/11/06 18.25.08 | 000,000,000 | –SD | C] – C:\ComboFix
[2010/11/06 18.24.46 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/11/06 16.01.12 | 000,000,000 | —D | C] – C:\Windows\pss
[2010/11/06 15.43.09 | 000,000,000 | —D | C] – C:\Windows\panther
[2010/11/06 06.58.06 | 000,101,376 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbmdm.sys
[2010/11/06 06.58.06 | 000,100,864 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbnet.sys
[2010/11/06 06.58.06 | 000,023,424 | —- | C] (Huawei Tech. Co., Ltd.) – C:\Windows\System32\drivers\ewdcsc.sys
[2010/11/06 06.37.24 | 000,000,000 | —D | C] – C:\Windows\LastGood.Tmp
[2010/11/05 06.03.17 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/11/05 06.03.17 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/11/05 06.03.17 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/11/05 06.03.09 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/11/05 06.02.44 | 000,000,000 | —D | C] – C:\Qoobox
[2010/11/05 05.50.00 | 000,000,000 | —D | C] – C:\ProgramData\moosoft
[2010/11/04 23.15.18 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2010/11/04 23.15.12 | 000,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2010/11/04 22.53.01 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\thecleaner
[2010/11/04 22.52.47 | 000,000,000 | —D | C] – C:\Program Files\The Cleaner
[2010/11/04 22.31.58 | 000,000,000 | —D | C] – C:\Users\marco\Documents\Usenet.nl
[2010/11/04 22.31.58 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\Usenet.nl
[2010/11/04 22.31.49 | 000,000,000 | —D | C] – C:\Program Files\Usenet.nl
[2010/11/04 22.31.24 | 036,946,400 | —- | C] (MooSoft Development LLC ) – C:\Users\marco\Desktop\cleaner7_setup.exe
[2010/11/04 22.27.20 | 003,023,984 | —- | C] ( ) – C:\Users\marco\Desktop\UsenetNLSetup_422135f.exe
[2010/11/04 19.20.11 | 001,913,056 | —- | C] (Trend Micro Inc.) – C:\Users\marco\Desktop\HousecallLauncher.exe
[2010/11/04 18.56.03 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\QuickScan
[2010/11/04 06.26.55 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2010/11/03 06.05.56 | 001,317,464 | —- | C] (Kaspersky Lab ZAO) – C:\Users\marco\Desktop\TDSSKiller.exe
[2010/11/01 07.04.13 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
[2010/10/31 22.06.11 | 004,813,736 | —- | C] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\systemtweaker.exe
[2010/10/31 21.40.27 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\Uniblue
[2010/10/31 21.40.19 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2010/10/31 16.10.03 | 005,273,528 | —- | C] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\registrybooster.exe
[2010/10/31 09.01.56 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Local\Threat Expert
[2010/10/31 07.02.14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2010/10/31 07.02.00 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2010/10/29 05.32.05 | 000,068,880 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
[2010/10/29 05.32.05 | 000,051,984 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2010/10/29 05.32.05 | 000,033,552 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2010/10/29 05.30.56 | 001,914,832 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2010/10/29 05.30.56 | 000,743,376 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2010/10/29 05.30.56 | 000,149,456 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2010/10/28 22.23.38 | 000,656,320 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctEFA.sys
[2010/10/28 22.23.38 | 000,338,880 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctDS.sys
[2010/10/28 22.23.31 | 000,249,616 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2010/10/28 22.23.30 | 000,102,184 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/10/28 22.23.11 | 000,237,632 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2010/10/28 22.23.11 | 000,159,936 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/10/28 22.22.30 | 000,123,712 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2010/10/28 22.22.30 | 000,087,400 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2010/10/28 22.22.30 | 000,031,960 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2010/10/28 22.22.24 | 000,070,536 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\PC Tools
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.c698.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.a323.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.710c.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.3318.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe
[2010/10/28 22.02.12 | 003,136,440 | —- | C] (McAfee, Inc.) – C:\Users\marco\Desktop\DMSetup.exe
[2010/10/28 21.25.55 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2010/10/28 21.07.41 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/10/28 21.07.41 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/10/24 14.45.27 | 000,000,000 | —D | C] – C:\Users\marco\Desktop\backups
[2010/10/24 14.27.32 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\marco\Desktop\HiJackThis.exe
[2010/10/23 07.42.43 | 000,000,000 | —D | C] – C:\Windows\McAfee.com
[2010/10/19 23.23.59 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\AnVi
[2008/12/04 19.14.24 | 000,049,152 | —- | C] ( ) – C:\Windows\Interop.IWshRuntimeLibrary.dll
[4 C:\Users\marco\Documents\*.tmp files -> C:\Users\marco\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\marco\*.tmp files -> C:\Users\marco\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/07 09.41.56 | 000,006,648 | —- | M] () – C:\Users\marco\AppData\Local\d3d9caps.dat
[2010/11/07 09.38.17 | 000,661,860 | —- | M] () – C:\Windows\System32\perfh010.dat
[2010/11/07 09.38.17 | 000,586,568 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/07 09.38.17 | 000,119,742 | —- | M] () – C:\Windows\System32\perfc010.dat
[2010/11/07 09.38.17 | 000,100,640 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/07 09.34.01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/07 09.33.50 | 268,435,456 | -HS- | M] () – C:\Windows\System32\temppf.sys
[2010/11/06 18.21.52 | 003,903,895 | R— | M] () – C:\Users\marco\Desktop\ComboFix.exe
[2010/11/06 17.00.19 | 000,001,132 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/06 17.00.17 | 000,000,332 | —- | M] () – C:\Windows\tasks\RegistryBooster.job
[2010/11/06 15.44.27 | 000,002,562 | —- | M] () – C:\Windows\diagwrn.xml
[2010/11/06 15.44.27 | 000,001,908 | —- | M] () – C:\Windows\diagerr.xml
[2010/11/06 15.43.51 | 000,002,354 | —- | M] () – C:\Users\marco\Desktop\Windows_Rapporto compatibilità.htm
[2010/11/06 13.39.00 | 000,000,442 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{75E1966D-AD9F-42D4-A7B8-0965F1B2B3CC}.job
[2010/11/06 13.38.49 | 000,009,216 | —- | M] () – C:\Windows\System32\umstartup.etl
[2010/11/06 06.58.15 | 000,000,876 | —- | M] () – C:\Users\Public\Desktop\Alice MOBILE E169.lnk
[2010/11/05 21.15.49 | 000,088,576 | —- | M] () – C:\Windows\MBR.exe
[2010/11/04 23.15.00 | 001,709,408 | —- | M] () – C:\Users\marco\Desktop\taskmanager17.exe
[2010/11/04 22.52.55 | 000,000,771 | —- | M] () – C:\Users\Public\Desktop\The Cleaner 2011.lnk
[2010/11/04 22.52.23 | 036,946,400 | —- | M] (MooSoft Development LLC ) – C:\Users\marco\Desktop\cleaner7_setup.exe
[2010/11/04 22.31.49 | 000,001,678 | —- | M] () – C:\Users\marco\Desktop\Usenet.nl.lnk
[2010/11/04 22.28.46 | 003,023,984 | —- | M] ( ) – C:\Users\marco\Desktop\UsenetNLSetup_422135f.exe
[2010/11/04 21.27.54 | 002,100,028 | —- | M] () – C:\Windows\System32\drivers\Cat.DB
[2010/11/04 19.20.23 | 001,913,056 | —- | M] (Trend Micro Inc.) – C:\Users\marco\Desktop\HousecallLauncher.exe
[2010/11/04 18.53.35 | 001,080,832 | —- | M] () – C:\Users\marco\Desktop\msxml3.msi
[2010/11/04 18.49.00 | 003,136,440 | —- | M] (McAfee, Inc.) – C:\Users\marco\Desktop\DMSetup.exe
[2010/11/04 06.59.07 | 000,000,092 | —- | M] () – C:\Users\marco\Desktop\fig.reg
[2010/11/03 22.04.56 | 000,021,504 | —- | M] () – C:\Windows\System32\umstartup000.etl
[2010/11/03 06.31.02 | 000,001,136 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/03 06.22.42 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 06.22.42 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 06.22.38 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/11/03 05.55.19 | 001,207,026 | —- | M] () – C:\Users\marco\Desktop\tdsskiller.zip
[2010/11/01 21.06.11 | 289,248,269 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/11/01 18.51.42 | 000,000,474 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for marco.job
[2010/11/01 07.21.44 | 000,286,404 | —- | M] () – C:\Users\marco\Desktop\gmer.zip
[2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
[2010/10/31 22.08.48 | 000,000,919 | —- | M] () – C:\Users\Public\Desktop\SystemTweaker.lnk
[2010/10/31 22.07.58 | 004,813,736 | —- | M] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\systemtweaker.exe
[2010/10/31 21.40.23 | 000,000,929 | —- | M] () – C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/10/31 16.10.55 | 005,273,528 | —- | M] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\registrybooster.exe
[2010/10/31 15.34.06 | 000,164,352 | —- | M] () – C:\Users\marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/31 09.01.19 | 000,689,664 | —- | M] () – C:\Users\marco\Desktop\MicrosoftFixit50202.msi
[2010/10/30 17.29.00 | 003,059,712 | —- | M] () – C:\Users\marco\Desktop\mvt_it.msi
[2010/10/28 22.22.53 | 000,001,824 | —- | M] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/10/28 21.37.02 | 001,373,616 | —- | M] () – C:\Users\marco\Desktop\MCPR.exe
[2010/10/28 21.25.14 | 000,507,360 | —- | M] () – C:\Users\marco\Desktop\sdsetup.exe
[2010/10/28 21.08.00 | 000,001,095 | —- | M] () – C:\Users\marco\Desktop\Spybot - Search & Destroy.lnk
[2010/10/28 05.20.24 | 000,000,036 | —- | M] () – C:\Users\marco\AppData\Local\housecall.guid.cache
[2010/10/26 11.30.08 | 001,317,464 | —- | M] (Kaspersky Lab ZAO) – C:\Users\marco\Desktop\TDSSKiller.exe
[2010/10/24 14.27.51 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\marco\Desktop\HiJackThis.exe
[2010/10/19 20.47.59 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2010/10/19 16.00.08 | 000,294,912 | —- | M] () – C:\Users\marco\Desktop\gmer.exe
[2010/10/17 15.01.54 | 000,024,064 | —- | M] () – C:\Users\marco\Documents\It is not possible to select your own login for this site.doc
[2010/10/17 14.16.55 | 000,075,731 | —- | M] () – C:\Users\marco\Documents\540335p.pdf
[2010/10/14 20.50.21 | 000,304,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/12 21.24.49 | 000,001,927 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[4 C:\Users\marco\Documents\*.tmp files -> C:\Users\marco\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\marco\*.tmp files -> C:\Users\marco\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/06 18.24.40 | 003,903,895 | R— | C] () – C:\Users\marco\Desktop\ComboFix.exe
[2010/11/06 13.13.44 | 000,002,354 | —- | C] () – C:\Users\marco\Desktop\Windows_Rapporto compatibilità.htm
[2010/11/06 13.12.22 | 000,002,562 | —- | C] () – C:\Windows\diagwrn.xml
[2010/11/06 13.12.22 | 000,001,908 | —- | C] () – C:\Windows\diagerr.xml
[2010/11/06 06.58.15 | 000,000,876 | —- | C] () – C:\Users\Public\Desktop\Alice MOBILE E169.lnk
[2010/11/05 06.03.17 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/11/05 06.03.17 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/11/05 06.03.17 | 000,088,576 | —- | C] () – C:\Windows\MBR.exe
[2010/11/05 06.03.17 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/11/05 06.03.17 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/11/04 23.14.48 | 001,709,408 | —- | C] () – C:\Users\marco\Desktop\taskmanager17.exe
[2010/11/04 22.52.55 | 000,000,771 | —- | C] () – C:\Users\Public\Desktop\The Cleaner 2011.lnk
[2010/11/04 22.31.49 | 000,001,678 | —- | C] () – C:\Users\marco\Desktop\Usenet.nl.lnk
[2010/11/04 18.53.35 | 001,080,832 | —- | C] () – C:\Users\marco\Desktop\msxml3.msi
[2010/11/04 06.59.07 | 000,000,092 | —- | C] () – C:\Users\marco\Desktop\fig.reg
[2010/11/03 06.30.20 | 268,435,456 | -HS- | C] () – C:\Windows\System32\temppf.sys
[2010/11/03 05.55.06 | 001,207,026 | —- | C] () – C:\Users\marco\Desktop\tdsskiller.zip
[2010/11/01 11.27.11 | 000,294,912 | —- | C] () – C:\Users\marco\Desktop\gmer.exe
[2010/11/01 07.21.37 | 000,286,404 | —- | C] () – C:\Users\marco\Desktop\gmer.zip
[2010/10/31 22.08.48 | 000,000,919 | —- | C] () – C:\Users\Public\Desktop\SystemTweaker.lnk
[2010/10/31 21.40.35 | 000,000,332 | —- | C] () – C:\Windows\tasks\RegistryBooster.job
[2010/10/31 21.40.23 | 000,000,929 | —- | C] () – C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/10/31 09.00.30 | 000,689,664 | —- | C] () – C:\Users\marco\Desktop\MicrosoftFixit50202.msi
[2010/10/30 07.11.43 | 003,059,712 | —- | C] () – C:\Users\marco\Desktop\mvt_it.msi
[2010/10/29 05.30.57 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2010/10/29 05.30.57 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2010/10/29 05.30.56 | 000,002,052 | —- | C] () – C:\Windows\UDB.zip
[2010/10/29 05.30.56 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2010/10/29 05.30.56 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2010/10/28 22.23.41 | 002,100,028 | —- | C] () – C:\Windows\System32\drivers\Cat.DB
[2010/10/28 22.22.53 | 000,001,824 | —- | C] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/10/28 22.02.03 | 001,373,616 | —- | C] () – C:\Users\marco\Desktop\MCPR.exe
[2010/10/28 21.25.55 | 000,507,360 | —- | C] () – C:\Users\marco\Desktop\sdsetup.exe
[2010/10/28 21.08.00 | 000,001,095 | —- | C] () – C:\Users\marco\Desktop\Spybot - Search & Destroy.lnk
[2010/10/28 05.20.24 | 000,000,036 | —- | C] () – C:\Users\marco\AppData\Local\housecall.guid.cache
[2010/10/17 15.01.52 | 000,024,064 | —- | C] () – C:\Users\marco\Documents\It is not possible to select your own login for this site.doc
[2010/10/17 14.16.54 | 000,075,731 | —- | C] () – C:\Users\marco\Documents\540335p.pdf
[2010/10/12 21.24.49 | 000,001,927 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/09/23 11.13.32 | 000,000,120 | —- | C] () – C:\Users\marco\AppData\Local\Dgigalu.dat
[2010/09/23 11.13.32 | 000,000,000 | —- | C] () – C:\Users\marco\AppData\Local\Olirihoji.bin
[2010/04/01 13.53.28 | 000,000,280 | —- | C] () – C:\Windows\System32\PGPsdk.dll.sig
[2009/11/23 04.21.51 | 000,000,424 | —- | C] () – C:\Windows\ODBC.INI
[2009/08/15 15.09.58 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/08/15 07.00.45 | 000,019,456 | —- | C] () – C:\Windows\System32\ventmon.dll
[2009/08/03 14.07.42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/28 22.06.04 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/04 05.42.55 | 000,000,033 | —- | C] () – C:\Windows\DownloadStudioScheduleMonitor.INI
[2009/05/01 06.02.47 | 000,000,004 | RHS- | C] () – C:\ProgramData\sysqcl1129139270.dat
[2009/04/29 16.56.31 | 000,000,992 | —- | C] () – C:\Windows\photopnt.ini
[2009/04/29 13.03.43 | 000,006,648 | —- | C] () – C:\Users\marco\AppData\Local\d3d9caps.dat
[2009/04/27 07.57.12 | 000,017,408 | —- | C] () – C:\Windows\System32\Delphimm.dll
[2009/04/22 07.19.13 | 000,003,676 | —- | C] () – C:\Users\marco\AppData\Roaming\wklnhst.dat
[2009/04/18 15.07.59 | 000,004,935 | —- | C] () – C:\ProgramData\srpdbdrl.vrc
[2009/04/16 13.17.24 | 000,164,352 | —- | C] () – C:\Users\marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/04 19.00.35 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1527.dll
[2008/12/04 09.31.15 | 000,204,800 | —- | C] () – C:\Windows\System32\SysHook.dll
[2008/12/04 09.29.31 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2008/12/04 09.29.31 | 000,000,036 | —- | C] () – C:\Windows\PidList.ini
[2008/12/04 09.28.11 | 000,001,694 | —- | C] () – C:\Windows\RtDefLvl.ini
[2008/06/03 21.47.50 | 000,015,360 | —- | C] () – C:\Windows\System32\hzofypl.dll
[2008/05/07 22.28.17 | 000,487,424 | —- | C] () – C:\Windows\System32\INT15.dll
[2008/05/07 22.25.27 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIOFM4.dll
[2008/05/07 22.25.27 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIBUN5.dll
[2008/04/30 09.09.06 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2008/04/30 09.09.01 | 000,872,448 | —- | C] () – C:\Windows\iconv.dll
[2008/04/30 09.09.01 | 000,743,424 | —- | C] () – C:\Windows\libxml2.dll
[2008/04/30 09.09.01 | 000,000,042 | —- | C] () – C:\Windows\Prelaunch.ini
[2007/11/06 21.19.28 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2006/11/02 13.35.32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 08.40.29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2001/12/26 15.12.30 | 000,065,536 | —- | C] () – C:\Windows\System32\multiplex_vcd.dll
[2001/09/03 22.46.38 | 000,110,592 | —- | C] () – C:\Windows\System32\Hmpg12.dll
[2001/07/30 15.33.56 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC.dll
[2001/07/23 21.04.36 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC_MMX.dll
[2000/06/21 20.22.35 | 000,126,336 | —- | C] () – C:\Windows\System32\hpf9xdr0.drv

========== LOP Check ==========

[2008/05/07 22.24.09 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Acer GameZone Console
[2009/05/17 08.40.19 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\AliceEntry
[2010/10/27 23.50.22 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\AnVi
[2009/05/04 05.42.55 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Conceiva
[2009/08/15 16.45.34 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\DAEMON Tools Lite
[2009/04/18 14.56.29 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Devicescape
[2009/04/18 14.28.58 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\eSobi
[2010/08/10 11.38.20 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\ICAClient
[2010/09/24 00.17.12 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Juniper Networks
[2009/04/21 10.50.53 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\NCH Swift Sound
[2010/09/26 16.43.44 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Nokia
[2009/05/27 22.07.06 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\OfficeWork Software
[2010/09/18 06.59.26 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\PC Suite
[2010/10/19 21.54.12 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\PGP Corporation
[2010/11/04 18.56.28 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\QuickScan
[2009/05/27 21.57.07 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\RelevantReach
[2009/12/24 07.44.19 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Scendix Software
[2009/04/22 07.19.15 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Template
[2010/11/04 22.53.02 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\thecleaner
[2009/04/18 08.34.50 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\TomTom
[2010/10/31 22.08.52 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Uniblue
[2010/11/04 22.35.41 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Usenet.nl
[2010/11/06 17.00.17 | 000,000,332 | —- | M] () – C:\Windows\Tasks\RegistryBooster.job
[2010/11/07 09.19.39 | 000,032,490 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/06 13.39.00 | 000,000,442 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{75E1966D-AD9F-42D4-A7B8-0965F1B2B3CC}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 10.49.52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 03.23.00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 03.23.00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 10.49.36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 10.46.03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 10.46.03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/01/12 21.30.08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\Cyberlink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 10.51.25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/11 07.28.23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/11 07.28.23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 03.24.05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 10.50.13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/21 03.24.50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 07.28.24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/11 07.28.24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009/08/15 15.09.58 | 000,721,904 | —- | M] () Unable to obtain MD5 – C:\Windows\System32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2008/01/21 04.14.18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04.14.08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04.14.18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11.34.08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11.34.08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /90 >
[2010/08/24 14.57.38 | 000,095,600 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeapfk.sys
[2010/08/24 14.57.38 | 000,386,712 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfehidk.sys
[2010/09/30 07.58.32 | 000,159,936 | —- | M] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/08/18 12.51.26 | 000,237,632 | —- | M] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2010/10/05 10.10.56 | 000,249,616 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2010/08/10 16.58.50 | 000,031,960 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2010/09/03 11.28.54 | 000,087,400 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2010/10/05 10.11.12 | 000,123,712 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2010/08/27 08.26.40 | 000,070,536 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2010/08/28 11.28.48 | 000,102,184 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/09/06 14.45.38 | 000,304,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2010/09/06 14.45.22 | 000,145,408 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv2.sys
[2010/09/06 14.45.19 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/08/26 11.39.46 | 000,051,984 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2010/08/26 11.39.46 | 000,033,552 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2010/08/26 11.39.46 | 000,068,880 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 180 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4298B0A2
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:430C6D84

< End of report >
Hello marcopcnn

Thank you for the log.

Please do the following:

  • Please open OTL


  • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {B99F805C-F0B1-48EA-8C8B-753BFCBED913} - No CLSID value found.
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O15 - HKCU\..Trusted Domains: carige.it ([www] http in Siti attendibili)
    O15 - HKCU\..Trusted Domains: directline.it ([www] * in Siti attendibili)
    O15 - HKCU\..Trusted Domains: fineco.it ([www] http in Siti attendibili)
    O15 - HKCU\..Trusted Domains: internet ([]about in Siti attendibili)
    O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Siti attendibili)
    O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Siti attendibili)
    O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Siti attendibili)
    O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Siti attendibili)
    O15 - HKCU\..Trusted Domains: tim.it ([www] http in Siti attendibili)
    O15 - HKCU\..Trusted Domains: vxsbill.com ([secure] https in Siti attendibili)
    O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Siti attendibili)
    O20 - AppInit_DLLs: (C:\Windows\system32\hzofypl.dll) - C:\Windows\System32\hzofypl.dll ()
    [2010/09/23 11.13.32 | 000,000,120 | —- | C] () – C:\Users\marco\AppData\Local\Dgigalu.dat
    [2010/09/23 11.13.32 | 000,000,000 | —- | C] () – C:\Users\marco\AppData\Local\Olirihoji.bin
    [2008/06/03 21.47.50 | 000,015,360 | —- | C] () – C:\Windows\System32\hzofypl.dll
    [4 C:\Users\marco\Documents\*.tmp files -> C:\Users\marco\Documents\*.tmp -> ]
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [1 C:\Users\marco\*.tmp files -> C:\Users\marco\*.tmp -> ]
    [1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
    [1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]

  • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
  • Allow the program to run unhindered.
  • Your machine will re-start itself. This is normal.
  • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

Please post the OTL log in your next reply and describe to me how the machine is running now.
Done, following the content of the OTL log file All processes killed Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret <[2010/09/23 11.13.32 | 000,000,120 | —- | C] () – C:\Users\marco\AppData\Local\Dgigalu.dat> in the current context! Error: Unable to interpret <[2010/09/23 11.13.32 | 000,000,000 | —- | C] () – C:\Users\marco\AppData\Local\Olirihoji.bin> in the current context! Error: Unable to interpret <[2008/06/03 21.47.50 | 000,015,360 | —- | C] () – C:\Windows\System32\hzofypl.dll> in the current context! Error: Unable to interpret <[4 C:\Users\marco\Documents\*.tmp files -> C:\Users\marco\Documents\*.tmp -> ]> in the current context! Error: Unable to interpret <[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]> in the current context! Error: Unable to interpret <[1 C:\Users\marco\*.tmp files -> C:\Users\marco\*.tmp -> ]> in the current context! Error: Unable to interpret <[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]> in the current context! Error: Unable to interpret <[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]> in the current context! ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 134 bytes ->Flash cache emptied: 116 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: marco ->Temp folder emptied: 195108 bytes ->Temporary Internet Files folder emptied: 322743114 bytes ->Java cache emptied: 60896900 bytes ->FireFox cache emptied: 42957463 bytes ->Google Chrome cache emptied: 7086181 bytes ->Flash cache emptied: 126456 bytes User: Public User: tristano ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 75 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 92 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 1063 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 414,00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: marco ->Flash cache emptied: 0 bytes User: Public User: tristano ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.17.2 log created on 11072010_185601
Hello marcopcnn

It does not look as though the script worked. When you copy and paste the script into OTL, please make sure that you include the ":" in :OTL.

Give it another try and please describe exactly how the machine is running when you post the log :)
You are right, When I copy I lose the ":" Following the correct ( I Hope) log file All processes killed ========== OTL ========== No active process named explorer.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B99F805C-F0B1-48EA-8C8B-753BFCBED913} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B99F805C-F0B1-48EA-8C8B-753BFCBED913}\ not found. Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\carige.it\www\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\directline.it\www\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fineco.it\www\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\microsoft.com\*.update\ deleted successfully. Invalid CLSID key: *.update Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\microsoft.com\*.update\ not found. Invalid CLSID key: *.update Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tim.it\www\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\vxsbill.com\secure\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\windowsupdate.com\download\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\Windows\system32\hzofypl.dll deleted successfully. C:\Windows\System32\hzofypl.dll moved successfully. C:\Users\marco\AppData\Local\Dgigalu.dat moved successfully. C:\Users\marco\AppData\Local\Olirihoji.bin moved successfully. File C:\Windows\System32\hzofypl.dll not found. C:\Users\marco\Documents\~WRL1476.tmp deleted successfully. C:\Users\marco\Documents\~WRL2599.tmp deleted successfully. C:\Users\marco\Documents\~WRL3822.tmp deleted successfully. C:\Users\marco\Documents\~WRL4058.tmp deleted successfully. C:\Users\marco\ia_remove.sh8553.tmp deleted successfully. C:\ProgramData\id.tmp deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: marco ->Temp folder emptied: 31832 bytes ->Temporary Internet Files folder emptied: 688262 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: tristano ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 92 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1,00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: marco ->Flash cache emptied: 0 bytes User: Public User: tristano ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.17.2 log created on 11072010_215942
Unfortunately nothing is changed. After reboot i have olways the blue screen with the same error
The PC is working only on safe mode
Is this maybe related to some missing or wrong system file due to the virus removal ?
I am afraid of the missin Vista installation disk

Following HJT log file
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22.11.44, on 08/11/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\PC Tools Security\pctsGui.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Users\marco\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…p;m=aspire_5735
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…p;m=aspire_5735
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…p;m=aspire_5735
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll (file missing)
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101031070323.dll (file missing)
O2 - BHO: IeMonitor - {8170D7DC-BDD6-461e-88EB-F047257898C9} - C:\Program Files\Conceiva\DownloadStudio\DLMonitr.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: (no name) - {B99F805C-F0B1-48EA-8C8B-753BFCBED913} - (no file)
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [DetectDatacard] C:\Program Files\AliceEntry\DetectDatacard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Security\pctsGui.exe" /hideGUI
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…144/mcfscan.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - AppInit_DLLs: C:\Windows\system32\hzofypl.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: BroadCam Service (BroadCamService) - Unknown owner - C:\Program Files\NCH Software\BroadCam\broadCam.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Eyeline Service (EyelineService) - Unknown owner - C:\Program Files\NCH Software\Eyeline\eyeline.exe
O23 - Service: Servizio di Google Update (gupdate1c9bea163443ae6) (gupdate1c9bea163443ae6) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: McAfee Servizio Personal Firewall (McMPFSvc) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: McAfee Scanner (McODS) - Unknown owner - C:\Program Files\McAfee\VirusScan\mcods.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe (file missing)
O23 - Service: McAfee Firewall Core Service (mfefire) - Unknown owner - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe (file missing)
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: PGPserv - PGP Corporation - C:\Windows\system32\PGPserv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Security\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\PC Tools Security\TFEngine\TFService.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

–
End of file - 11053 bytes
I have found tha there is a key combination that can start the restore procedure for my pre installed vista Home premium. The procedure will restore the original ACER configuration. What do you think ? Is it usefull tha I use these procedure instead of the installation disk tha you require some post ago ? Let me know your suggestion.
Hello marcopcnn

Let me know your suggestion.

That is an option we can use, but I have not given up on you yet. Lets try this first.

Please do the following from Safe Mode with Networking:


  • mbr.exe


    • Please download mbr.exe and save it to the root directory, usually C:\ <- (Important).

  • Next


    • Open Notepad (Start > All Programs > Accessories).
    • Copy and Paste the text in the code box below into Notepad

    @echo off
    @mbr -t 
    @start log.txt

    • Save this as mbr.bat to your desktop.
    • You will see an icon on your desktop called mbr.bat
    • Double click on it to run.
    • A log should be created on your desktop, please post it in your next reply.
I have exactly done what you suggest, following the result 1) A dos windows is opened, with the indication c:\windpws\system32\cmd.exe 2) The windows appears blak with no other information 3) No LOG (OR txt) file created 4) The windows stay open as no instruction loaded ( No executed command appears) it seems that somefing is not working May I run MRB.exe directely from the c:\ double clicking on the mbr.exe file on c: P.S: Sorry for the question but it seems tha there was a different message few ours ago, with instruction to act on local registry Have youy changed your mind or is mine mistake ?
Hello marcopcnn

Sorry for the question but it seems tha there was a different message few ours ago, with instruction to act on local registry

I do not understand what you mean here marco.

I asked you if you had your installation disk earlier, but if you have a set of restore disks they can be used to return your machine to the way it was when you first bought it. If you decide to use them you must save all of your data first as it will NOT be saved when you perform the restore.

it seems that somefing is not working

I agree. Lets check a few things before we continue:

First, when you save the mbr.bat file, please make sure that you save it as Type 'All Files' and save it directly to the C:\ drive where you saved mbr.exe

Once you have done this, navigate to mbr.bat and double click on it to run the file again. If a log is created this time please post it in your next reply.

If no log is created, please run GMER again from safe mode (instructions in post number 2) and post the log when it has finished scanning :)

Hello marcopcnn

Sorry for the question but it seems tha there was a different message few ours ago, with instruction to act on local registry

I do not understand what you mean here marco.

I asked you if you had your installation disk earlier, but if you have a set of restore disks they can be used to return your machine to the way it was when you first bought it. If you decide to use them you must save all of your data first as it will NOT be saved when you perform the restore.

it seems that somefing is not working

I agree. Lets check a few things before we continue:

First, when you save the mbr.bat file, please make sure that you save it as Type 'All Files' and save it directly to the C:\ drive where you saved mbr.exe

Once you have done this, navigate to mbr.bat and double click on it to run the file again. If a log is created this time please post it in your next reply.

If no log is created, please run GMER again from safe mode (instructions in post number 2) and post the log when it has finished scanning :)


OK mbr starts but at the end and error "Enable to find log.txt" appears. The DOS windows stay open and it is possible to readf the content..
It is short so if needed i can type the entire message in the next post typing the content from the screen. At the end of the there is the indication that possible rootkit infection was found.
One more thing. looking at the last hJT report i have seen tha McAfee is steel present.
This is very strange because, as explained, i have completely removed this antivuirus few days ago using the McAfee removal tools and deleting any remaining McAfee dir manully.
But today a McAfee dir is present
According to your instruction i am running Gmer and I will post the resulting log as soon as the analysis will be completed
Attached the gmer log file content
GMER 1.0.15.15477 - http://www.gmer.net
Rootkit scan 2010-11-10 07:28:37
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\marco\AppData\Local\Temp\kwtyapoc.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x8A996A96] <– ROOTKIT !!!
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x8A996D5E] <– ROOTKIT !!!
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x8A996506] <– ROOTKIT !!!
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8A99705A] <– ROOTKIT !!!

INT 0x72 ? 85FA0BF8
INT 0x72 ? 85FA0BF8
INT 0x72 ? 85FA0BF8
INT 0x72 ? 85FA0BF8
INT 0x72 ? 85FA0BF8
INT 0x82 ? 85FA0BF8
INT 0x92 ? 85321BF8
INT 0x92 ? 85321BF8
INT 0x92 ? 85321BF8
INT 0x92 ? 85321BF8
INT 0x92 ? 85321BF8
INT 0xA2 ? 85FA0BF8

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 209 826EA96C 8 Bytes [96, 6A, 99, 8A, 5E, 6D, 99, …]
.text ntkrnlpa.exe!KeSetEvent + 621 826EAD84 4 Bytes [06, 65, 99, 8A]
.text ntkrnlpa.exe!KeSetEvent + 6E5 826EAE48 4 Bytes [5A, 70, 99, 8A]
? System32\Drivers\spuc.sys Impossibile trovare il percorso specificato. !
.text USBPORT.SYS!DllUnload 8ADD741B 5 Bytes JMP 85FA01D8
.text a18ijg9c.SYS 8E7AC000 22 Bytes [82, 23, 61, 82, 6C, 22, 61, …]
.text a18ijg9c.SYS 8E7AC017 98 Bytes [00, 32, B7, 79, 80, 3D, B5, …]
.text a18ijg9c.SYS 8E7AC07A 82 Bytes [72, 82, E3, 71, 65, 82, 18, …]
.text a18ijg9c.SYS 8E7AC0CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, …]
.text a18ijg9c.SYS 8E7AC0DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, …]
.text …
? \ArcName\multi(0)disk(0)rdisk(0)partition(2)\Windows\system32\drivers\PctWfpFilter.sys Impossibile trovare il percorso specificato. !

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 85CC21F8

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

Device \FileSystem\fastfat \FatCdrom 868741F8
Device \Driver\netbt \Device\NetBT_Tcpip_{E32137B0-9136-4E14-A212-B582DD75950F} 868021F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF dinamico/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF dinamico/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 853231F8
Device \Driver\netbt \Device\NetBT_Tcpip_{401AB5F1-76EE-4C34-8495-845C9DB36442} 868021F8
Device \Driver\usbuhci \Device\USBPDO-0 860091F8
Device \Driver\usbuhci \Device\USBPDO-1 860091F8
Device \Driver\usbuhci \Device\USBPDO-2 860091F8
Device \Driver\usbehci \Device\USBPDO-3 860071F8
Device \Driver\usbuhci \Device\USBPDO-4 860091F8

AttachedDevice \Driver\tdx \Device\Tcp pctgntdi.sys

Device \Driver\usbuhci \Device\USBPDO-5 860091F8
Device \Driver\usbuhci \Device\USBPDO-6 860091F8
Device \Driver\volmgr \Device\HarddiskVolume1 853231F8
Device \Driver\usbehci \Device\USBPDO-7 860071F8
Device \Driver\volmgr \Device\HarddiskVolume2 853231F8
Device \Driver\cdrom \Device\CdRom0 8609C1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85CC01F8
Device \Driver\atapi \Device\Ide\IdePort0 85CC01F8
Device \Driver\atapi \Device\Ide\IdePort1 85CC01F8
Device \Driver\atapi \Device\Ide\IdePort2 85CC01F8
Device \Driver\atapi \Device\Ide\IdePort3 85CC01F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 85CC01F8
Device \Driver\msahci \Device\Ide\PciIde0Channel0 85CC11F8
Device \Driver\msahci \Device\Ide\PciIde0Channel1 85CC11F8
Device \Driver\msahci \Device\Ide\PciIde0Channel4 85CC11F8
Device \Driver\msahci \Device\Ide\PciIde0Channel5 85CC11F8
Device \Driver\volmgr \Device\HarddiskVolume3 853231F8
Device \Driver\cdrom \Device\CdRom1 8609C1F8
Device \Driver\prohlp02 \Device\ProHlp02 8D2C2E90
Device \Driver\netbt \Device\NetBt_Wins_Export 868021F8
Device \Driver\Smb \Device\NetbiosSmb 867FF1F8
Device \Driver\iScsiPrt \Device\RaidPort0 860A5500

AttachedDevice \Driver\tdx \Device\Udp pctgntdi.sys
AttachedDevice \Driver\tdx \Device\RawIp pctgntdi.sys

Device \Driver\usbuhci \Device\USBFDO-0 860091F8
Device \Driver\sptd \Device\1825649180 spuc.sys
Device \Driver\PCI_PNP3169 \Device\0000006d spuc.sys
Device \Driver\usbuhci \Device\USBFDO-1 860091F8
Device \Driver\usbuhci \Device\USBFDO-2 860091F8
Device \Driver\usbehci \Device\USBFDO-3 860071F8
Device \Driver\usbuhci \Device\USBFDO-4 860091F8
Device \Driver\usbuhci \Device\USBFDO-5 860091F8
Device \Driver\usbuhci \Device\USBFDO-6 860091F8
Device \Driver\usbehci \Device\USBFDO-7 860071F8
Device \Driver\a18ijg9c \Device\Scsi\a18ijg9c1 8609B1F8
Device \Driver\a18ijg9c \Device\Scsi\a18ijg9c1Port5Path0Target0Lun0 8609B1F8
Device \FileSystem\fastfat \Fat 868741F8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestione filtri file system Microsoft/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

Device \FileSystem\cdfs \Cdfs 86D6A1F8

—- Services - GMER 1.0.15 —-

Service (*** hidden *** ) [MANUAL] mfeavfk01 <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 772
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations \??\C:\SensApi.dll??\??\C:\msimg32.dll??\??\C:\msimg32.dll??\??\C:\msimg32.dll??\??\C:\msimg32.dll??\??\C:\msimg32.dll??\??\C:\msimg32.dll??\??\C:\SensApi.dll??\??\C:\SensApi.dll??
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management@ExistingPageFiles \??\C:\pagefile.sys?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BootId 641
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 303177727
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@VideoInitTime 15
Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID e7810fe1-de11-408e-b390-6a99b3f
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog@FileCounter 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000ee7500064
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000ee7500064@d87533f93f3d 0x4C 0xAB 0xB2 0xF6 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\Ecache\Parameters@ReadyBootPlanUsage 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\Ecache\Parameters@LastBootStatus 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk01
Reg HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk01@AltServiceName mfeavfk
Reg HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk01@DisplayName McAfee Inc.
Reg HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk01@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk01@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk01@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk01@DeleteFlag 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\mfewfpk@LoadArg 00000000
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 1894
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x29 0x54 0x94 0x54 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x4B 0x64 0x03 0xD0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xAD 0xA8 0xF7 0x9C …
Reg HKLM\SYSTEM\CurrentControlSet\Services\SynTP\Parameters@DetectTimeMS 1299
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{401AB5F1-76EE-4C34-8495-845C9DB36442}@LeaseObtainedTime 1288761622
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{401AB5F1-76EE-4C34-8495-845C9DB36442}@T1 1288804822
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{401AB5F1-76EE-4C34-8495-845C9DB36442}@T2 1288837222
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{401AB5F1-76EE-4C34-8495-845C9DB36442}@LeaseTerminatesTime 1288848022
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@DhcpServer 192.168.0.1
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@Lease 86400
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@LeaseObtainedTime 1288732757
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@T1 1288775957
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@T2 1288808357
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@LeaseTerminatesTime 1288819157
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@DhcpIPAddress 192.168.0.4
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@DhcpNameServer 192.168.0.1
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@DhcpDefaultGateway 192.168.0.1?
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E32137B0-9136-4E14-A212-B582DD75950F}@DhcpSubnetMaskOpt 255.255.255.0?
Reg HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters@ServiceDllUnloadOnStop 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Last Counter 5108
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Last Help 5109
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Object List 4914 4920 4932 4942 4952 4972 5016 5026 5064 5070 5086 5094
Reg HKLM\SYSTEM\CurrentControlSet\Services\{401AB5F1-76EE-4C34-8495-845C9DB36442}\Parameters\Tcpip@LeaseObtainedTime 1288761622
Reg HKLM\SYSTEM\CurrentControlSet\Services\{401AB5F1-76EE-4C34-8495-845C9DB36442}\Parameters\Tcpip@T1 1288804822
Reg HKLM\SYSTEM\CurrentControlSet\Services\{401AB5F1-76EE-4C34-8495-845C9DB36442}\Parameters\Tcpip@T2 1288837222
Reg HKLM\SYSTEM\CurrentControlSet\Services\{401AB5F1-76EE-4C34-8495-845C9DB36442}\Parameters\Tcpip@LeaseTerminatesTime 1288848022
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@DhcpIPAddress 192.168.0.4
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@DhcpServer 192.168.0.1
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@Lease 86400
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@LeaseObtainedTime 1288732757
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@T1 1288775957
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@T2 1288808357
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@LeaseTerminatesTime 1288819157
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@DhcpDefaultGatewa 192.168.0.1?
Reg HKLM\SYSTEM\CurrentControlSet\Services\{E32137B0-9136-4E14-A212-B582DD75950F}\Parameters\Tcpip@DhcpSubnetMaskOpt 255.255.255.0?
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000ee7500064 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000ee7500064@d87533f93f3d 0x4C 0xAB 0xB2 0xF6 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x29 0x54 0x94 0x54 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x4B 0x64 0x03 0xD0 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xAD 0xA8 0xF7 0x9C …
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib@Last Counter 5108
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib@Last Help 5109
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1298227280-525688840-3569612356-1000@State 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1298227280-525688840-3569612356-1000@RefCount 0

—- Files - GMER 1.0.15 —-

File C:\Windows\temp\TMP19B.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMP1A42.tmp (size mismatch) 233536/0 bytes executable
File C:\Windows\temp\TMP21CA.tmp (size mismatch) 3939799/0 bytes executable
File C:\Windows\temp\TMP244D.tmp (size mismatch) 241728/0 bytes executable
File C:\Windows\temp\TMP2795.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMP2843.tmp (size mismatch) 239168/0 bytes executable
File C:\Windows\temp\TMP2B8F.tmp (size mismatch) 339520/0 bytes executable
File C:\Windows\temp\TMP2CFA.tmp (size mismatch) 325696/0 bytes executable
File C:\Windows\temp\TMP2DE6.tmp (size mismatch) 415664/0 bytes executable
File C:\Windows\temp\TMP2F7F.tmp (size mismatch) 830528/0 bytes executable
File C:\Windows\temp\TMP30.tmp (size mismatch) 172783/0 bytes executable
File C:\Windows\temp\TMP300C.tmp (size mismatch) 59456/0 bytes executable
File C:\Windows\temp\TMP3127.tmp (size mismatch) 208960/0 bytes executable
File C:\Windows\temp\TMP9DD6.tmp (size mismatch) 3260480/0 bytes executable
File C:\Windows\temp\TMPA19.tmp (size mismatch) 1048640/0 bytes executable
File C:\Windows\temp\TMPA2CC.tmp (size mismatch) 4875328/0 bytes executable
File C:\Windows\temp\TMPA309.tmp (size mismatch) 496624/0 bytes executable
File C:\Windows\temp\TMPA404.tmp (size mismatch) 401472/0 bytes executable
File C:\Windows\temp\TMPA434.tmp (size mismatch) 393280/0 bytes executable
File C:\Windows\temp\TMPA465.tmp (size mismatch) 397376/0 bytes executable
File C:\Windows\temp\TMPA497.tmp (size mismatch) 397376/0 bytes executable
File C:\Windows\temp\TMPA4C6.tmp (size mismatch) 335936/0 bytes executable
File C:\Windows\temp\TMPA4F7.tmp (size mismatch) 335936/0 bytes executable
File C:\Windows\temp\TMPA528.tmp (size mismatch) 397376/0 bytes executable
File C:\Windows\temp\TMPA569.tmp (size mismatch) 352320/0 bytes executable
File C:\Windows\temp\TMPA58B.tmp (size mismatch) 386032/0 bytes executable
File C:\Windows\temp\TMPA7CF.tmp (size mismatch) 472128/0 bytes executable
File C:\Windows\temp\TMPA7F5.tmp (size mismatch) 1048640/0 bytes executable
File C:\Windows\temp\TMPAA53.tmp (size mismatch) 2896240/0 bytes executable
File C:\Windows\temp\TMPAAF3.tmp (size mismatch) 2601024/0 bytes executable
File C:\Windows\temp\TMPB796.tmp (size mismatch) 496624/0 bytes executable
File C:\Windows\temp\TMPB7E5.tmp (size mismatch) 496624/0 bytes executable
File C:\Windows\temp\TMPB836.tmp (size mismatch) 496624/0 bytes executable
File C:\Windows\temp\TMPB8D3.tmp (size mismatch) 422896/0 bytes executable
File C:\Windows\temp\TMPB904.tmp (size mismatch) 422896/0 bytes executable
File C:\Windows\temp\TMPB935.tmp (size mismatch) 422896/0 bytes executable
File C:\Windows\temp\TMPB975.tmp (size mismatch) 386032/0 bytes executable
File C:\Windows\temp\TMPBB7A.tmp (size mismatch) 4991108/0 bytes executable
File C:\Windows\temp\TMPC2BC.tmp (size mismatch) 496624/0 bytes executable
File C:\Windows\temp\TMP5D54.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP5D85.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP5DC5.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP5E25.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP5E55.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP5E96.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP5EC7.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP5F26.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP5F57.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP5F97.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP5FD8.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP6009.tmp (size mismatch) 355904/0 bytes executable
File C:\Windows\temp\TMP6039.tmp (size mismatch) 355904/0 bytes executable
File C:\Windows\temp\TMP607A.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP60AB.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP60DB.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP611C.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP614D.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP618D.tmp (size mismatch) 406016/0 bytes executable
File C:\Windows\temp\TMP6468.tmp (size mismatch) 10283336/0 bytes executable
File C:\Windows\temp\TMP6642.tmp (size mismatch) 5520960/0 bytes executable
File C:\Windows\temp\TMP664D.tmp (size mismatch) 233536/0 bytes executable
File C:\Windows\temp\TMP66CC.tmp (size mismatch) 233536/0 bytes executable
File C:\Windows\temp\TMP69FC.tmp (size mismatch) 1273856/0 bytes executable
File C:\Windows\temp\TMP6C20.tmp (size mismatch) 8157973/0 bytes executable
File C:\Windows\temp\TMP7037.tmp (size mismatch) 496624/0 bytes executable
File C:\Windows\temp\TMP720D.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMP723E.tmp (size mismatch) 286784/0 bytes executable
File C:\Windows\temp\TMP726F.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMP7290.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMP72C1.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMP72F1.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMP7322.tmp (size mismatch) 335936/0 bytes executable
File C:\Windows\temp\TMP7353.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMP7384.tmp (size mismatch) 323648/0 bytes executable
File C:\Windows\temp\TMP73B5.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMP7424.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMP7455.tmp (size mismatch) 323648/0 bytes executable
File C:\Windows\temp\TMP7485.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMP74B6.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMP7518.tmp (size mismatch) 266304/0 bytes executable
File C:\Windows\temp\TMP7539.tmp (size mismatch) 270400/0 bytes executable
File C:\Windows\temp\TMP755A.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMP758B.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMP75BC.tmp (size mismatch) 282688/0 bytes executable
File C:\Windows\temp\TMP75ED.tmp (size mismatch) 422896/0 bytes executable
File C:\Windows\temp\TMP76E8.tmp (size mismatch) 1048640/0 bytes executable
File C:\Windows\temp\TMP7861.tmp (size mismatch) 2408512/0 bytes executable
File C:\Windows\temp\TMP7B6C.tmp (size mismatch) 542208/0 bytes executable
File C:\Windows\temp\TMP7BED.tmp (size mismatch) 1048640/0 bytes executable
File C:\Windows\temp\TMP7C76.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP7CB6.tmp (size mismatch) 376384/0 bytes executable
File C:\Windows\temp\TMP7CE7.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP7D37.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP7D77.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP7DA8.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP7DE9.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP7E19.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP7E8B.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP7EBB.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP7F0B.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP7F4C.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP7F7D.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP7FCD.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP7FFD.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP802E.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP806F.tmp (size mismatch) 355904/0 bytes executable
File C:\Windows\temp\TMP809F.tmp (size mismatch) 355904/0 bytes executable
File C:\Windows\temp\TMP80EF.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP8130.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP8161.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP81A1.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP81D2.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP8212.tmp (size mismatch) 406016/0 bytes executable
File C:\Windows\temp\TMP836B.tmp (size mismatch) 1626008/0 bytes executable
File C:\Windows\temp\TMP865A.tmp (size mismatch) 8169863/0 bytes executable
File C:\Windows\temp\TMP8A05.tmp (size mismatch) 587537/0 bytes executable
File C:\Windows\temp\TMP31E4.tmp (size mismatch) 59456/0 bytes executable
File C:\Windows\temp\TMP5D13.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP62F6.tmp (size mismatch) 1626016/0 bytes executable
File C:\Windows\temp\TMP74E7.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMP7E4A.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP8CF.tmp (size mismatch) 3006528/0 bytes executable
File C:\Windows\temp\TMP9AC7.tmp (size mismatch) 1048640/0 bytes executable
File C:\Windows\temp\TMPC8FC.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMP8F51.tmp (size mismatch) 542208/0 bytes executable
File C:\Windows\temp\TMP8FF2.tmp (size mismatch) 82496/0 bytes executable
File C:\Windows\temp\TMP908B.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP90BC.tmp (size mismatch) 376384/0 bytes executable
File C:\Windows\temp\TMP90ED.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP912D.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP915E.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP918F.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP91D0.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP9200.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP9241.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP9272.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP92B2.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP92E3.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP9314.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP9354.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP9385.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP93C5.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP93F6.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP9436.tmp (size mismatch) 355904/0 bytes executable
File C:\Windows\temp\TMP9467.tmp (size mismatch) 355904/0 bytes executable
File C:\Windows\temp\TMP9482.tmp (size mismatch) 172783/0 bytes executable
File C:\Windows\temp\TMP9498.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP94D8.tmp (size mismatch) 405056/0 bytes executable
File C:\Windows\temp\TMP9509.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP9539.tmp (size mismatch) 2494528/0 bytes executable
File C:\Windows\temp\TMP954A.tmp (size mismatch) 417344/0 bytes executable
File C:\Windows\temp\TMP957A.tmp (size mismatch) 413248/0 bytes executable
File C:\Windows\temp\TMP95AB.tmp (size mismatch) 406016/0 bytes executable
File C:\Windows\temp\TMP980E.tmp (size mismatch) 1626016/0 bytes executable
File C:\Windows\temp\TMPC56D.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMPC59E.tmp (size mismatch) 286784/0 bytes executable
File C:\Windows\temp\TMPC5BF.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMPC5F0.tmp (size mismatch) 323648/0 bytes executable
File C:\Windows\temp\TMPC620.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPC661.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPC692.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMPC6C2.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPC6F3.tmp (size mismatch) 335936/0 bytes executable
File C:\Windows\temp\TMPC724.tmp (size mismatch) 335936/0 bytes executable
File C:\Windows\temp\TMPC755.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMPC786.tmp (size mismatch) 323648/0 bytes executable
File C:\Windows\temp\TMPC7B6.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMPC7E7.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPC818.tmp (size mismatch) 323648/0 bytes executable
File C:\Windows\temp\TMPC839.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMPC86A.tmp (size mismatch) 331840/0 bytes executable
File C:\Windows\temp\TMPC89B.tmp (size mismatch) 323648/0 bytes executable
File C:\Windows\temp\TMPC8CC.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPC92D.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPC95E.tmp (size mismatch) 266304/0 bytes executable
File C:\Windows\temp\TMPC99E.tmp (size mismatch) 270400/0 bytes executable
File C:\Windows\temp\TMPC9C0.tmp (size mismatch) 315456/0 bytes executable
File C:\Windows\temp\TMPC9F0.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPCA21.tmp (size mismatch) 323648/0 bytes executable
File C:\Windows\temp\TMPCA52.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPCA83.tmp (size mismatch) 282688/0 bytes executable
File C:\Windows\temp\TMPCAA4.tmp (size mismatch) 319552/0 bytes executable
File C:\Windows\temp\TMPCAD5.tmp (size mismatch) 323648/0 bytes executable
File C:\Windows\temp\TMPCB06.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMPCB36.tmp (size mismatch) 422896/0 bytes executable
File C:\Windows\temp\TMPCE74.tmp (size mismatch) 496624/0 bytes executable
File C:\Windows\temp\TMPCEB4.tmp (size mismatch) 327744/0 bytes executable
File C:\Windows\temp\TMPCF61.tmp (size mismatch) 1340758/0 bytes executable
File C:\Windows\temp\TMPD07A.tmp (size mismatch) 1365056/0 bytes executable
File C:\Windows\temp\TMPD124.tmp (size mismatch) 1116904/0 bytes executable
File C:\Windows\temp\TMPD27F.tmp (size mismatch) 1345912/0 bytes executable
File C:\Windows\temp\TMPD36.tmp (size mismatch) 2224192/0 bytes executable
File C:\Windows\temp\TMPD4A5.tmp (size mismatch) 429632/0 bytes executable
File C:\Windows\temp\TMPD53D.tmp (size mismatch) 225344/0 bytes executable
File C:\Windows\temp\TMPD542.tmp (size mismatch) 163392/0 bytes executable
File C:\Windows\temp\TMPD664.tmp (size mismatch) 233536/0 bytes executable
File C:\Windows\temp\TMPD78E.tmp (size mismatch) 2547492/0 bytes executable
File C:\Windows\temp\TMPD851.tmp (size mismatch) 387136/0 bytes executable
File C:\Windows\temp\TMPD8DF.tmp (size mismatch) 544320/0 bytes executable
File C:\Windows\temp\TMPDA39.tmp (size mismatch) 1398336/0 bytes executable
File C:\Windows\temp\TMPDCE8.tmp (size mismatch) 568896/0 bytes executable
File C:\Windows\temp\TMPDF9B.tmp (size mismatch) 2008568/0 bytes executable
File C:\Windows\temp\TMPE998.tmp (size mismatch) 1308736/0 bytes executable
File C:\Windows\temp\TMPF40A.tmp (size mismatch) 225344/0 bytes executable
File C:\Windows\temp\TMPF572.tmp (size mismatch) 172783/0 bytes executable
File C:\Windows\temp\TMPFC9D.tmp (size mismatch) 172783/0 bytes executable
File C:\Windows\temp\TMPFD5A.tmp (size mismatch) 229440/0 bytes executable
File C:\Windows\temp\TMPFE6C.tmp (size mismatch) 1110080/0 bytes executable
File C:\Windows\temp\TMPFED7.tmp (size mismatch) 225344/0 bytes executable
File C:\Windows\temp\TMP32B1.tmp (size mismatch) 58944/0 bytes executable
File C:\Windows\temp\TMP334F.tmp (size mismatch) 59456/0 bytes executable
File C:\Windows\temp\TMP340.tmp (size mismatch) 2135368/0 bytes executable
File C:\Windows\temp\TMP340C.tmp (size mismatch) 180288/0 bytes executable
File C:\Windows\temp\TMP3537.tmp (size mismatch) 830528/0 bytes executable
File C:\Windows\temp\TMP36ED.tmp (size mismatch) 65894/0 bytes executable
File C:\Windows\temp\TMP3790.tmp (size mismatch) 241728/0 bytes executable
File C:\Windows\temp\TMP3EE3.tmp (size mismatch) 2543680/0 bytes executable
File C:\Windows\temp\TMP3FFD.tmp (size mismatch) 1048640/0 bytes executable
File C:\Windows\temp\TMP4885.tmp (size mismatch) 1302592/0 bytes executable
File C:\Windows\temp\TMP4E99.tmp (size mismatch) 172783/0 bytes executable
File C:\Windows\temp\TMP563.tmp (size mismatch) 1048640/0 bytes executable
File C:\Windows\temp\TMP576A.tmp (size mismatch) 1273856/0 bytes executable
File C:\Windows\temp\TMP5949.tmp (size mismatch) 1855552/0 bytes executable
File C:\Windows\temp\TMP5AC6.tmp (size mismatch) 542208/0 bytes executable
File C:\Windows\temp\TMP5B3F.tmp (size mismatch) 1620512/0 bytes executable
File C:\Windows\temp\TMP5C00.tmp (size mismatch) 421440/0 bytes executable
File C:\Windows\temp\TMP5C31.tmp (size mismatch) 376384/0 bytes executable
File C:\Windows\temp\TMP5C71.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP5CA2.tmp (size mismatch) 409152/0 bytes executable
File C:\Windows\temp\TMP5CE3.tmp (size mismatch) 417344/0 bytes executable

—- EOF - GMER 1.0.15 —-
Hello marcopcnn

It would be really useful to see the mbr report.

If you are sure the log is short enough for you to type it in please do so (thanks) :)
Hello marcopcnn

Actually, you don't need to type in the message at all, you can copy/paste it here directly:

Click on the tiny c:\ in the top left hand corner of the window:

[external image: Posted Image]

The select Edit > Mark All

The text should be highlighted in white.

Next, click on c:\ again and select Edit > Copy

Open Notepad and select Paste

You should now have the log in Notepad, which you can paste in your next reply :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI