marcopcnn
Here the OTL scan results
The setting are the same used in the first scan
One more info. I have removed my McAfee antivirus because it cause continuous mulfuction aftar any restart. (System very slow and frequent stop)
OTL logfile created on: 07/11/2010 14.57.34 - Run 2
OTL by OldTimer - Version 3.2.17.2 Folder = C:\Users\marco\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 87,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 94,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 228,01 Gb Total Space | 54,27 Gb Free Space | 23,80% Space Free | Partition Type: NTFS
Drive D: | 227,98 Gb Total Space | 69,41 Gb Free Space | 30,45% Space Free | Partition Type: NTFS
Drive F: | 7,45 Gb Total Space | 0,68 Gb Free Space | 9,12% Space Free | Partition Type: FAT32
Computer Name: PC-MARCO | User Name: marco | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
PRC - [2009/04/11 07.27.36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
MOD - [2010/08/31 16.43.52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - File not found [Unknown | Stopped] – C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe – (McShield)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2010/09/29 15.00.56 | 001,145,304 | —- | M] (PC Tools) [Auto | Stopped] – C:\Program Files\PC Tools Security\pctsSvc.exe – (sdCoreService)
SRV - [2010/09/24 11.19.06 | 000,235,472 | —- | M] (Threat Expert Ltd.) [Auto | Stopped] – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2010/08/26 11.39.46 | 000,070,928 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files\PC Tools Security\TFEngine\TFService.exe – (ThreatFire)
SRV - [2010/08/24 14.57.38 | 000,141,792 | —- | M] (McAfee, Inc.) [Unknown | Stopped] – C:\Windows\System32\mfevtps.exe – (mfevtp)
SRV - [2010/08/24 10.38.18 | 000,092,008 | —- | M] (TomTom) [Auto | Stopped] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2010/06/14 14.07.14 | 000,615,936 | —- | M] (Nokia) [On_Demand | Stopped] – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer)
SRV - [2010/04/01 13.53.28 | 000,135,288 | —- | M] (PGP Corporation) [Auto | Stopped] – C:\Windows\System32\PGPserv.exe – (PGPserv)
SRV - [2010/03/15 13.02.36 | 000,366,840 | —- | M] (PC Tools) [Auto | Stopped] – C:\Program Files\PC Tools Security\pctsAuxs.exe – (sdAuxService)
SRV - [2009/09/25 02.27.04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009/04/21 10.48.16 | 000,425,988 | —- | M] () [Auto | Stopped] – C:\Program Files\NCH Software\Eyeline\eyeline.exe – (EyelineService)
SRV - [2009/04/21 10.47.27 | 000,368,644 | —- | M] () [Auto | Stopped] – C:\Program Files\NCH Software\BroadCam\broadCam.exe – (BroadCamService)
SRV - [2009/01/26 14.31.10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Stopped] – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/05/14 17.05.30 | 000,500,784 | —- | M] (Egis Incorporated) [Auto | Stopped] – C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe – (eDataSecurity Service)
SRV - [2008/04/06 21.42.24 | 000,050,424 | —- | M] (NewTech InfoSystems, Inc.) [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe – (NTIBackupSvc)
SRV - [2008/04/04 02.03.14 | 000,131,072 | —- | M] () [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe – (NTISchedulerSvc)
SRV - [2008/03/21 12.22.52 | 000,024,576 | —- | M] () [Auto | Stopped] – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe – (ETService)
SRV - [2008/03/18 20.27.12 | 000,013,312 | —- | M] (Agere Systems) [Auto | Stopped] – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio)
SRV - [2008/03/03 12.11.14 | 000,016,384 | —- | M] (NewTech Infosystems, Inc.) [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe – (BUNAgentSvc)
SRV - [2008/01/21 03.23.32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2008/01/16 17.35.02 | 000,081,504 | —- | M] () [Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe – (CLHNService)
SRV - [2007/12/06 16.15.28 | 000,110,592 | —- | M] () [Disabled | Stopped] – C:\Acer\Mobility Center\MobilityService.exe – (MobilityService)
SRV - [2007/11/06 21.22.26 | 000,092,792 | —- | M] (CACE Technologies) [On_Demand | Stopped] – C:\Program Files\WinPcap\rpcapd.exe – (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | System | Stopped] – C:\Windows\System32\drivers\mfewfpk.sys – (mfewfpk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mferkdet.sys – (mferkdet)
DRV - File not found [Kernel | System | Stopped] – C:\Windows\System32\DRIVERS\mfenlfk.sys – (mfenlfk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfefirek.sys – (mfefirek)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\cfwids.sys – (cfwids)
DRV - [2010/10/05 10.10.56 | 000,249,616 | —- | M] (PC Tools) [Kernel | System | Stopped] – C:\Windows\System32\drivers\pctgntdi.sys – (pctgntdi)
DRV - [2010/08/27 08.26.40 | 000,070,536 | —- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\pctplsg.sys – (pctplsg)
DRV - [2010/08/26 11.39.46 | 000,068,880 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\TfSysMon.sys – (TfSysMon)
DRV - [2010/08/26 11.39.46 | 000,051,984 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\TfFsMon.sys – (TfFsMon)
DRV - [2010/08/26 11.39.46 | 000,033,552 | –S- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TfNetMon.sys – (TfNetMon)
DRV - [2010/08/24 14.57.38 | 000,386,712 | —- | M] (McAfee, Inc.) [Kernel | Boot | Stopped] – C:\Windows\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2010/08/24 14.57.38 | 000,095,600 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2010/08/18 12.51.26 | 000,237,632 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2010/07/16 13.59.54 | 000,656,320 | —- | M] (PC Tools) [File_System | Boot | Running] – C:\Windows\system32\drivers\pctEFA.sys – (pctEFA)
DRV - [2010/07/16 13.59.54 | 000,338,880 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\pctDS.sys – (pctDS)
DRV - [2010/04/01 13.53.28 | 000,266,360 | —- | M] (PGP Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\PGPwded.sys – (PGPwded)
DRV - [2010/04/01 13.53.28 | 000,243,832 | —- | M] (PGP Corporation) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PGPdisk.sys – (PGPdisk)
DRV - [2010/04/01 13.53.28 | 000,040,568 | —- | M] (PGP Corporation) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PGPsdk.sys – (PGPsdkDriver)
DRV - [2010/04/01 13.53.26 | 000,136,312 | —- | M] (PGP Corporation) [File_System | Boot | Running] – C:\Windows\System32\Drivers\PGPfsfd.sys – (pgpfs)
DRV - [2010/04/01 13.53.26 | 000,013,432 | —- | M] (PGP Corporation) [File_System | Boot | Running] – C:\Windows\system32\DRIVERS\Pgpwdefs.sys – (Pgpwdefs)
DRV - [2010/02/05 04.16.10 | 000,028,048 | —- | M] (CSR, plc) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BthAvrcp.sys – (BthAvrcp)
DRV - [2009/09/30 06.53.12 | 001,184,768 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2009/08/15 15.09.58 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2008/08/26 09.26.12 | 000,018,816 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\pccsmcfd.sys – (pccsmcfd)
DRV - [2008/08/12 13.33.38 | 000,061,440 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\RTSTOR.sys – (RTSTOR)
DRV - [2008/07/11 19.20.10 | 002,381,312 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\igdkmd32.sys – (igfx)
DRV - [2008/06/14 02.10.08 | 002,152,344 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/05/14 17.05.44 | 000,060,464 | —- | M] (Egis Incorporated) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PSDVdisk.sys – (psdvdisk)
DRV - [2008/05/14 17.05.42 | 000,018,992 | —- | M] (Egis Incorporated) [File_System | Boot | Running] – C:\Windows\system32\DRIVERS\psdfilter.sys – (PSDFilter)
DRV - [2008/05/14 17.05.42 | 000,016,944 | —- | M] (Egis Incorporated) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PSDNServ.sys – (PSDNServ)
DRV - [2008/04/25 19.08.42 | 000,199,472 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2008/04/18 14.01.24 | 000,061,424 | —- | M] (Cyberlink Corp.) [Kernel | Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl – ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796})
DRV - [2008/03/21 09.48.24 | 000,015,392 | —- | M] (Acer, Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\int15.sys – (int15)
DRV - [2008/03/01 00.13.38 | 001,202,560 | —- | M] (Agere Systems) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2008/02/21 10.55.00 | 000,299,008 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\yk60x86.sys – (yukonwlh)
DRV - [2008/02/18 15.55.20 | 000,101,376 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ewusbmdm.sys – (hwdatacard)
DRV - [2008/01/31 02.52.06 | 000,014,848 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\NTIDrvr.sys – (NTIDrvr)
DRV - [2008/01/31 02.51.50 | 000,013,824 | —- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\UBHelper.sys – (UBHelper)
DRV - [2008/01/21 03.23.27 | 000,386,616 | —- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasr.sys – (MegaSR)
DRV - [2008/01/21 03.23.27 | 000,149,560 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2008/01/21 03.23.27 | 000,031,288 | —- | M] (LSI Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2008/01/21 03.23.26 | 000,101,432 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2008/01/21 03.23.26 | 000,074,808 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2008/01/21 03.23.26 | 000,040,504 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2008/01/21 03.23.25 | 000,300,600 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2008/01/21 03.23.25 | 000,089,656 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2008/01/21 03.23.24 | 001,122,360 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2008/01/21 03.23.24 | 000,118,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2008/01/21 03.23.24 | 000,079,928 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2008/01/21 03.23.23 | 000,654,336 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTCNXT3.SYS – (winachsf)
DRV - [2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2008/01/21 03.23.23 | 000,130,616 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2008/01/21 03.23.23 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2008/01/21 03.23.23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2008/01/21 03.23.23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2008/01/21 03.23.23 | 000,079,416 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2008/01/21 03.23.23 | 000,030,720 | —- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nscirda.sys – (NSCIRDA)
DRV - [2008/01/21 03.23.22 | 000,987,648 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTDPV3.SYS – (HSF_DPV)
DRV - [2008/01/21 03.23.22 | 000,342,584 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2008/01/21 03.23.22 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2008/01/21 03.23.21 | 000,422,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2008/01/21 03.23.21 | 000,102,968 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2008/01/21 03.23.20 | 000,238,648 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2008/01/21 03.23.20 | 000,179,712 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\b57nd60x.sys – (b57nd60x)
DRV - [2008/01/21 03.23.00 | 000,020,024 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2008/01/21 03.23.00 | 000,019,000 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2008/01/21 03.23.00 | 000,017,464 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2008/01/16 17.35.08 | 000,122,368 | —- | M] (Cyberlink Corp.) [Kernel | Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys – (NTIPPKernel)
DRV - [2007/11/06 21.22.06 | 000,034,064 | —- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\npf.sys – (NPF)
DRV - [2007/03/08 09.53.44 | 000,099,584 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZTEusbser.sys – (qcusbser)
DRV - [2006/11/03 06.29.36 | 000,021,264 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\DKbFltr.sys – (DKbFltr)
DRV - [2006/11/02 10.50.35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 10.50.35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 10.50.19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 10.50.17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 10.50.11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 10.50.09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 10.50.07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 10.50.05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 10.50.03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 10.49.59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 10.49.56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 09.25.24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 09.24.47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 09.24.46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 09.24.45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 09.24.44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 09.24.44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 08.36.50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2004/01/26 16.36.35 | 000,095,552 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\Windows\System32\drivers\prohlp02.sys – (prohlp02)
DRV - [2004/01/26 16.01.28 | 000,052,224 | —- | M] (Protection Technology) [Kernel | System | Stopped] – C:\Windows\System32\drivers\prodrv06.sys – (prodrv06)
DRV - [2003/12/01 16.20.52 | 000,004,832 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\Windows\System32\drivers\sfhlp01.sys – (sfhlp01)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "NCH Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2117678&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.startup.homepage: "http://homepage.acer.com/rdr.aspx?b=ACAW&l;=0410&s;=2&o;=vp32&d;=1208&m;=aspire_5735"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}:5.0.16
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.732
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.50
FF - prefs.js..network.proxy.http: "192.168.0.1"
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/16 21.39.47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2010/10/29 05.30.59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/31 07.03.23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 05.09.56 | 000,000,000 | —D | M]
[2009/12/24 07.44.43 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Extensions
[2009/12/24 07.44.43 | 000,000,000 | —D | M] (No name found) – C:\Users\marco\AppData\Roaming\mozilla\Extensions\{2f1e6a90-e99e-11dd-ba2f-0800200c9a66}
[2009/04/18 08.35.01 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Extensions\[removed]
[2010/11/06 16.30.02 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions
[2010/10/16 04.46.40 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/11/04 18.55.55 | 000,000,000 | —D | M] (No name found) – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2009/04/21 10.48.03 | 000,000,868 | —- | M] () – C:\Users\marco\AppData\Roaming\Mozilla\FireFox\Profiles\pttb29kf.default\searchplugins\conduit.xml
[2009/08/15 15.32.53 | 000,002,395 | —- | M] () – C:\Users\marco\AppData\Roaming\Mozilla\FireFox\Profiles\pttb29kf.default\searchplugins\daemon-search.xml
[2010/11/06 16.30.02 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/03 01.52.16 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/04/05 08.57.45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}
[2006/06/16 10.16.04 | 000,205,312 | —- | M] (NETDIMENSION CORPORATION) – C:\Program Files\Mozilla Firefox\plugins\NPMXENG.DLL
[2009/08/21 22.20.57 | 000,001,412 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\demauro.xml
[2010/03/14 07.10.28 | 000,000,744 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-it.xml
[2010/03/14 07.10.28 | 000,000,825 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\hoepli.xml
[2010/03/14 07.10.28 | 000,001,182 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-it.xml
[2010/03/14 07.10.28 | 000,000,953 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-it.xml
O1 HOSTS File: ([2006/09/18 22.41.32 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101031070323.dll File not found
O2 - BHO: (DownloadStudio IE Add-on) - {8170D7DC-BDD6-461e-88EB-F047257898C9} - C:\Program Files\Conceiva\DownloadStudio\DLMonitr.dll (Conceiva Pty Ltd)
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (no name) - {B99F805C-F0B1-48EA-8C8B-753BFCBED913} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DetectDatacard] C:\Program Files\AliceEntry\DetectDatacard.exe (ONDA)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe File not found
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [ProductReg] C:\Program Files\Acer\WR_PopUp\ProductReg.exe (Acer)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Inserisci &blog; in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: carige.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: directline.it ([www] * in Siti attendibili)
O15 - HKCU\..Trusted Domains: fineco.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: internet ([]about in Siti attendibili)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Siti attendibili)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Siti attendibili)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Siti attendibili)
O15 - HKCU\..Trusted Domains: tim.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: vxsbill.com ([secure] https in Siti attendibili)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Siti attendibili)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…144/mcfscan.cab (McFreeScan Class)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\Windows\system32\hzofypl.dll) - C:\Windows\System32\hzofypl.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Acer01.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22.43.36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/10/26 08.21.46 | 000,000,219 | —- | M] () - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/11/06 18.51.55 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/11/06 18.51.55 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Local\temp
[2010/11/06 18.25.08 | 000,000,000 | –SD | C] – C:\ComboFix
[2010/11/06 18.24.46 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/11/06 16.01.12 | 000,000,000 | —D | C] – C:\Windows\pss
[2010/11/06 15.43.09 | 000,000,000 | —D | C] – C:\Windows\panther
[2010/11/06 06.58.06 | 000,101,376 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbmdm.sys
[2010/11/06 06.58.06 | 000,100,864 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbnet.sys
[2010/11/06 06.58.06 | 000,023,424 | —- | C] (Huawei Tech. Co., Ltd.) – C:\Windows\System32\drivers\ewdcsc.sys
[2010/11/06 06.37.24 | 000,000,000 | —D | C] – C:\Windows\LastGood.Tmp
[2010/11/05 06.03.17 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/11/05 06.03.17 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/11/05 06.03.17 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/11/05 06.03.09 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/11/05 06.02.44 | 000,000,000 | —D | C] – C:\Qoobox
[2010/11/05 05.50.00 | 000,000,000 | —D | C] – C:\ProgramData\moosoft
[2010/11/04 23.15.18 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2010/11/04 23.15.12 | 000,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2010/11/04 22.53.01 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\thecleaner
[2010/11/04 22.52.47 | 000,000,000 | —D | C] – C:\Program Files\The Cleaner
[2010/11/04 22.31.58 | 000,000,000 | —D | C] – C:\Users\marco\Documents\Usenet.nl
[2010/11/04 22.31.58 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\Usenet.nl
[2010/11/04 22.31.49 | 000,000,000 | —D | C] – C:\Program Files\Usenet.nl
[2010/11/04 22.31.24 | 036,946,400 | —- | C] (MooSoft Development LLC ) – C:\Users\marco\Desktop\cleaner7_setup.exe
[2010/11/04 22.27.20 | 003,023,984 | —- | C] ( ) – C:\Users\marco\Desktop\UsenetNLSetup_422135f.exe
[2010/11/04 19.20.11 | 001,913,056 | —- | C] (Trend Micro Inc.) – C:\Users\marco\Desktop\HousecallLauncher.exe
[2010/11/04 18.56.03 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\QuickScan
[2010/11/04 06.26.55 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2010/11/03 06.05.56 | 001,317,464 | —- | C] (Kaspersky Lab ZAO) – C:\Users\marco\Desktop\TDSSKiller.exe
[2010/11/01 07.04.13 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
[2010/10/31 22.06.11 | 004,813,736 | —- | C] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\systemtweaker.exe
[2010/10/31 21.40.27 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\Uniblue
[2010/10/31 21.40.19 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2010/10/31 16.10.03 | 005,273,528 | —- | C] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\registrybooster.exe
[2010/10/31 09.01.56 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Local\Threat Expert
[2010/10/31 07.02.14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2010/10/31 07.02.00 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2010/10/29 05.32.05 | 000,068,880 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
[2010/10/29 05.32.05 | 000,051,984 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2010/10/29 05.32.05 | 000,033,552 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2010/10/29 05.30.56 | 001,914,832 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2010/10/29 05.30.56 | 000,743,376 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2010/10/29 05.30.56 | 000,149,456 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2010/10/28 22.23.38 | 000,656,320 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctEFA.sys
[2010/10/28 22.23.38 | 000,338,880 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctDS.sys
[2010/10/28 22.23.31 | 000,249,616 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2010/10/28 22.23.30 | 000,102,184 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/10/28 22.23.11 | 000,237,632 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2010/10/28 22.23.11 | 000,159,936 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/10/28 22.22.30 | 000,123,712 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2010/10/28 22.22.30 | 000,087,400 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2010/10/28 22.22.30 | 000,031,960 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2010/10/28 22.22.24 | 000,070,536 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\PC Tools
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.c698.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.a323.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.710c.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.3318.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe
[2010/10/28 22.02.12 | 003,136,440 | —- | C] (McAfee, Inc.) – C:\Users\marco\Desktop\DMSetup.exe
[2010/10/28 21.25.55 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2010/10/28 21.07.41 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/10/28 21.07.41 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/10/24 14.45.27 | 000,000,000 | —D | C] – C:\Users\marco\Desktop\backups
[2010/10/24 14.27.32 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\marco\Desktop\HiJackThis.exe
[2010/10/23 07.42.43 | 000,000,000 | —D | C] – C:\Windows\McAfee.com
[2010/10/19 23.23.59 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\AnVi
[2008/12/04 19.14.24 | 000,049,152 | —- | C] ( ) – C:\Windows\Interop.IWshRuntimeLibrary.dll
[4 C:\Users\marco\Documents\*.tmp files -> C:\Users\marco\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\marco\*.tmp files -> C:\Users\marco\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/07 09.41.56 | 000,006,648 | —- | M] () – C:\Users\marco\AppData\Local\d3d9caps.dat
[2010/11/07 09.38.17 | 000,661,860 | —- | M] () – C:\Windows\System32\perfh010.dat
[2010/11/07 09.38.17 | 000,586,568 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/07 09.38.17 | 000,119,742 | —- | M] () – C:\Windows\System32\perfc010.dat
[2010/11/07 09.38.17 | 000,100,640 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/07 09.34.01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/07 09.33.50 | 268,435,456 | -HS- | M] () – C:\Windows\System32\temppf.sys
[2010/11/06 18.21.52 | 003,903,895 | R— | M] () – C:\Users\marco\Desktop\ComboFix.exe
[2010/11/06 17.00.19 | 000,001,132 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/06 17.00.17 | 000,000,332 | —- | M] () – C:\Windows\tasks\RegistryBooster.job
[2010/11/06 15.44.27 | 000,002,562 | —- | M] () – C:\Windows\diagwrn.xml
[2010/11/06 15.44.27 | 000,001,908 | —- | M] () – C:\Windows\diagerr.xml
[2010/11/06 15.43.51 | 000,002,354 | —- | M] () – C:\Users\marco\Desktop\Windows_Rapporto compatibilità.htm
[2010/11/06 13.39.00 | 000,000,442 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{75E1966D-AD9F-42D4-A7B8-0965F1B2B3CC}.job
[2010/11/06 13.38.49 | 000,009,216 | —- | M] () – C:\Windows\System32\umstartup.etl
[2010/11/06 06.58.15 | 000,000,876 | —- | M] () – C:\Users\Public\Desktop\Alice MOBILE E169.lnk
[2010/11/05 21.15.49 | 000,088,576 | —- | M] () – C:\Windows\MBR.exe
[2010/11/04 23.15.00 | 001,709,408 | —- | M] () – C:\Users\marco\Desktop\taskmanager17.exe
[2010/11/04 22.52.55 | 000,000,771 | —- | M] () – C:\Users\Public\Desktop\The Cleaner 2011.lnk
[2010/11/04 22.52.23 | 036,946,400 | —- | M] (MooSoft Development LLC ) – C:\Users\marco\Desktop\cleaner7_setup.exe
[2010/11/04 22.31.49 | 000,001,678 | —- | M] () – C:\Users\marco\Desktop\Usenet.nl.lnk
[2010/11/04 22.28.46 | 003,023,984 | —- | M] ( ) – C:\Users\marco\Desktop\UsenetNLSetup_422135f.exe
[2010/11/04 21.27.54 | 002,100,028 | —- | M] () – C:\Windows\System32\drivers\Cat.DB
[2010/11/04 19.20.23 | 001,913,056 | —- | M] (Trend Micro Inc.) – C:\Users\marco\Desktop\HousecallLauncher.exe
[2010/11/04 18.53.35 | 001,080,832 | —- | M] () – C:\Users\marco\Desktop\msxml3.msi
[2010/11/04 18.49.00 | 003,136,440 | —- | M] (McAfee, Inc.) – C:\Users\marco\Desktop\DMSetup.exe
[2010/11/04 06.59.07 | 000,000,092 | —- | M] () – C:\Users\marco\Desktop\fig.reg
[2010/11/03 22.04.56 | 000,021,504 | —- | M] () – C:\Windows\System32\umstartup000.etl
[2010/11/03 06.31.02 | 000,001,136 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/03 06.22.42 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 06.22.42 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 06.22.38 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/11/03 05.55.19 | 001,207,026 | —- | M] () – C:\Users\marco\Desktop\tdsskiller.zip
[2010/11/01 21.06.11 | 289,248,269 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/11/01 18.51.42 | 000,000,474 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for marco.job
[2010/11/01 07.21.44 | 000,286,404 | —- | M] () – C:\Users\marco\Desktop\gmer.zip
[2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
[2010/10/31 22.08.48 | 000,000,919 | —- | M] () – C:\Users\Public\Desktop\SystemTweaker.lnk
[2010/10/31 22.07.58 | 004,813,736 | —- | M] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\systemtweaker.exe
[2010/10/31 21.40.23 | 000,000,929 | —- | M] () – C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/10/31 16.10.55 | 005,273,528 | —- | M] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\registrybooster.exe
[2010/10/31 15.34.06 | 000,164,352 | —- | M] () – C:\Users\marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/31 09.01.19 | 000,689,664 | —- | M] () – C:\Users\marco\Desktop\MicrosoftFixit50202.msi
[2010/10/30 17.29.00 | 003,059,712 | —- | M] () – C:\Users\marco\Desktop\mvt_it.msi
[2010/10/28 22.22.53 | 000,001,824 | —- | M] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/10/28 21.37.02 | 001,373,616 | —- | M] () – C:\Users\marco\Desktop\MCPR.exe
[2010/10/28 21.25.14 | 000,507,360 | —- | M] () – C:\Users\marco\Desktop\sdsetup.exe
[2010/10/28 21.08.00 | 000,001,095 | —- | M] () – C:\Users\marco\Desktop\Spybot - Search & Destroy.lnk
[2010/10/28 05.20.24 | 000,000,036 | —- | M] () – C:\Users\marco\AppData\Local\housecall.guid.cache
[2010/10/26 11.30.08 | 001,317,464 | —- | M] (Kaspersky Lab ZAO) – C:\Users\marco\Desktop\TDSSKiller.exe
[2010/10/24 14.27.51 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\marco\Desktop\HiJackThis.exe
[2010/10/19 20.47.59 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2010/10/19 16.00.08 | 000,294,912 | —- | M] () – C:\Users\marco\Desktop\gmer.exe
[2010/10/17 15.01.54 | 000,024,064 | —- | M] () – C:\Users\marco\Documents\It is not possible to select your own login for this site.doc
[2010/10/17 14.16.55 | 000,075,731 | —- | M] () – C:\Users\marco\Documents\540335p.pdf
[2010/10/14 20.50.21 | 000,304,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/12 21.24.49 | 000,001,927 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[4 C:\Users\marco\Documents\*.tmp files -> C:\Users\marco\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\marco\*.tmp files -> C:\Users\marco\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/06 18.24.40 | 003,903,895 | R— | C] () – C:\Users\marco\Desktop\ComboFix.exe
[2010/11/06 13.13.44 | 000,002,354 | —- | C] () – C:\Users\marco\Desktop\Windows_Rapporto compatibilità.htm
[2010/11/06 13.12.22 | 000,002,562 | —- | C] () – C:\Windows\diagwrn.xml
[2010/11/06 13.12.22 | 000,001,908 | —- | C] () – C:\Windows\diagerr.xml
[2010/11/06 06.58.15 | 000,000,876 | —- | C] () – C:\Users\Public\Desktop\Alice MOBILE E169.lnk
[2010/11/05 06.03.17 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/11/05 06.03.17 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/11/05 06.03.17 | 000,088,576 | —- | C] () – C:\Windows\MBR.exe
[2010/11/05 06.03.17 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/11/05 06.03.17 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/11/04 23.14.48 | 001,709,408 | —- | C] () – C:\Users\marco\Desktop\taskmanager17.exe
[2010/11/04 22.52.55 | 000,000,771 | —- | C] () – C:\Users\Public\Desktop\The Cleaner 2011.lnk
[2010/11/04 22.31.49 | 000,001,678 | —- | C] () – C:\Users\marco\Desktop\Usenet.nl.lnk
[2010/11/04 18.53.35 | 001,080,832 | —- | C] () – C:\Users\marco\Desktop\msxml3.msi
[2010/11/04 06.59.07 | 000,000,092 | —- | C] () – C:\Users\marco\Desktop\fig.reg
[2010/11/03 06.30.20 | 268,435,456 | -HS- | C] () – C:\Windows\System32\temppf.sys
[2010/11/03 05.55.06 | 001,207,026 | —- | C] () – C:\Users\marco\Desktop\tdsskiller.zip
[2010/11/01 11.27.11 | 000,294,912 | —- | C] () – C:\Users\marco\Desktop\gmer.exe
[2010/11/01 07.21.37 | 000,286,404 | —- | C] () – C:\Users\marco\Desktop\gmer.zip
[2010/10/31 22.08.48 | 000,000,919 | —- | C] () – C:\Users\Public\Desktop\SystemTweaker.lnk
[2010/10/31 21.40.35 | 000,000,332 | —- | C] () – C:\Windows\tasks\RegistryBooster.job
[2010/10/31 21.40.23 | 000,000,929 | —- | C] () – C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/10/31 09.00.30 | 000,689,664 | —- | C] () – C:\Users\marco\Desktop\MicrosoftFixit50202.msi
[2010/10/30 07.11.43 | 003,059,712 | —- | C] () – C:\Users\marco\Desktop\mvt_it.msi
[2010/10/29 05.30.57 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2010/10/29 05.30.57 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2010/10/29 05.30.56 | 000,002,052 | —- | C] () – C:\Windows\UDB.zip
[2010/10/29 05.30.56 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2010/10/29 05.30.56 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2010/10/28 22.23.41 | 002,100,028 | —- | C] () – C:\Windows\System32\drivers\Cat.DB
[2010/10/28 22.22.53 | 000,001,824 | —- | C] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/10/28 22.02.03 | 001,373,616 | —- | C] () – C:\Users\marco\Desktop\MCPR.exe
[2010/10/28 21.25.55 | 000,507,360 | —- | C] () – C:\Users\marco\Desktop\sdsetup.exe
[2010/10/28 21.08.00 | 000,001,095 | —- | C] () – C:\Users\marco\Desktop\Spybot - Search & Destroy.lnk
[2010/10/28 05.20.24 | 000,000,036 | —- | C] () – C:\Users\marco\AppData\Local\housecall.guid.cache
[2010/10/17 15.01.52 | 000,024,064 | —- | C] () – C:\Users\marco\Documents\It is not possible to select your own login for this site.doc
[2010/10/17 14.16.54 | 000,075,731 | —- | C] () – C:\Users\marco\Documents\540335p.pdf
[2010/10/12 21.24.49 | 000,001,927 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/09/23 11.13.32 | 000,000,120 | —- | C] () – C:\Users\marco\AppData\Local\Dgigalu.dat
[2010/09/23 11.13.32 | 000,000,000 | —- | C] () – C:\Users\marco\AppData\Local\Olirihoji.bin
[2010/04/01 13.53.28 | 000,000,280 | —- | C] () – C:\Windows\System32\PGPsdk.dll.sig
[2009/11/23 04.21.51 | 000,000,424 | —- | C] () – C:\Windows\ODBC.INI
[2009/08/15 15.09.58 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/08/15 07.00.45 | 000,019,456 | —- | C] () – C:\Windows\System32\ventmon.dll
[2009/08/03 14.07.42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/28 22.06.04 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/04 05.42.55 | 000,000,033 | —- | C] () – C:\Windows\DownloadStudioScheduleMonitor.INI
[2009/05/01 06.02.47 | 000,000,004 | RHS- | C] () – C:\ProgramData\sysqcl1129139270.dat
[2009/04/29 16.56.31 | 000,000,992 | —- | C] () – C:\Windows\photopnt.ini
[2009/04/29 13.03.43 | 000,006,648 | —- | C] () – C:\Users\marco\AppData\Local\d3d9caps.dat
[2009/04/27 07.57.12 | 000,017,408 | —- | C] () – C:\Windows\System32\Delphimm.dll
[2009/04/22 07.19.13 | 000,003,676 | —- | C] () – C:\Users\marco\AppData\Roaming\wklnhst.dat
[2009/04/18 15.07.59 | 000,004,935 | —- | C] () – C:\ProgramData\srpdbdrl.vrc
[2009/04/16 13.17.24 | 000,164,352 | —- | C] () – C:\Users\marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/04 19.00.35 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1527.dll
[2008/12/04 09.31.15 | 000,204,800 | —- | C] () – C:\Windows\System32\SysHook.dll
[2008/12/04 09.29.31 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2008/12/04 09.29.31 | 000,000,036 | —- | C] () – C:\Windows\PidList.ini
[2008/12/04 09.28.11 | 000,001,694 | —- | C] () – C:\Windows\RtDefLvl.ini
[2008/06/03 21.47.50 | 000,015,360 | —- | C] () – C:\Windows\System32\hzofypl.dll
[2008/05/07 22.28.17 | 000,487,424 | —- | C] () – C:\Windows\System32\INT15.dll
[2008/05/07 22.25.27 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIOFM4.dll
[2008/05/07 22.25.27 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIBUN5.dll
[2008/04/30 09.09.06 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2008/04/30 09.09.01 | 000,872,448 | —- | C] () – C:\Windows\iconv.dll
[2008/04/30 09.09.01 | 000,743,424 | —- | C] () – C:\Windows\libxml2.dll
[2008/04/30 09.09.01 | 000,000,042 | —- | C] () – C:\Windows\Prelaunch.ini
[2007/11/06 21.19.28 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2006/11/02 13.35.32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 08.40.29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2001/12/26 15.12.30 | 000,065,536 | —- | C] () – C:\Windows\System32\multiplex_vcd.dll
[2001/09/03 22.46.38 | 000,110,592 | —- | C] () – C:\Windows\System32\Hmpg12.dll
[2001/07/30 15.33.56 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC.dll
[2001/07/23 21.04.36 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC_MMX.dll
[2000/06/21 20.22.35 | 000,126,336 | —- | C] () – C:\Windows\System32\hpf9xdr0.drv
========== LOP Check ==========
[2008/05/07 22.24.09 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Acer GameZone Console
[2009/05/17 08.40.19 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\AliceEntry
[2010/10/27 23.50.22 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\AnVi
[2009/05/04 05.42.55 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Conceiva
[2009/08/15 16.45.34 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\DAEMON Tools Lite
[2009/04/18 14.56.29 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Devicescape
[2009/04/18 14.28.58 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\eSobi
[2010/08/10 11.38.20 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\ICAClient
[2010/09/24 00.17.12 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Juniper Networks
[2009/04/21 10.50.53 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\NCH Swift Sound
[2010/09/26 16.43.44 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Nokia
[2009/05/27 22.07.06 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\OfficeWork Software
[2010/09/18 06.59.26 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\PC Suite
[2010/10/19 21.54.12 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\PGP Corporation
[2010/11/04 18.56.28 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\QuickScan
[2009/05/27 21.57.07 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\RelevantReach
[2009/12/24 07.44.19 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Scendix Software
[2009/04/22 07.19.15 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Template
[2010/11/04 22.53.02 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\thecleaner
[2009/04/18 08.34.50 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\TomTom
[2010/10/31 22.08.52 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Uniblue
[2010/11/04 22.35.41 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Usenet.nl
[2010/11/06 17.00.17 | 000,000,332 | —- | M] () – C:\Windows\Tasks\RegistryBooster.job
[2010/11/07 09.19.39 | 000,032,490 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/06 13.39.00 | 000,000,442 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{75E1966D-AD9F-42D4-A7B8-0965F1B2B3CC}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 10.49.52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 03.23.00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 03.23.00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 10.49.36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 10.46.03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 10.46.03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: EVENTLOG.DLL >
[2007/01/12 21.30.08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\Cyberlink\PowerDirector\EventLog.dll
< MD5 for: IASTORV.SYS >
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 10.51.25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2009/04/11 07.28.23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/11 07.28.23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 03.24.05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2006/11/02 10.50.13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/21 03.24.50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 07.28.24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/11 07.28.24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009/08/15 15.09.58 | 000,721,904 | —- | M] () Unable to obtain MD5 – C:\Windows\System32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2008/01/21 04.14.18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04.14.08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04.14.18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11.34.08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11.34.08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /90 >
[2010/08/24 14.57.38 | 000,095,600 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeapfk.sys
[2010/08/24 14.57.38 | 000,386,712 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfehidk.sys
[2010/09/30 07.58.32 | 000,159,936 | —- | M] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/08/18 12.51.26 | 000,237,632 | —- | M] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2010/10/05 10.10.56 | 000,249,616 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2010/08/10 16.58.50 | 000,031,960 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2010/09/03 11.28.54 | 000,087,400 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2010/10/05 10.11.12 | 000,123,712 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2010/08/27 08.26.40 | 000,070,536 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2010/08/28 11.28.48 | 000,102,184 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/09/06 14.45.38 | 000,304,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2010/09/06 14.45.22 | 000,145,408 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv2.sys
[2010/09/06 14.45.19 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/08/26 11.39.46 | 000,051,984 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2010/08/26 11.39.46 | 000,033,552 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2010/08/26 11.39.46 | 000,068,880 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 180 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4298B0A2
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:430C6D84
< End of report >
The setting are the same used in the first scan
One more info. I have removed my McAfee antivirus because it cause continuous mulfuction aftar any restart. (System very slow and frequent stop)
OTL logfile created on: 07/11/2010 14.57.34 - Run 2
OTL by OldTimer - Version 3.2.17.2 Folder = C:\Users\marco\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 87,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 94,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 228,01 Gb Total Space | 54,27 Gb Free Space | 23,80% Space Free | Partition Type: NTFS
Drive D: | 227,98 Gb Total Space | 69,41 Gb Free Space | 30,45% Space Free | Partition Type: NTFS
Drive F: | 7,45 Gb Total Space | 0,68 Gb Free Space | 9,12% Space Free | Partition Type: FAT32
Computer Name: PC-MARCO | User Name: marco | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
PRC - [2009/04/11 07.27.36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
MOD - [2010/08/31 16.43.52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - File not found [Unknown | Stopped] – C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe – (McShield)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - File not found [Auto | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2010/09/29 15.00.56 | 001,145,304 | —- | M] (PC Tools) [Auto | Stopped] – C:\Program Files\PC Tools Security\pctsSvc.exe – (sdCoreService)
SRV - [2010/09/24 11.19.06 | 000,235,472 | —- | M] (Threat Expert Ltd.) [Auto | Stopped] – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2010/08/26 11.39.46 | 000,070,928 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files\PC Tools Security\TFEngine\TFService.exe – (ThreatFire)
SRV - [2010/08/24 14.57.38 | 000,141,792 | —- | M] (McAfee, Inc.) [Unknown | Stopped] – C:\Windows\System32\mfevtps.exe – (mfevtp)
SRV - [2010/08/24 10.38.18 | 000,092,008 | —- | M] (TomTom) [Auto | Stopped] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2010/06/14 14.07.14 | 000,615,936 | —- | M] (Nokia) [On_Demand | Stopped] – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer)
SRV - [2010/04/01 13.53.28 | 000,135,288 | —- | M] (PGP Corporation) [Auto | Stopped] – C:\Windows\System32\PGPserv.exe – (PGPserv)
SRV - [2010/03/15 13.02.36 | 000,366,840 | —- | M] (PC Tools) [Auto | Stopped] – C:\Program Files\PC Tools Security\pctsAuxs.exe – (sdAuxService)
SRV - [2009/09/25 02.27.04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009/04/21 10.48.16 | 000,425,988 | —- | M] () [Auto | Stopped] – C:\Program Files\NCH Software\Eyeline\eyeline.exe – (EyelineService)
SRV - [2009/04/21 10.47.27 | 000,368,644 | —- | M] () [Auto | Stopped] – C:\Program Files\NCH Software\BroadCam\broadCam.exe – (BroadCamService)
SRV - [2009/01/26 14.31.10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Stopped] – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/05/14 17.05.30 | 000,500,784 | —- | M] (Egis Incorporated) [Auto | Stopped] – C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe – (eDataSecurity Service)
SRV - [2008/04/06 21.42.24 | 000,050,424 | —- | M] (NewTech InfoSystems, Inc.) [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe – (NTIBackupSvc)
SRV - [2008/04/04 02.03.14 | 000,131,072 | —- | M] () [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe – (NTISchedulerSvc)
SRV - [2008/03/21 12.22.52 | 000,024,576 | —- | M] () [Auto | Stopped] – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe – (ETService)
SRV - [2008/03/18 20.27.12 | 000,013,312 | —- | M] (Agere Systems) [Auto | Stopped] – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio)
SRV - [2008/03/03 12.11.14 | 000,016,384 | —- | M] (NewTech Infosystems, Inc.) [Auto | Stopped] – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe – (BUNAgentSvc)
SRV - [2008/01/21 03.23.32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2008/01/16 17.35.02 | 000,081,504 | —- | M] () [Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe – (CLHNService)
SRV - [2007/12/06 16.15.28 | 000,110,592 | —- | M] () [Disabled | Stopped] – C:\Acer\Mobility Center\MobilityService.exe – (MobilityService)
SRV - [2007/11/06 21.22.26 | 000,092,792 | —- | M] (CACE Technologies) [On_Demand | Stopped] – C:\Program Files\WinPcap\rpcapd.exe – (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | System | Stopped] – C:\Windows\System32\drivers\mfewfpk.sys – (mfewfpk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mferkdet.sys – (mferkdet)
DRV - File not found [Kernel | System | Stopped] – C:\Windows\System32\DRIVERS\mfenlfk.sys – (mfenlfk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfefirek.sys – (mfefirek)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\cfwids.sys – (cfwids)
DRV - [2010/10/05 10.10.56 | 000,249,616 | —- | M] (PC Tools) [Kernel | System | Stopped] – C:\Windows\System32\drivers\pctgntdi.sys – (pctgntdi)
DRV - [2010/08/27 08.26.40 | 000,070,536 | —- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\pctplsg.sys – (pctplsg)
DRV - [2010/08/26 11.39.46 | 000,068,880 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\TfSysMon.sys – (TfSysMon)
DRV - [2010/08/26 11.39.46 | 000,051,984 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\TfFsMon.sys – (TfFsMon)
DRV - [2010/08/26 11.39.46 | 000,033,552 | –S- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TfNetMon.sys – (TfNetMon)
DRV - [2010/08/24 14.57.38 | 000,386,712 | —- | M] (McAfee, Inc.) [Kernel | Boot | Stopped] – C:\Windows\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2010/08/24 14.57.38 | 000,095,600 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2010/08/18 12.51.26 | 000,237,632 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2010/07/16 13.59.54 | 000,656,320 | —- | M] (PC Tools) [File_System | Boot | Running] – C:\Windows\system32\drivers\pctEFA.sys – (pctEFA)
DRV - [2010/07/16 13.59.54 | 000,338,880 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\pctDS.sys – (pctDS)
DRV - [2010/04/01 13.53.28 | 000,266,360 | —- | M] (PGP Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\PGPwded.sys – (PGPwded)
DRV - [2010/04/01 13.53.28 | 000,243,832 | —- | M] (PGP Corporation) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PGPdisk.sys – (PGPdisk)
DRV - [2010/04/01 13.53.28 | 000,040,568 | —- | M] (PGP Corporation) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PGPsdk.sys – (PGPsdkDriver)
DRV - [2010/04/01 13.53.26 | 000,136,312 | —- | M] (PGP Corporation) [File_System | Boot | Running] – C:\Windows\System32\Drivers\PGPfsfd.sys – (pgpfs)
DRV - [2010/04/01 13.53.26 | 000,013,432 | —- | M] (PGP Corporation) [File_System | Boot | Running] – C:\Windows\system32\DRIVERS\Pgpwdefs.sys – (Pgpwdefs)
DRV - [2010/02/05 04.16.10 | 000,028,048 | —- | M] (CSR, plc) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BthAvrcp.sys – (BthAvrcp)
DRV - [2009/09/30 06.53.12 | 001,184,768 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2009/08/15 15.09.58 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2008/08/26 09.26.12 | 000,018,816 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\pccsmcfd.sys – (pccsmcfd)
DRV - [2008/08/12 13.33.38 | 000,061,440 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\RTSTOR.sys – (RTSTOR)
DRV - [2008/07/11 19.20.10 | 002,381,312 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\igdkmd32.sys – (igfx)
DRV - [2008/06/14 02.10.08 | 002,152,344 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/05/14 17.05.44 | 000,060,464 | —- | M] (Egis Incorporated) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PSDVdisk.sys – (psdvdisk)
DRV - [2008/05/14 17.05.42 | 000,018,992 | —- | M] (Egis Incorporated) [File_System | Boot | Running] – C:\Windows\system32\DRIVERS\psdfilter.sys – (PSDFilter)
DRV - [2008/05/14 17.05.42 | 000,016,944 | —- | M] (Egis Incorporated) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\PSDNServ.sys – (PSDNServ)
DRV - [2008/04/25 19.08.42 | 000,199,472 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2008/04/18 14.01.24 | 000,061,424 | —- | M] (Cyberlink Corp.) [Kernel | Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl – ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796})
DRV - [2008/03/21 09.48.24 | 000,015,392 | —- | M] (Acer, Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\int15.sys – (int15)
DRV - [2008/03/01 00.13.38 | 001,202,560 | —- | M] (Agere Systems) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2008/02/21 10.55.00 | 000,299,008 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\yk60x86.sys – (yukonwlh)
DRV - [2008/02/18 15.55.20 | 000,101,376 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ewusbmdm.sys – (hwdatacard)
DRV - [2008/01/31 02.52.06 | 000,014,848 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\NTIDrvr.sys – (NTIDrvr)
DRV - [2008/01/31 02.51.50 | 000,013,824 | —- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\UBHelper.sys – (UBHelper)
DRV - [2008/01/21 03.23.27 | 000,386,616 | —- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasr.sys – (MegaSR)
DRV - [2008/01/21 03.23.27 | 000,149,560 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2008/01/21 03.23.27 | 000,031,288 | —- | M] (LSI Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2008/01/21 03.23.26 | 000,101,432 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2008/01/21 03.23.26 | 000,074,808 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2008/01/21 03.23.26 | 000,040,504 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2008/01/21 03.23.25 | 000,300,600 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2008/01/21 03.23.25 | 000,089,656 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2008/01/21 03.23.24 | 001,122,360 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2008/01/21 03.23.24 | 000,118,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2008/01/21 03.23.24 | 000,079,928 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2008/01/21 03.23.23 | 000,654,336 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTCNXT3.SYS – (winachsf)
DRV - [2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2008/01/21 03.23.23 | 000,130,616 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2008/01/21 03.23.23 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2008/01/21 03.23.23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2008/01/21 03.23.23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2008/01/21 03.23.23 | 000,079,416 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2008/01/21 03.23.23 | 000,030,720 | —- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nscirda.sys – (NSCIRDA)
DRV - [2008/01/21 03.23.22 | 000,987,648 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTDPV3.SYS – (HSF_DPV)
DRV - [2008/01/21 03.23.22 | 000,342,584 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2008/01/21 03.23.22 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2008/01/21 03.23.21 | 000,422,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2008/01/21 03.23.21 | 000,102,968 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2008/01/21 03.23.20 | 000,238,648 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2008/01/21 03.23.20 | 000,179,712 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\b57nd60x.sys – (b57nd60x)
DRV - [2008/01/21 03.23.00 | 000,020,024 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2008/01/21 03.23.00 | 000,019,000 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2008/01/21 03.23.00 | 000,017,464 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2008/01/16 17.35.08 | 000,122,368 | —- | M] (Cyberlink Corp.) [Kernel | Auto | Stopped] – C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys – (NTIPPKernel)
DRV - [2007/11/06 21.22.06 | 000,034,064 | —- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\npf.sys – (NPF)
DRV - [2007/03/08 09.53.44 | 000,099,584 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZTEusbser.sys – (qcusbser)
DRV - [2006/11/03 06.29.36 | 000,021,264 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\DKbFltr.sys – (DKbFltr)
DRV - [2006/11/02 10.50.35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 10.50.35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 10.50.19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 10.50.17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 10.50.11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 10.50.09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 10.50.07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 10.50.05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 10.50.03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 10.49.59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 10.49.56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 09.25.24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 09.24.47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 09.24.46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 09.24.45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 09.24.44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 09.24.44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 08.36.50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2004/01/26 16.36.35 | 000,095,552 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\Windows\System32\drivers\prohlp02.sys – (prohlp02)
DRV - [2004/01/26 16.01.28 | 000,052,224 | —- | M] (Protection Technology) [Kernel | System | Stopped] – C:\Windows\System32\drivers\prodrv06.sys – (prodrv06)
DRV - [2003/12/01 16.20.52 | 000,004,832 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\Windows\System32\drivers\sfhlp01.sys – (sfhlp01)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "NCH Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2117678&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.startup.homepage: "http://homepage.acer.com/rdr.aspx?b=ACAW&l;=0410&s;=2&o;=vp32&d;=1208&m;=aspire_5735"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}:5.0.16
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.732
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.50
FF - prefs.js..network.proxy.http: "192.168.0.1"
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/16 21.39.47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2010/10/29 05.30.59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/31 07.03.23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 05.09.56 | 000,000,000 | —D | M]
[2009/12/24 07.44.43 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Extensions
[2009/12/24 07.44.43 | 000,000,000 | —D | M] (No name found) – C:\Users\marco\AppData\Roaming\mozilla\Extensions\{2f1e6a90-e99e-11dd-ba2f-0800200c9a66}
[2009/04/18 08.35.01 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Extensions\[removed]
[2010/11/06 16.30.02 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions
[2010/10/16 04.46.40 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/11/04 18.55.55 | 000,000,000 | —D | M] (No name found) – C:\Users\marco\AppData\Roaming\mozilla\Firefox\Profiles\pttb29kf.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2009/04/21 10.48.03 | 000,000,868 | —- | M] () – C:\Users\marco\AppData\Roaming\Mozilla\FireFox\Profiles\pttb29kf.default\searchplugins\conduit.xml
[2009/08/15 15.32.53 | 000,002,395 | —- | M] () – C:\Users\marco\AppData\Roaming\Mozilla\FireFox\Profiles\pttb29kf.default\searchplugins\daemon-search.xml
[2010/11/06 16.30.02 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/03 01.52.16 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/04/05 08.57.45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}
[2006/06/16 10.16.04 | 000,205,312 | —- | M] (NETDIMENSION CORPORATION) – C:\Program Files\Mozilla Firefox\plugins\NPMXENG.DLL
[2009/08/21 22.20.57 | 000,001,412 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\demauro.xml
[2010/03/14 07.10.28 | 000,000,744 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-it.xml
[2010/03/14 07.10.28 | 000,000,825 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\hoepli.xml
[2010/03/14 07.10.28 | 000,001,182 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-it.xml
[2010/03/14 07.10.28 | 000,000,953 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-it.xml
O1 HOSTS File: ([2006/09/18 22.41.32 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101031070323.dll File not found
O2 - BHO: (DownloadStudio IE Add-on) - {8170D7DC-BDD6-461e-88EB-F047257898C9} - C:\Program Files\Conceiva\DownloadStudio\DLMonitr.dll (Conceiva Pty Ltd)
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (no name) - {B99F805C-F0B1-48EA-8C8B-753BFCBED913} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DetectDatacard] C:\Program Files\AliceEntry\DetectDatacard.exe (ONDA)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe File not found
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [ProductReg] C:\Program Files\Acer\WR_PopUp\ProductReg.exe (Acer)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Inserisci &blog; in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: carige.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: directline.it ([www] * in Siti attendibili)
O15 - HKCU\..Trusted Domains: fineco.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: internet ([]about in Siti attendibili)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Siti attendibili)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Siti attendibili)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Siti attendibili)
O15 - HKCU\..Trusted Domains: tim.it ([www] http in Siti attendibili)
O15 - HKCU\..Trusted Domains: vxsbill.com ([secure] https in Siti attendibili)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Siti attendibili)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…144/mcfscan.cab (McFreeScan Class)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\Windows\system32\hzofypl.dll) - C:\Windows\System32\hzofypl.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Acer01.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22.43.36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/10/26 08.21.46 | 000,000,219 | —- | M] () - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/11/06 18.51.55 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/11/06 18.51.55 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Local\temp
[2010/11/06 18.25.08 | 000,000,000 | –SD | C] – C:\ComboFix
[2010/11/06 18.24.46 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/11/06 16.01.12 | 000,000,000 | —D | C] – C:\Windows\pss
[2010/11/06 15.43.09 | 000,000,000 | —D | C] – C:\Windows\panther
[2010/11/06 06.58.06 | 000,101,376 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbmdm.sys
[2010/11/06 06.58.06 | 000,100,864 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbnet.sys
[2010/11/06 06.58.06 | 000,023,424 | —- | C] (Huawei Tech. Co., Ltd.) – C:\Windows\System32\drivers\ewdcsc.sys
[2010/11/06 06.37.24 | 000,000,000 | —D | C] – C:\Windows\LastGood.Tmp
[2010/11/05 06.03.17 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/11/05 06.03.17 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/11/05 06.03.17 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/11/05 06.03.09 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/11/05 06.02.44 | 000,000,000 | —D | C] – C:\Qoobox
[2010/11/05 05.50.00 | 000,000,000 | —D | C] – C:\ProgramData\moosoft
[2010/11/04 23.15.18 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2010/11/04 23.15.12 | 000,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2010/11/04 22.53.01 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\thecleaner
[2010/11/04 22.52.47 | 000,000,000 | —D | C] – C:\Program Files\The Cleaner
[2010/11/04 22.31.58 | 000,000,000 | —D | C] – C:\Users\marco\Documents\Usenet.nl
[2010/11/04 22.31.58 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\Usenet.nl
[2010/11/04 22.31.49 | 000,000,000 | —D | C] – C:\Program Files\Usenet.nl
[2010/11/04 22.31.24 | 036,946,400 | —- | C] (MooSoft Development LLC ) – C:\Users\marco\Desktop\cleaner7_setup.exe
[2010/11/04 22.27.20 | 003,023,984 | —- | C] ( ) – C:\Users\marco\Desktop\UsenetNLSetup_422135f.exe
[2010/11/04 19.20.11 | 001,913,056 | —- | C] (Trend Micro Inc.) – C:\Users\marco\Desktop\HousecallLauncher.exe
[2010/11/04 18.56.03 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\QuickScan
[2010/11/04 06.26.55 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2010/11/03 06.05.56 | 001,317,464 | —- | C] (Kaspersky Lab ZAO) – C:\Users\marco\Desktop\TDSSKiller.exe
[2010/11/01 07.04.13 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
[2010/10/31 22.06.11 | 004,813,736 | —- | C] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\systemtweaker.exe
[2010/10/31 21.40.27 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\Uniblue
[2010/10/31 21.40.19 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2010/10/31 16.10.03 | 005,273,528 | —- | C] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\registrybooster.exe
[2010/10/31 09.01.56 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Local\Threat Expert
[2010/10/31 07.02.14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2010/10/31 07.02.00 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2010/10/29 05.32.05 | 000,068,880 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
[2010/10/29 05.32.05 | 000,051,984 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2010/10/29 05.32.05 | 000,033,552 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2010/10/29 05.30.56 | 001,914,832 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2010/10/29 05.30.56 | 000,743,376 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2010/10/29 05.30.56 | 000,149,456 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2010/10/28 22.23.38 | 000,656,320 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctEFA.sys
[2010/10/28 22.23.38 | 000,338,880 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctDS.sys
[2010/10/28 22.23.31 | 000,249,616 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2010/10/28 22.23.30 | 000,102,184 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/10/28 22.23.11 | 000,237,632 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2010/10/28 22.23.11 | 000,159,936 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/10/28 22.22.30 | 000,123,712 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2010/10/28 22.22.30 | 000,087,400 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2010/10/28 22.22.30 | 000,031,960 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2010/10/28 22.22.24 | 000,070,536 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\PC Tools
[2010/10/28 22.21.47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.c698.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.a323.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.710c.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe.3318.deleteme
[2010/10/28 22.14.42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe
[2010/10/28 22.02.12 | 003,136,440 | —- | C] (McAfee, Inc.) – C:\Users\marco\Desktop\DMSetup.exe
[2010/10/28 21.25.55 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2010/10/28 21.07.41 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/10/28 21.07.41 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/10/24 14.45.27 | 000,000,000 | —D | C] – C:\Users\marco\Desktop\backups
[2010/10/24 14.27.32 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\marco\Desktop\HiJackThis.exe
[2010/10/23 07.42.43 | 000,000,000 | —D | C] – C:\Windows\McAfee.com
[2010/10/19 23.23.59 | 000,000,000 | —D | C] – C:\Users\marco\AppData\Roaming\AnVi
[2008/12/04 19.14.24 | 000,049,152 | —- | C] ( ) – C:\Windows\Interop.IWshRuntimeLibrary.dll
[4 C:\Users\marco\Documents\*.tmp files -> C:\Users\marco\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\marco\*.tmp files -> C:\Users\marco\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/07 09.41.56 | 000,006,648 | —- | M] () – C:\Users\marco\AppData\Local\d3d9caps.dat
[2010/11/07 09.38.17 | 000,661,860 | —- | M] () – C:\Windows\System32\perfh010.dat
[2010/11/07 09.38.17 | 000,586,568 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/07 09.38.17 | 000,119,742 | —- | M] () – C:\Windows\System32\perfc010.dat
[2010/11/07 09.38.17 | 000,100,640 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/07 09.34.01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/07 09.33.50 | 268,435,456 | -HS- | M] () – C:\Windows\System32\temppf.sys
[2010/11/06 18.21.52 | 003,903,895 | R— | M] () – C:\Users\marco\Desktop\ComboFix.exe
[2010/11/06 17.00.19 | 000,001,132 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/06 17.00.17 | 000,000,332 | —- | M] () – C:\Windows\tasks\RegistryBooster.job
[2010/11/06 15.44.27 | 000,002,562 | —- | M] () – C:\Windows\diagwrn.xml
[2010/11/06 15.44.27 | 000,001,908 | —- | M] () – C:\Windows\diagerr.xml
[2010/11/06 15.43.51 | 000,002,354 | —- | M] () – C:\Users\marco\Desktop\Windows_Rapporto compatibilità.htm
[2010/11/06 13.39.00 | 000,000,442 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{75E1966D-AD9F-42D4-A7B8-0965F1B2B3CC}.job
[2010/11/06 13.38.49 | 000,009,216 | —- | M] () – C:\Windows\System32\umstartup.etl
[2010/11/06 06.58.15 | 000,000,876 | —- | M] () – C:\Users\Public\Desktop\Alice MOBILE E169.lnk
[2010/11/05 21.15.49 | 000,088,576 | —- | M] () – C:\Windows\MBR.exe
[2010/11/04 23.15.00 | 001,709,408 | —- | M] () – C:\Users\marco\Desktop\taskmanager17.exe
[2010/11/04 22.52.55 | 000,000,771 | —- | M] () – C:\Users\Public\Desktop\The Cleaner 2011.lnk
[2010/11/04 22.52.23 | 036,946,400 | —- | M] (MooSoft Development LLC ) – C:\Users\marco\Desktop\cleaner7_setup.exe
[2010/11/04 22.31.49 | 000,001,678 | —- | M] () – C:\Users\marco\Desktop\Usenet.nl.lnk
[2010/11/04 22.28.46 | 003,023,984 | —- | M] ( ) – C:\Users\marco\Desktop\UsenetNLSetup_422135f.exe
[2010/11/04 21.27.54 | 002,100,028 | —- | M] () – C:\Windows\System32\drivers\Cat.DB
[2010/11/04 19.20.23 | 001,913,056 | —- | M] (Trend Micro Inc.) – C:\Users\marco\Desktop\HousecallLauncher.exe
[2010/11/04 18.53.35 | 001,080,832 | —- | M] () – C:\Users\marco\Desktop\msxml3.msi
[2010/11/04 18.49.00 | 003,136,440 | —- | M] (McAfee, Inc.) – C:\Users\marco\Desktop\DMSetup.exe
[2010/11/04 06.59.07 | 000,000,092 | —- | M] () – C:\Users\marco\Desktop\fig.reg
[2010/11/03 22.04.56 | 000,021,504 | —- | M] () – C:\Windows\System32\umstartup000.etl
[2010/11/03 06.31.02 | 000,001,136 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/03 06.22.42 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 06.22.42 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 06.22.38 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/11/03 05.55.19 | 001,207,026 | —- | M] () – C:\Users\marco\Desktop\tdsskiller.zip
[2010/11/01 21.06.11 | 289,248,269 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/11/01 18.51.42 | 000,000,474 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for marco.job
[2010/11/01 07.21.44 | 000,286,404 | —- | M] () – C:\Users\marco\Desktop\gmer.zip
[2010/11/01 07.04.20 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Users\marco\Desktop\OTL.exe
[2010/10/31 22.08.48 | 000,000,919 | —- | M] () – C:\Users\Public\Desktop\SystemTweaker.lnk
[2010/10/31 22.07.58 | 004,813,736 | —- | M] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\systemtweaker.exe
[2010/10/31 21.40.23 | 000,000,929 | —- | M] () – C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/10/31 16.10.55 | 005,273,528 | —- | M] (Uniblue Systems Ltd ) – C:\Users\marco\Desktop\registrybooster.exe
[2010/10/31 15.34.06 | 000,164,352 | —- | M] () – C:\Users\marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/31 09.01.19 | 000,689,664 | —- | M] () – C:\Users\marco\Desktop\MicrosoftFixit50202.msi
[2010/10/30 17.29.00 | 003,059,712 | —- | M] () – C:\Users\marco\Desktop\mvt_it.msi
[2010/10/28 22.22.53 | 000,001,824 | —- | M] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/10/28 21.37.02 | 001,373,616 | —- | M] () – C:\Users\marco\Desktop\MCPR.exe
[2010/10/28 21.25.14 | 000,507,360 | —- | M] () – C:\Users\marco\Desktop\sdsetup.exe
[2010/10/28 21.08.00 | 000,001,095 | —- | M] () – C:\Users\marco\Desktop\Spybot - Search & Destroy.lnk
[2010/10/28 05.20.24 | 000,000,036 | —- | M] () – C:\Users\marco\AppData\Local\housecall.guid.cache
[2010/10/26 11.30.08 | 001,317,464 | —- | M] (Kaspersky Lab ZAO) – C:\Users\marco\Desktop\TDSSKiller.exe
[2010/10/24 14.27.51 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\marco\Desktop\HiJackThis.exe
[2010/10/19 20.47.59 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2010/10/19 16.00.08 | 000,294,912 | —- | M] () – C:\Users\marco\Desktop\gmer.exe
[2010/10/17 15.01.54 | 000,024,064 | —- | M] () – C:\Users\marco\Documents\It is not possible to select your own login for this site.doc
[2010/10/17 14.16.55 | 000,075,731 | —- | M] () – C:\Users\marco\Documents\540335p.pdf
[2010/10/14 20.50.21 | 000,304,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/12 21.24.49 | 000,001,927 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[4 C:\Users\marco\Documents\*.tmp files -> C:\Users\marco\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\marco\*.tmp files -> C:\Users\marco\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/06 18.24.40 | 003,903,895 | R— | C] () – C:\Users\marco\Desktop\ComboFix.exe
[2010/11/06 13.13.44 | 000,002,354 | —- | C] () – C:\Users\marco\Desktop\Windows_Rapporto compatibilità.htm
[2010/11/06 13.12.22 | 000,002,562 | —- | C] () – C:\Windows\diagwrn.xml
[2010/11/06 13.12.22 | 000,001,908 | —- | C] () – C:\Windows\diagerr.xml
[2010/11/06 06.58.15 | 000,000,876 | —- | C] () – C:\Users\Public\Desktop\Alice MOBILE E169.lnk
[2010/11/05 06.03.17 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/11/05 06.03.17 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/11/05 06.03.17 | 000,088,576 | —- | C] () – C:\Windows\MBR.exe
[2010/11/05 06.03.17 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/11/05 06.03.17 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/11/04 23.14.48 | 001,709,408 | —- | C] () – C:\Users\marco\Desktop\taskmanager17.exe
[2010/11/04 22.52.55 | 000,000,771 | —- | C] () – C:\Users\Public\Desktop\The Cleaner 2011.lnk
[2010/11/04 22.31.49 | 000,001,678 | —- | C] () – C:\Users\marco\Desktop\Usenet.nl.lnk
[2010/11/04 18.53.35 | 001,080,832 | —- | C] () – C:\Users\marco\Desktop\msxml3.msi
[2010/11/04 06.59.07 | 000,000,092 | —- | C] () – C:\Users\marco\Desktop\fig.reg
[2010/11/03 06.30.20 | 268,435,456 | -HS- | C] () – C:\Windows\System32\temppf.sys
[2010/11/03 05.55.06 | 001,207,026 | —- | C] () – C:\Users\marco\Desktop\tdsskiller.zip
[2010/11/01 11.27.11 | 000,294,912 | —- | C] () – C:\Users\marco\Desktop\gmer.exe
[2010/11/01 07.21.37 | 000,286,404 | —- | C] () – C:\Users\marco\Desktop\gmer.zip
[2010/10/31 22.08.48 | 000,000,919 | —- | C] () – C:\Users\Public\Desktop\SystemTweaker.lnk
[2010/10/31 21.40.35 | 000,000,332 | —- | C] () – C:\Windows\tasks\RegistryBooster.job
[2010/10/31 21.40.23 | 000,000,929 | —- | C] () – C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/10/31 09.00.30 | 000,689,664 | —- | C] () – C:\Users\marco\Desktop\MicrosoftFixit50202.msi
[2010/10/30 07.11.43 | 003,059,712 | —- | C] () – C:\Users\marco\Desktop\mvt_it.msi
[2010/10/29 05.30.57 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2010/10/29 05.30.57 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2010/10/29 05.30.56 | 000,002,052 | —- | C] () – C:\Windows\UDB.zip
[2010/10/29 05.30.56 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2010/10/29 05.30.56 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2010/10/28 22.23.41 | 002,100,028 | —- | C] () – C:\Windows\System32\drivers\Cat.DB
[2010/10/28 22.22.53 | 000,001,824 | —- | C] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/10/28 22.02.03 | 001,373,616 | —- | C] () – C:\Users\marco\Desktop\MCPR.exe
[2010/10/28 21.25.55 | 000,507,360 | —- | C] () – C:\Users\marco\Desktop\sdsetup.exe
[2010/10/28 21.08.00 | 000,001,095 | —- | C] () – C:\Users\marco\Desktop\Spybot - Search & Destroy.lnk
[2010/10/28 05.20.24 | 000,000,036 | —- | C] () – C:\Users\marco\AppData\Local\housecall.guid.cache
[2010/10/17 15.01.52 | 000,024,064 | —- | C] () – C:\Users\marco\Documents\It is not possible to select your own login for this site.doc
[2010/10/17 14.16.54 | 000,075,731 | —- | C] () – C:\Users\marco\Documents\540335p.pdf
[2010/10/12 21.24.49 | 000,001,927 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/09/23 11.13.32 | 000,000,120 | —- | C] () – C:\Users\marco\AppData\Local\Dgigalu.dat
[2010/09/23 11.13.32 | 000,000,000 | —- | C] () – C:\Users\marco\AppData\Local\Olirihoji.bin
[2010/04/01 13.53.28 | 000,000,280 | —- | C] () – C:\Windows\System32\PGPsdk.dll.sig
[2009/11/23 04.21.51 | 000,000,424 | —- | C] () – C:\Windows\ODBC.INI
[2009/08/15 15.09.58 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/08/15 07.00.45 | 000,019,456 | —- | C] () – C:\Windows\System32\ventmon.dll
[2009/08/03 14.07.42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/28 22.06.04 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/04 05.42.55 | 000,000,033 | —- | C] () – C:\Windows\DownloadStudioScheduleMonitor.INI
[2009/05/01 06.02.47 | 000,000,004 | RHS- | C] () – C:\ProgramData\sysqcl1129139270.dat
[2009/04/29 16.56.31 | 000,000,992 | —- | C] () – C:\Windows\photopnt.ini
[2009/04/29 13.03.43 | 000,006,648 | —- | C] () – C:\Users\marco\AppData\Local\d3d9caps.dat
[2009/04/27 07.57.12 | 000,017,408 | —- | C] () – C:\Windows\System32\Delphimm.dll
[2009/04/22 07.19.13 | 000,003,676 | —- | C] () – C:\Users\marco\AppData\Roaming\wklnhst.dat
[2009/04/18 15.07.59 | 000,004,935 | —- | C] () – C:\ProgramData\srpdbdrl.vrc
[2009/04/16 13.17.24 | 000,164,352 | —- | C] () – C:\Users\marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/04 19.00.35 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1527.dll
[2008/12/04 09.31.15 | 000,204,800 | —- | C] () – C:\Windows\System32\SysHook.dll
[2008/12/04 09.29.31 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2008/12/04 09.29.31 | 000,000,036 | —- | C] () – C:\Windows\PidList.ini
[2008/12/04 09.28.11 | 000,001,694 | —- | C] () – C:\Windows\RtDefLvl.ini
[2008/06/03 21.47.50 | 000,015,360 | —- | C] () – C:\Windows\System32\hzofypl.dll
[2008/05/07 22.28.17 | 000,487,424 | —- | C] () – C:\Windows\System32\INT15.dll
[2008/05/07 22.25.27 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIOFM4.dll
[2008/05/07 22.25.27 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIBUN5.dll
[2008/04/30 09.09.06 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2008/04/30 09.09.01 | 000,872,448 | —- | C] () – C:\Windows\iconv.dll
[2008/04/30 09.09.01 | 000,743,424 | —- | C] () – C:\Windows\libxml2.dll
[2008/04/30 09.09.01 | 000,000,042 | —- | C] () – C:\Windows\Prelaunch.ini
[2007/11/06 21.19.28 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2006/11/02 13.35.32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 08.40.29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2001/12/26 15.12.30 | 000,065,536 | —- | C] () – C:\Windows\System32\multiplex_vcd.dll
[2001/09/03 22.46.38 | 000,110,592 | —- | C] () – C:\Windows\System32\Hmpg12.dll
[2001/07/30 15.33.56 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC.dll
[2001/07/23 21.04.36 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC_MMX.dll
[2000/06/21 20.22.35 | 000,126,336 | —- | C] () – C:\Windows\System32\hpf9xdr0.drv
========== LOP Check ==========
[2008/05/07 22.24.09 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Acer GameZone Console
[2009/05/17 08.40.19 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\AliceEntry
[2010/10/27 23.50.22 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\AnVi
[2009/05/04 05.42.55 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Conceiva
[2009/08/15 16.45.34 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\DAEMON Tools Lite
[2009/04/18 14.56.29 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Devicescape
[2009/04/18 14.28.58 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\eSobi
[2010/08/10 11.38.20 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\ICAClient
[2010/09/24 00.17.12 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Juniper Networks
[2009/04/21 10.50.53 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\NCH Swift Sound
[2010/09/26 16.43.44 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Nokia
[2009/05/27 22.07.06 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\OfficeWork Software
[2010/09/18 06.59.26 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\PC Suite
[2010/10/19 21.54.12 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\PGP Corporation
[2010/11/04 18.56.28 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\QuickScan
[2009/05/27 21.57.07 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\RelevantReach
[2009/12/24 07.44.19 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Scendix Software
[2009/04/22 07.19.15 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Template
[2010/11/04 22.53.02 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\thecleaner
[2009/04/18 08.34.50 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\TomTom
[2010/10/31 22.08.52 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Uniblue
[2010/11/04 22.35.41 | 000,000,000 | —D | M] – C:\Users\marco\AppData\Roaming\Usenet.nl
[2010/11/06 17.00.17 | 000,000,332 | —- | M] () – C:\Windows\Tasks\RegistryBooster.job
[2010/11/07 09.19.39 | 000,032,490 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/06 13.39.00 | 000,000,442 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{75E1966D-AD9F-42D4-A7B8-0965F1B2B3CC}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 03.23.01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 10.49.52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 07.32.26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 03.23.00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 03.23.00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 10.49.36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/12/04 19.01.31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 10.46.03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 10.46.03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: EVENTLOG.DLL >
[2007/01/12 21.30.08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\Cyberlink\PowerDirector\EventLog.dll
< MD5 for: IASTORV.SYS >
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 03.23.23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 10.51.25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2009/04/11 07.28.23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/11 07.28.23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 03.24.05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2006/11/02 10.50.13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 03.23.21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/21 03.24.50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 07.28.24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/11 07.28.24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009/08/15 15.09.58 | 000,721,904 | —- | M] () Unable to obtain MD5 – C:\Windows\System32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2008/01/21 04.14.18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04.14.08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04.14.18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11.34.08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11.34.08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /90 >
[2010/08/24 14.57.38 | 000,095,600 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeapfk.sys
[2010/08/24 14.57.38 | 000,386,712 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfehidk.sys
[2010/09/30 07.58.32 | 000,159,936 | —- | M] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/08/18 12.51.26 | 000,237,632 | —- | M] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2010/10/05 10.10.56 | 000,249,616 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2010/08/10 16.58.50 | 000,031,960 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2010/09/03 11.28.54 | 000,087,400 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2010/10/05 10.11.12 | 000,123,712 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2010/08/27 08.26.40 | 000,070,536 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2010/08/28 11.28.48 | 000,102,184 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/09/06 14.45.38 | 000,304,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2010/09/06 14.45.22 | 000,145,408 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv2.sys
[2010/09/06 14.45.19 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/08/26 11.39.46 | 000,051,984 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2010/08/26 11.39.46 | 000,033,552 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2010/08/26 11.39.46 | 000,068,880 | –S- | M] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 180 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4298B0A2
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:430C6D84
< End of report >