This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

remove searchqu

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello! I have a problem, and I cannot solve it on my own, so any help would be great. I cannot change my homepage, or should I say,something happened and change my homepage to www.searchqu.com. I don't really remember what program I installed to catch this problem and I tried to find solution by myself but i wasnt very successful. Can someone help me please? Thanks in advance.
Hi

Please run the following:

  • Download OTL and save it to your desktop.
  • Double click on the [external image: Posted Image] icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top, make sure Standard output is selected.
  • Under the Extra Registry section, check Use SafeList
  • Under Custom scan's and fixes section paste in the below text


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    nvraid.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button.
  • Do not change any other settings. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.


NEXT

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
thank you for your help

this is the extras.txt notepad
OTL Extras logfile created on: 5/30/2011 9:10:07 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Francesco\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.80 Gb Total Physical Memory | 2.26 Gb Available Physical Memory | 59.55% Memory free
7.60 Gb Paging File | 5.93 Gb Available in Paging File | 78.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.04 Gb Total Space | 92.93 Gb Free Space | 62.35% Space Free | Partition Type: NTFS
Drive D: | 148.65 Gb Total Space | 140.70 Gb Free Space | 94.65% Space Free | Partition Type: NTFS

Computer Name: FRANCESCO-TOSH | User Name: Francesco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{24811C12-F4A9-4D0F-8494-A7B8FE46123C}" = TOSHIBA ReelTime
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"4F214B105BE2C47A7C10086525680BB7DCF7DEEB" = Windows Driver Package - ATI Technologies Inc. (amdkmdap) Display (10/05/2010 8.783.0.0000)
"E8AD071510D6DB50A4A5327191F59F7569D3BB7F" = Windows Driver Package - ATI Technologies Inc. (amdkmdap) Display (10/05/2010 8.783.0.0000)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0FF68F26-416C-4954-ACA5-6AD5F9DE99C1}" = Nero Multimedia Suite 10 Essentials
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}" = Nero MediaHub 10
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2290A680-4083-410A-ADCC-7092C67FC052}" = TOSHIBA Online Product Information
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3C349576-B3B4-6708-F73C-DC2932065357}" = BBC iPlayer Desktop
"{3D047C6C-19EE-46E3-C14B-9FA84260DF9B}" = Photo Service - powered by myphotobook
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68AB6930-5BFF-4FF6-923B-516A91984FE6}" = Nero BackItUp 10
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}" = Toshiba Manuals
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}" = TOSHIBA Media Controller
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A74F16FA-1D5B-405B-8D8D-1BC6F9DAED8B}" = Amazon.co.uk
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}" = TOSHIBA Assist
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DBB7021A-3437-446F-ACE5-7261644A972C}" = Toshiba TEMPRO
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0FAA369-B0E3-48B8-9447-4873103B0012}" = TOSHIBA ConfigFree
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}" = TOSHIBA Media Controller Plug-in
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{FDE58148-57E7-43BF-879A-29CCE818C078}" = eBay
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVS Audio Converter 6.3_is1" = AVS Audio Converter version 6.3
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"conduitEngine" = Conduit Engine
"DAEMON Tools Lite" = DAEMON Tools Lite
"eMule" = eMule
"eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1" = Photo Service - powered by myphotobook
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}" = TOSHIBA ReelTime
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder
"InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NIS" = Norton Internet Security
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"The KMPlayer" = The KMPlayer (remove only)
"TOSHIBA Game Console" = WildTangent ORB Game Console
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WT088682" = Bejeweled 2 Deluxe
"WT088696" = Chuzzle Deluxe
"WT088759" = Polar Bowler
"WT089367" = Farm Mania 2
"WT089378" = Jewel Quest II
"WT089380" = Penguins!
"WT089381" = Slingo Supreme
"WT089388" = Zuma Deluxe
"WT089395" = Plants vs. Zombies - Game of the Year
"WT089404" = Fishdom

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/13/2011 10:49:33 AM | Computer Name = Francesco-TOSH | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Francesco\Downloads\SoftonicDownloader_for_kmplayer.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.

Error - 5/13/2011 11:12:47 AM | Computer Name = Francesco-TOSH | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "c:\program files (x86)\microsoft\search
enhancement pack\search helper\sepsearchhelperie.dll".Error in manifest or policy
file "c:\program files (x86)\microsoft\search enhancement pack\search helper\sepsearchhelperie.dll"
on line 2. Invalid Xml syntax.

Error - 5/13/2011 11:13:21 AM | Computer Name = Francesco-TOSH | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\Users\francesco\downloads\SoftonicDownloader_for_kmplayer.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.

Error - 5/13/2011 11:13:26 AM | Computer Name = Francesco-TOSH | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\Users\francesco\downloads\SoftonicDownloader_for_kmplayer.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.

Error - 5/13/2011 7:30:48 PM | Computer Name = Francesco-TOSH | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "c:\program files (x86)\microsoft\search
enhancement pack\search helper\sepsearchhelperie.dll".Error in manifest or policy
file "c:\program files (x86)\microsoft\search enhancement pack\search helper\sepsearchhelperie.dll"
on line 2. Invalid Xml syntax.

Error - 5/13/2011 10:01:04 PM | Computer Name = Francesco-TOSH | Source = MsiInstaller | ID = 11935
Description =

Error - 5/13/2011 10:06:11 PM | Computer Name = Francesco-TOSH | Source = MsiInstaller | ID = 11935
Description =

Error - 5/13/2011 10:07:37 PM | Computer Name = Francesco-TOSH | Source = MsiInstaller | ID = 11935
Description =

Error - 5/14/2011 10:44:00 AM | Computer Name = Francesco-TOSH | Source = MsiInstaller | ID = 1013
Description =

Error - 5/21/2011 11:41:18 AM | Computer Name = Francesco-TOSH | Source = MsiInstaller | ID = 10005
Description =

[ System Events ]
Error - 5/10/2011 2:13:57 PM | Computer Name = Francesco-TOSH | Source = DCOM | ID = 10010
Description =

Error - 5/10/2011 2:13:59 PM | Computer Name = Francesco-TOSH | Source = DCOM | ID = 10010
Description =

Error - 5/10/2011 4:19:12 PM | Computer Name = Francesco-TOSH | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the NIS service.

Error - 5/13/2011 10:01:11 PM | Computer Name = Francesco-TOSH | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Visual C++ 2008 Redistributable
Package (KB973924).

Error - 5/13/2011 10:06:43 PM | Computer Name = Francesco-TOSH | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft XML Core Services 4.0 Service
Pack 2 for x64-based Systems (KB954430).

Error - 5/13/2011 10:08:47 PM | Computer Name = Francesco-TOSH | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Update for Microsoft XML Core Services 4.0 Service Pack
2 for x64-based Systems (KB973688).


< End of report >


THIS IS OTL.Txt Notepad
OTL logfile created on: 5/30/2011 9:10:07 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Francesco\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.80 Gb Total Physical Memory | 2.26 Gb Available Physical Memory | 59.55% Memory free
7.60 Gb Paging File | 5.93 Gb Available in Paging File | 78.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.04 Gb Total Space | 92.93 Gb Free Space | 62.35% Space Free | Partition Type: NTFS
Drive D: | 148.65 Gb Total Space | 140.70 Gb Free Space | 94.65% Space Free | Partition Type: NTFS

Computer Name: FRANCESCO-TOSH | User Name: Francesco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/30 08:59:48 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Francesco\Desktop\OTL(1).exe
PRC - [2011/05/13 14:09:59 | 004,769,136 | —- | M] (BitTorrent, Inc.) – C:\Users\Francesco\Downloads\BitTorrent-7.2.1.exe
PRC - [2011/04/17 01:45:11 | 000,130,008 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe
PRC - [2011/04/14 17:25:41 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/01/20 10:20:12 | 001,305,408 | —- | M] (DT Soft Ltd) – C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2010/09/02 19:25:46 | 001,234,216 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
PRC - [2010/08/27 18:20:14 | 001,811,456 | —- | M] (Realsil Microelectronics Inc.) – C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
PRC - [2010/08/15 20:54:50 | 000,034,160 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
PRC - [2010/06/03 17:09:00 | 000,304,560 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2010/05/04 13:07:22 | 000,503,080 | —- | M] (Nero AG) – c:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010/05/01 17:55:36 | 002,454,840 | —- | M] (TOSHIBA CORPORATION.) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
PRC - [2010/04/24 01:10:34 | 000,209,768 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/04/24 01:10:28 | 000,483,688 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/03/03 15:42:02 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/03 15:41:58 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/07/28 21:26:42 | 000,062,848 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009/03/10 19:51:20 | 000,046,448 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe


========== Modules (SafeList) ==========

MOD - [2011/05/30 08:59:48 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Francesco\Desktop\OTL(1).exe
MOD - [2011/04/08 16:56:28 | 000,018,176 | —- | M] (McAfee, Inc.) – c:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll
MOD - [2010/08/21 06:21:32 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/09/28 13:30:28 | 000,489,384 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe – (TosCoSrv)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/02/05 18:44:48 | 000,137,560 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe – (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2009/07/28 15:48:06 | 000,140,632 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\SysNative\TODDSrv.exe – (TODDSrv)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/04/17 01:45:11 | 000,130,008 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe – (NIS)
SRV - [2011/02/16 15:49:08 | 000,101,048 | —- | M] (McAfee, Inc.) [Auto | Running] – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe – (McAfee SiteAdvisor Service)
SRV - [2010/08/27 18:20:14 | 001,811,456 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2010/07/28 22:36:52 | 000,246,520 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [2010/05/11 10:40:52 | 000,124,368 | —- | M] (Toshiba Europe GmbH) [On_Demand | Stopped] – C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe – (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO)
SRV - [2010/05/04 13:07:22 | 000,503,080 | —- | M] (Nero AG) [Auto | Running] – c:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate)
SRV - [2010/04/24 01:10:34 | 000,209,768 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe – (sftvsa)
SRV - [2010/04/24 01:10:28 | 000,483,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe – (sftlist)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/03 15:42:02 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/03/03 15:41:58 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2010/01/28 17:44:40 | 000,249,200 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe – (cfWiMAXService)
SRV - [2009/10/06 10:21:50 | 000,051,512 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe – (TMachInfo)
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/03/10 19:51:20 | 000,046,448 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe – (ConfigFree Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/05/14 15:20:24 | 000,254,528 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV:64bit: - [2011/05/10 19:35:10 | 000,174,200 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2011/03/31 04:00:09 | 000,744,568 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.sys – (SRTSP)
DRV:64bit: - [2011/03/31 04:00:09 | 000,040,568 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.sys – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2011/03/22 01:39:49 | 000,382,584 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnets.sys – (SymNetS)
DRV:64bit: - [2011/03/15 03:31:23 | 000,912,504 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.sys – (SymEFA)
DRV:64bit: - [2011/03/11 07:22:41 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 07:22:40 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/27 07:47:10 | 000,450,680 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.sys – (SymDS)
DRV:64bit: - [2011/01/21 12:52:00 | 000,020,592 | —- | M] (Compal Electronics, INC.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CeKbFilter.sys – (CeKbFilter)
DRV:64bit: - [2010/11/16 02:45:33 | 000,171,128 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\ironx64.sys – (SymIRON)
DRV:64bit: - [2010/10/05 22:23:18 | 007,884,288 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2010/10/05 21:15:14 | 000,285,696 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2010/07/29 06:10:42 | 010,610,400 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/06/23 16:10:56 | 000,344,680 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010/04/28 12:32:20 | 000,932,384 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\rtl8192ce.sys – (RTL8192Ce)
DRV:64bit: - [2010/04/24 01:10:32 | 000,022,376 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftvollh.sys – (Sftvol)
DRV:64bit: - [2010/04/24 01:10:28 | 000,269,672 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftplaylh.sys – (Sftplay)
DRV:64bit: - [2010/04/24 01:10:28 | 000,025,960 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftredirlh.sys – (Sftredir)
DRV:64bit: - [2010/04/24 01:10:20 | 000,721,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftfslh.sys – (Sftfs)
DRV:64bit: - [2010/03/22 11:55:20 | 000,046,192 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\LPCFilter.sys – (LPCFilter)
DRV:64bit: - [2010/03/10 19:51:32 | 000,316,464 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2010/02/27 08:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2010/01/15 13:22:08 | 000,538,136 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/01/07 10:05:46 | 000,232,992 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/09/17 13:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/30 20:22:04 | 000,027,784 | —- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\tdcmdpst.sys – (tdcmdpst)
DRV:64bit: - [2009/07/14 16:31:18 | 000,026,840 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\TVALZ_O.SYS – (TVALZ)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/22 18:06:38 | 000,035,008 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\PGEffect.sys – (PGEffect)
DRV:64bit: - [2009/06/10 21:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2011/05/18 09:49:22 | 002,011,768 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110529.002\EX64.SYS – (NAVEX15)
DRV - [2011/05/18 09:49:22 | 000,117,880 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110529.002\ENG64.SYS – (NAVENG)
DRV - [2011/05/11 11:47:39 | 000,481,912 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2011/05/11 11:47:39 | 000,136,824 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/04/19 01:35:53 | 001,127,032 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20110518.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2011/03/15 03:29:00 | 000,476,792 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20110527.001\IDSviA64.sys – (IDSVia64)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPlgn\ [2011/05/10 19:35:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn\ [2011/05/10 19:34:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/05/25 09:22:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/25 10:07:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/05/29 22:11:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Francesco\AppData\Roaming\Mozilla\Extensions
[2011/05/29 22:07:05 | 000,000,000 | —D | M] (No name found) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions
[2011/05/13 14:11:11 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/05/13 14:11:11 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions\[removed]
[2011/05/29 12:46:34 | 000,000,000 | —D | M] (Diccionario de Español/España) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions\[removed]
[2011/05/29 12:53:29 | 000,000,000 | —D | M] (Dizionario italiano) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions\[removed]
[2011/05/13 14:11:11 | 000,000,863 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\searchplugins\conduit.xml
[2011/05/13 12:49:54 | 000,002,472 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\searchplugins\safesearch.xml
[2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\searchplugins\SearchquWebSearch.xml
[2011/05/29 22:11:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) –
[2011/05/25 09:22:25 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2011/05/10 19:34:50 | 000,000,000 | —D | M] (Norton Toolbar) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN
[2011/05/10 19:35:14 | 000,000,000 | —D | M] (Symantec IPS) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPLGN
() (No name found) – C:\USERS\FRANCESCO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0QMP24DP.DEFAULT\EXTENSIONS\[removed]
[2011/04/14 17:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
[2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [NBAgent] c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/05/30 08:59:38 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\Francesco\Desktop\OTL(1).exe
[2011/05/29 23:47:35 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JabRef
[2011/05/29 23:47:34 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\JabRef 2.6
[2011/05/29 13:31:25 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/05/28 23:06:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/05/28 23:06:50 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/05/27 15:13:44 | 000,000,000 | —D | C] – C:\ProgramData\eMule
[2011/05/27 15:12:52 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\eMule
[2011/05/27 15:12:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eMule
[2011/05/27 15:12:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\eMule
[2011/05/26 23:10:43 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Windows Live
[2011/05/26 23:10:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\{BB525367-5BD2-4E07-BC87-8244094814CD}
[2011/05/26 23:10:15 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Windows Live Writer
[2011/05/26 23:10:15 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Windows Live Writer
[2011/05/25 11:17:59 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2011/05/25 11:17:57 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\AVS4YOU
[2011/05/25 11:17:48 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2011/05/25 11:17:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2011/05/25 11:17:22 | 010,833,920 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\libmfxsw32.dll
[2011/05/25 11:17:20 | 010,915,840 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\libmfxhw32.dll
[2011/05/25 11:17:20 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\GdiPlus.dll
[2011/05/25 11:17:19 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3a.dll
[2011/05/25 11:17:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2011/05/25 11:17:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2011/05/25 10:08:54 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Apple Computer
[2011/05/25 10:08:54 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Apple Computer
[2011/05/25 10:08:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/25 10:08:23 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/05/25 10:08:23 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/05/25 10:08:23 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/05/25 10:08:23 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2011/05/25 10:08:04 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/25 10:08:03 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/05/25 10:08:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/25 10:08:03 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/05/25 10:07:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/25 10:06:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/25 10:06:55 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/25 10:06:44 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Apple
[2011/05/25 10:06:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/25 10:06:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/05/25 10:06:19 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/25 10:06:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/25 10:06:11 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/25 10:06:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/25 09:23:36 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/23 22:18:31 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Ilivid Player
[2011/05/23 22:17:13 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\PackageAware
[2011/05/22 19:39:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\skypePM
[2011/05/22 19:38:42 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Skype
[2011/05/19 02:34:45 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/19 02:34:45 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/18 09:32:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/05/17 10:52:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2011/05/14 15:33:23 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2011/05/14 15:33:23 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2011/05/14 15:33:23 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2011/05/14 15:33:23 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2011/05/14 15:33:23 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2011/05/14 15:33:23 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2011/05/14 15:33:23 | 000,021,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_2.dll
[2011/05/14 15:33:23 | 000,018,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_2.dll
[2011/05/14 15:33:22 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2011/05/14 15:33:22 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2011/05/14 15:33:22 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2011/05/14 15:33:22 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2011/05/14 15:33:22 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2011/05/14 15:33:21 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2011/05/14 15:33:21 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2011/05/14 15:33:21 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2011/05/14 15:33:21 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2011/05/14 15:33:21 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2011/05/14 15:33:21 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2011/05/14 15:33:21 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2011/05/14 15:33:21 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2011/05/14 15:33:20 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2011/05/14 15:33:20 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2011/05/14 15:33:20 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2011/05/14 15:33:20 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2011/05/14 15:33:18 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2011/05/14 15:33:18 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2011/05/14 15:33:18 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2011/05/14 15:33:18 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2011/05/14 15:33:17 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2011/05/14 15:33:17 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2011/05/14 15:33:17 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2011/05/14 15:33:17 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2011/05/14 15:33:16 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2011/05/14 15:33:16 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2011/05/14 15:33:15 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2011/05/14 15:33:15 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2011/05/14 15:33:15 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2011/05/14 15:33:15 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2011/05/14 15:33:13 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2011/05/14 15:33:13 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2011/05/14 15:33:09 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2011/05/14 15:33:07 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2011/05/14 15:33:07 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2011/05/14 15:33:07 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2011/05/14 15:33:07 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2011/05/14 15:33:07 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2011/05/14 15:33:07 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2011/05/14 15:33:06 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2011/05/14 15:33:06 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2011/05/14 15:33:05 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2011/05/14 15:33:05 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2011/05/14 15:33:04 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2011/05/14 15:33:04 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2011/05/14 15:33:04 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2011/05/14 15:33:04 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2011/05/14 15:33:03 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2011/05/14 15:33:03 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2011/05/14 15:32:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/05/14 15:28:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Activision
[2011/05/14 15:20:24 | 000,254,528 | —- | C] (DT Soft Ltd) – C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011/05/14 15:20:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\DAEMON Tools Lite
[2011/05/14 15:19:42 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\DAEMON Tools Lite
[2011/05/14 15:19:42 | 000,000,000 | —D | C] – C:\ProgramData\DAEMON Tools Lite
[2011/05/14 13:06:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
[2011/05/14 03:29:01 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2011/05/14 03:29:01 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2011/05/14 03:03:58 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2011/05/14 03:03:58 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2011/05/14 03:03:58 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2011/05/14 03:03:58 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2011/05/14 03:03:58 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2011/05/14 03:03:58 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2011/05/14 03:03:58 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2011/05/14 03:03:58 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2011/05/14 03:03:45 | 000,294,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browserchoice.exe
[2011/05/13 15:48:07 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/13 15:00:42 | 000,000,000 | —D | C] – C:\ProgramData\VirtualizedApplications
[2011/05/13 14:25:11 | 000,000,000 | —D | C] – C:\Users\Francesco\Desktop\Call of duty 4 [PC-DVD] [English] [www.topetorrent.com]
[2011/05/13 14:17:34 | 000,000,000 | —D | C] – C:\Users\Francesco\Documents\The KMPlayer
[2011/05/13 14:17:18 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
[2011/05/13 14:17:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\The KMPlayer
[2011/05/13 14:11:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2011/05/13 14:11:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ConduitEngine
[2011/05/13 14:11:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitTorrentBar
[2011/05/13 14:10:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitTorrent
[2011/05/13 14:10:04 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\BitTorrent
[2011/05/13 13:01:41 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/05/13 13:01:41 | 002,614,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2011/05/13 13:01:39 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskschd.dll
[2011/05/13 13:01:39 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmicmiplugin.dll
[2011/05/13 13:01:39 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskschd.dll
[2011/05/13 13:01:39 | 000,473,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskcomp.dll
[2011/05/13 13:01:39 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskeng.exe
[2011/05/13 13:01:39 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskcomp.dll
[2011/05/13 13:01:39 | 000,285,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\schtasks.exe
[2011/05/13 13:01:39 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schtasks.exe
[2011/05/13 13:01:38 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2011/05/13 13:01:38 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/05/13 13:01:37 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sbe.dll
[2011/05/13 13:01:37 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sbe.dll
[2011/05/13 13:01:37 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2011/05/13 13:01:37 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/05/13 13:01:37 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2011/05/13 13:01:37 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2011/05/13 13:01:35 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2011/05/13 13:01:34 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/05/13 13:01:34 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/05/13 13:01:02 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/05/13 13:01:02 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/05/13 13:01:00 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/05/13 13:00:59 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/05/13 13:00:59 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/05/13 13:00:52 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/05/13 13:00:52 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/05/13 13:00:52 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/05/13 13:00:49 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/05/13 13:00:49 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/05/13 13:00:49 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/05/13 13:00:49 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\davclnt.dll
[2011/05/13 13:00:49 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/05/13 13:00:49 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/05/13 13:00:49 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/05/13 13:00:49 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/05/13 13:00:39 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/05/13 13:00:39 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/05/13 13:00:31 | 001,395,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42.dll
[2011/05/13 13:00:31 | 001,359,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42u.dll
[2011/05/13 13:00:30 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42u.dll
[2011/05/13 13:00:30 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42.dll
[2011/05/13 13:00:26 | 000,367,104 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/05/13 13:00:26 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/05/13 13:00:26 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/05/13 13:00:26 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/05/13 13:00:13 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/13 13:00:13 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/13 13:00:13 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/13 13:00:13 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/13 13:00:12 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/13 13:00:12 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/13 13:00:12 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/13 13:00:12 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/13 13:00:12 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/13 13:00:12 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/13 13:00:12 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/13 13:00:12 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/13 13:00:12 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/05/13 13:00:12 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/13 12:59:27 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/05/13 12:59:26 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/05/13 12:59:26 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/05/13 12:59:25 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/05/13 12:59:25 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/05/13 12:59:25 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/05/13 12:59:25 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/05/13 12:59:25 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/05/13 12:59:25 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/05/13 12:59:25 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/05/13 12:59:25 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/05/13 12:59:24 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/05/13 12:59:24 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/05/13 12:59:24 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/05/13 12:59:24 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/05/13 12:59:24 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/05/13 12:59:24 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/05/13 12:59:14 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2011/05/13 12:59:14 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2011/05/13 12:59:12 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnsapi.dll
[2011/05/13 12:59:12 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnscacheugc.exe
[2011/05/13 12:59:12 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dnscacheugc.exe
[2011/05/13 12:58:56 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/05/13 12:58:45 | 000,640,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2011/05/13 12:58:45 | 000,603,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2011/05/13 12:58:45 | 000,518,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2011/05/13 12:58:45 | 000,019,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kd1394.dll
[2011/05/13 12:58:44 | 000,556,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2011/05/13 12:58:44 | 000,020,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdusb.dll
[2011/05/13 12:58:44 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdcom.dll
[2011/05/13 12:58:42 | 003,138,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2011/05/13 12:58:42 | 002,690,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2011/05/13 12:58:41 | 001,097,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2011/05/13 12:58:41 | 001,034,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2011/05/13 12:58:40 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FXSCOVER.exe
[2011/05/13 12:58:40 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2011/05/13 12:58:40 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2011/05/13 12:58:38 | 002,566,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2011/05/13 12:58:37 | 001,686,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2011/05/13 12:58:37 | 000,187,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2011/05/13 12:58:37 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2011/05/13 12:58:37 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2011/05/13 12:58:36 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2011/05/13 12:58:36 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2011/05/13 12:58:32 | 000,112,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2011/05/13 12:58:26 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/05/13 12:58:26 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/05/13 12:56:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2011/05/13 12:49:12 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Mozilla
[2011/05/13 12:49:12 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Mozilla
[2011/05/13 12:49:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/05/11 11:38:09 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\SoftGrid Client
[2011/05/11 11:38:09 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\SoftGrid Client
[2011/05/11 11:37:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/05/11 11:37:29 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/05/11 11:37:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Application Virtualization Client
[2011/05/11 11:37:14 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\TP
[2011/05/10 19:35:38 | 000,000,000 | —D | C] – C:\Users\Francesco\Documents\Symantec
[2011/05/10 19:35:10 | 000,174,200 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/10 19:35:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/05/10 19:35:10 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/05/10 19:35:03 | 000,912,504 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.sys
[2011/05/10 19:35:03 | 000,744,568 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.sys
[2011/05/10 19:35:03 | 000,450,680 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.sys
[2011/05/10 19:35:03 | 000,382,584 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnets.sys
[2011/05/10 19:35:03 | 000,171,128 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\ironx64.sys
[2011/05/10 19:35:03 | 000,040,568 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.sys
[2011/05/10 19:34:50 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64\1206000.01D
[2011/05/10 19:33:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64
[2011/05/10 19:33:41 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2011/05/10 19:33:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Internet Security
[2011/05/10 19:28:23 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/05/10 19:24:55 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2011/05/10 19:24:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2011/05/10 14:13:03 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Toshiba
[2011/05/10 14:13:02 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\TOSHIBA_Corporation
[2011/05/10 14:11:45 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Nero
[2011/05/10 14:11:36 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Toshiba
[2011/05/10 14:11:15 | 000,000,000 | R–D | C] – C:\Users\Francesco\Searches
[2011/05/10 14:11:15 | 000,000,000 | R–D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/10 14:11:15 | 000,000,000 | -H-D | C] – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/10 14:11:07 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Identities
[2011/05/10 14:11:04 | 000,000,000 | R–D | C] – C:\Users\Francesco\Contacts
[2011/05/10 14:11:01 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\VirtualStore
[2011/05/10 14:10:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\BBC iPlayer Desktop
[2011/05/10 14:10:52 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Adobe
[2011/05/10 14:10:52 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Adobe
[2011/05/10 14:08:43 | 000,000,000 | —D | C] – C:\ProgramData\ToshibaEurope
[2011/05/10 14:08:26 | 000,000,000 | –SD | C] – C:\Users\Francesco\AppData\Roaming\Microsoft
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Videos
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Saved Games
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Pictures
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Music
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Links
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Favorites
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Downloads
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\My Documents
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Desktop
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\AppData\Local\Temporary Internet Files
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Templates
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Start Menu
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\SendTo
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Recent
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\PrintHood
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\NetHood
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Documents\My Videos
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Documents\My Pictures
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Documents\My Music
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\My Documents
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Local Settings
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\AppData\Local\History
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Cookies
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Application Data
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\AppData\Local\Application Data
[2011/05/10 14:08:26 | 000,000,000 | -H-D | C] – C:\Users\Francesco\AppData
[2011/05/10 14:08:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Temp
[2011/05/10 14:08:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Microsoft
[2011/05/10 14:08:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Media Center Programs
[2011/05/10 14:08:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Macromedia
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/30 08:59:48 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Francesco\Desktop\OTL(1).exe
[2011/05/30 08:36:58 | 000,016,304 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/30 08:36:58 | 000,016,304 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/30 08:29:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/30 08:29:26 | 3059,748,864 | -HS- | M] () – C:\hiberfil.sys
[2011/05/29 23:47:35 | 000,001,863 | —- | M] () – C:\Users\Francesco\Desktop\JabRef 2.6.lnk
[2011/05/29 22:13:48 | 000,002,046 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
[2011/05/28 23:06:50 | 000,002,995 | —- | M] () – C:\Users\Francesco\Desktop\HiJackThis.lnk
[2011/05/28 21:53:54 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/05/27 15:13:07 | 000,001,008 | —- | M] () – C:\Users\Public\Desktop\eMule.lnk
[2011/05/26 12:50:59 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/26 12:50:59 | 000,628,904 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/05/26 12:50:59 | 000,110,798 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/25 11:17:50 | 000,001,304 | —- | M] () – C:\Users\Francesco\Desktop\AVS4YOU Software Navigator.lnk
[2011/05/25 11:17:29 | 000,001,260 | —- | M] () – C:\Users\Francesco\Desktop\AVS Audio Converter6.lnk
[2011/05/25 10:08:23 | 001,369,628 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\Cat.DB
[2011/05/23 22:18:22 | 000,000,134 | —- | M] () – C:\Users\Public\Desktop\Get free emoticons and winks!.url
[2011/05/22 19:39:26 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2011/05/22 19:38:39 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/21 17:22:22 | 000,002,320 | —- | M] () – C:\{A940746A-CBF7-4003-BF23-D565CD49AFEB}
[2011/05/21 17:20:28 | 000,002,424 | —- | M] () – C:\{12FD8E42-4F6C-49FF-B5B9-5EC3213011E7}
[2011/05/14 15:32:51 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Call of Duty® 4 - Modern Warfare™ Singleplayer.lnk
[2011/05/14 15:32:51 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Call of Duty® 4 - Modern Warfare™ Multiplayer.lnk
[2011/05/14 15:32:29 | 000,000,331 | —- | M] () – C:\Windows\game.ini
[2011/05/14 15:20:24 | 000,254,528 | —- | M] (DT Soft Ltd) – C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011/05/14 15:20:19 | 000,001,961 | —- | M] () – C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2011/05/14 03:30:39 | 000,274,320 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/05/14 03:02:21 | 000,722,802 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/13 15:48:07 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/13 14:21:19 | 000,001,046 | —- | M] () – C:\Users\Francesco\Desktop\KMPlayer.lnk
[2011/05/13 14:16:25 | 015,103,144 | —- | M] () – C:\Users\Francesco\Desktop\kmp.exe
[2011/05/13 12:49:06 | 000,001,149 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/10 19:35:10 | 000,174,200 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/10 19:35:10 | 000,007,488 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/10 19:35:10 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/10 19:35:09 | 000,002,572 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2011/05/10 19:15:33 | 000,001,448 | —- | M] () – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/10 15:06:31 | 000,039,252 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/05/10 15:06:31 | 000,039,252 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/05/10 15:03:49 | 000,000,000 | RHS- | M] () – C:\Windows\SysWow64\drivers\TOSHIBA_Satellite C660_13769-EN_PSC0QE-01100.MRK
[2011/05/10 14:10:57 | 000,000,988 | —- | M] () – C:\Users\Public\Desktop\BBC iPlayer Desktop.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/29 23:47:35 | 000,001,863 | —- | C] () – C:\Users\Francesco\Desktop\JabRef 2.6.lnk
[2011/05/28 23:06:50 | 000,002,995 | —- | C] () – C:\Users\Francesco\Desktop\HiJackThis.lnk
[2011/05/28 21:53:54 | 000,002,021 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/05/27 15:13:07 | 000,001,008 | —- | C] () – C:\Users\Public\Desktop\eMule.lnk
[2011/05/25 11:17:50 | 000,001,304 | —- | C] () – C:\Users\Francesco\Desktop\AVS4YOU Software Navigator.lnk
[2011/05/25 11:17:29 | 000,001,260 | —- | C] () – C:\Users\Francesco\Desktop\AVS Audio Converter6.lnk
[2011/05/25 10:06:41 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/23 22:18:22 | 000,000,134 | —- | C] () – C:\Users\Public\Desktop\Get free emoticons and winks!.url
[2011/05/22 19:39:26 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/05/21 17:22:20 | 000,002,320 | —- | C] () – C:\{A940746A-CBF7-4003-BF23-D565CD49AFEB}
[2011/05/21 17:20:25 | 000,002,424 | —- | C] () – C:\{12FD8E42-4F6C-49FF-B5B9-5EC3213011E7}
[2011/05/14 15:32:51 | 000,002,014 | —- | C] () – C:\Users\Public\Desktop\Call of Duty® 4 - Modern Warfare™ Singleplayer.lnk
[2011/05/14 15:32:51 | 000,002,014 | —- | C] () – C:\Users\Public\Desktop\Call of Duty® 4 - Modern Warfare™ Multiplayer.lnk
[2011/05/14 15:32:28 | 000,000,331 | —- | C] () – C:\Windows\game.ini
[2011/05/14 15:20:19 | 000,001,961 | —- | C] () – C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2011/05/13 14:17:18 | 000,001,046 | —- | C] () – C:\Users\Francesco\Desktop\KMPlayer.lnk
[2011/05/13 14:16:05 | 015,103,144 | —- | C] () – C:\Users\Francesco\Desktop\kmp.exe
[2011/05/13 12:49:06 | 000,001,161 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/13 12:49:06 | 000,001,149 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/11 11:37:34 | 000,722,802 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/10 19:35:10 | 001,369,628 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\Cat.DB
[2011/05/10 19:35:10 | 000,007,488 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/10 19:35:10 | 000,000,855 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/10 19:35:09 | 000,002,572 | —- | C] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2011/05/10 19:35:03 | 000,007,492 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\iron.cat
[2011/05/10 19:35:03 | 000,007,462 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.cat
[2011/05/10 19:35:03 | 000,007,460 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.cat
[2011/05/10 19:35:03 | 000,007,458 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnet64.cat
[2011/05/10 19:35:03 | 000,007,458 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.cat
[2011/05/10 19:35:03 | 000,003,373 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa.inf
[2011/05/10 19:35:03 | 000,002,792 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds.inf
[2011/05/10 19:35:03 | 000,001,446 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnet.inf
[2011/05/10 19:35:03 | 000,001,438 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.inf
[2011/05/10 19:35:03 | 000,001,422 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.inf
[2011/05/10 19:35:03 | 000,000,772 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\iron.inf
[2011/05/10 19:35:03 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\isolate.ini
[2011/05/10 19:34:57 | 000,000,000 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.cat
[2011/05/10 19:15:33 | 000,001,448 | —- | C] () – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/10 15:03:49 | 000,000,000 | RHS- | C] () – C:\Windows\SysWow64\drivers\TOSHIBA_Satellite C660_13769-EN_PSC0QE-01100.MRK
[2011/05/10 14:11:18 | 000,001,454 | —- | C] () – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/10 14:10:57 | 000,001,000 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BBC iPlayer Desktop.lnk
[2011/05/10 14:10:57 | 000,000,988 | —- | C] () – C:\Users\Public\Desktop\BBC iPlayer Desktop.lnk
[2011/05/10 14:08:26 | 000,002,046 | —- | C] () – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
[2011/05/10 14:08:26 | 000,000,290 | —- | C] () – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/10 14:08:26 | 000,000,272 | —- | C] () – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/01/21 13:04:08 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2011/01/21 12:57:24 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2010/11/10 15:43:32 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/10 15:41:29 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2010/07/29 06:08:46 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/29 06:08:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/29 06:08:42 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/29 05:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/29 05:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2010/03/03 23:36:32 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\SPCtl.dll
[2009/07/14 06:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/05/30 09:11:51 | 000,000,000 | —D | M] – C:\Users\Francesco\AppData\Roaming\BitTorrent
[2011/05/14 15:24:03 | 000,000,000 | —D | M] – C:\Users\Francesco\AppData\Roaming\DAEMON Tools Lite
[2011/05/29 23:47:35 | 000,000,000 | —D | M] – C:\Users\Francesco\AppData\Roaming\JabRef 2.6
[2011/05/30 00:12:09 | 000,000,000 | —D | M] – C:\Users\Francesco\AppData\Roaming\SoftGrid Client
[2011/05/10 19:15:09 | 000,000,000 | —D | M] – C:\Users\Francesco\AppData\Roaming\Toshiba
[2011/05/11 11:38:16 | 000,000,000 | —D | M] – C:\Users\Francesco\AppData\Roaming\TP
[2011/05/26 23:10:15 | 000,000,000 | —D | M] – C:\Users\Francesco\AppData\Roaming\Windows Live Writer
[2009/07/14 06:08:49 | 000,014,322 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/14 02:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/14 02:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_1f6d6691df50b157\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.20776_none_39c28c74544f69e8\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/14 02:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 02:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\SysNative\cngaudit.dll
[2009/07/14 02:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2010/01/15 13:22:08 | 000,538,136 | —- | M] (Intel Corporation) MD5=85977CD13FC16069CE0AF7943A811775 – C:\Windows\SysNative\drivers\iaStor.sys
[2010/01/15 13:22:08 | 000,538,136 | —- | M] (Intel Corporation) MD5=85977CD13FC16069CE0AF7943A811775 – C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_5d42c6448888c5bd\iaStor.sys

< MD5 for: IASTORV.SYS >
[2010/05/12 09:37:57 | 000,410,504 | —- | M] (Intel Corporation) MD5=513DC087CFED7D2BB82F005385D3531F – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16592_none_0af87721a183cb70\iaStorV.sys
[2011/03/11 07:19:16 | 000,410,496 | —- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 07:41:26 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011/03/11 07:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\SysNative\drivers\iaStorV.sys
[2011/03/11 07:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011/03/11 07:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011/03/11 07:25:49 | 000,410,496 | —- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009/07/14 02:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 02:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
[2010/05/12 09:50:37 | 000,410,496 | —- | M] (Intel Corporation) MD5=E353CF970C5D4D6A092911E15FB78C07 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20712_none_0bd89532ba6088d9\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/14 02:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\SysNative\netlogon.dll
[2009/07/14 02:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVRAID.SYS >
[2011/03/11 07:41:34 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvraid.sys
[2009/07/14 02:48:27 | 000,149,056 | —- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvraid.sys
[2009/07/14 02:48:27 | 000,149,056 | —- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys
[2010/05/12 09:50:49 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=491E3CF1A4F0869E32197E34603B9BE1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20712_none_96a205e1f19732b1\nvraid.sys
[2011/03/11 07:19:21 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=666CA16F17914C1CD3616CF16DE0A6EA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvraid.sys
[2011/03/11 07:23:06 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=A4D9C9A608A97F59307C2F2600EDC6A4 – C:\Windows\SysNative\drivers\nvraid.sys
[2011/03/11 07:23:06 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=A4D9C9A608A97F59307C2F2600EDC6A4 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvraid.sys
[2011/03/11 07:23:06 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=A4D9C9A608A97F59307C2F2600EDC6A4 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvraid.sys
[2011/03/11 07:25:53 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=A5C82EB2F72AA004887F90B84A771F73 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvraid.sys
[2010/05/12 09:38:10 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=DEAB10231CBDB0881FC25428EBE11506 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16592_none_95c1e7d0d8ba7548\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2010/05/12 09:38:10 | 000,166,280 | —- | M] (NVIDIA Corporation) MD5=0AF7B8136794E23E87BE138992880E64 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16592_none_95c1e7d0d8ba7548\nvstor.sys
[2009/07/14 02:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 02:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011/03/11 07:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\SysNative\drivers\nvstor.sys
[2011/03/11 07:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011/03/11 07:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011/03/11 07:25:53 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2010/05/12 09:50:49 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=CE76755AF933E728CEBA6C7A970838A4 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20712_none_96a205e1f19732b1\nvstor.sys
[2011/03/11 07:19:21 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 07:41:34 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/14 02:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\SysNative\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >

< End of report >

aswMBR version 0.9.5.317 Copyright© 2011 AVAST Software
Run date: 2011-05-30 09:27:30
—————————–
09:27:30.992 OS Version: Windows x64 6.1.7600
09:27:30.992 Number of processors: 4 586 0x2505
09:27:30.992 ComputerName: FRANCESCO-TOSH UserName: Francesco
09:27:32.053 Initialize success
09:27:38.199 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:27:38.199 Disk 0 Vendor: TOSHIBA_ GH10 Size: 305245MB BusType: 3
09:27:38.230 Disk 0 MBR read successfully
09:27:38.230 Disk 0 MBR scan
09:27:38.230 Disk 0 Windows 7 default MBR code
09:27:38.230 Service scanning
09:27:39.182 Disk 0 trace - called modules:
09:27:39.182
09:27:39.182 Scan finished successfully
09:28:09.711 Disk 0 MBR has been saved successfully to "C:\Users\Francesco\Desktop\MBR.dat"
09:28:09.711 The log file has been saved successfully to "C:\Users\Francesco\Desktop\aswMBR.txt"
Hi,

Please do the following:


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
    FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
    [2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\searchplugins\SearchquWebSearch.xml
    [2011/05/23 22:18:31 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Ilivid Player
    [2011/03/23 13:24:21 | 000,005,529 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
    O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT


Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
Thank you so much, you're a genius!!!

my firefox is working as it should

Here the logs you would

All processes killed
========== OTL ==========
Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage
Prefs.js: "http://www.searchqu.com/web?src=ffb&systemid=406&q=" removed from keyword.URL
C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\searchplugins\SearchquWebSearch.xml moved successfully.
C:\Users\Francesco\AppData\Local\Ilivid Player folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Francesco\Desktop\cmd.bat deleted successfully.
C:\Users\Francesco\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 56504 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Francesco
->Flash cache emptied: 71613 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Francesco
->Temp folder emptied: 49533091 bytes
->Temporary Internet Files folder emptied: 78706763 bytes
->FireFox cache emptied: 72044206 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 27162368 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50467 bytes
RecycleBin emptied: 12042173 bytes

Total Files Cleaned = 228.00 mb


OTL by OldTimer - Version 3.2.23.0 log created on 05302011_125500

Files\Folders moved on Reboot…
C:\Users\Francesco\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…

ComboFix 11-05-29.02 - Francesco 30/05/2011 13:02:42.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.3891.2241 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
.
.
((((((((((((((((((((((((( Files Created from 2011-04-28 to 2011-05-30 )))))))))))))))))))))))))))))))
.
.
2011-05-30 12:07 . 2011-05-30 12:07 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-05-30 12:00 . 2011-05-30 12:01 ——– d—–w- C:\32788R22FWJFW
2011-05-30 11:55 . 2011-05-30 11:55 ——– d—–w- C:\_OTL
2011-05-29 12:31 . 2011-05-29 12:31 ——– d—–r- C:\MSOCache
2011-05-28 22:06 . 2011-05-28 22:06 ——– d—–w- c:\program files (x86)\Trend Micro
2011-05-27 14:13 . 2011-05-27 14:13 ——– d—–w- c:\programdata\eMule
2011-05-27 14:12 . 2011-05-27 14:12 ——– d—–w- c:\program files (x86)\eMule
2011-05-25 10:17 . 2011-05-25 10:17 ——– d—–w- c:\programdata\AVS4YOU
2011-05-25 10:17 . 2010-11-29 15:21 10833920 —-a-w- c:\windows\SysWow64\libmfxsw32.dll
2011-05-25 10:17 . 2010-11-29 15:21 10915840 —-a-w- c:\windows\SysWow64\libmfxhw32.dll
2011-05-25 10:17 . 2010-11-12 18:18 1700352 —-a-w- c:\windows\SysWow64\GdiPlus.dll
2011-05-25 10:17 . 2010-11-12 18:18 24576 —-a-w- c:\windows\SysWow64\msxml3a.dll
2011-05-25 10:17 . 2011-05-25 10:17 ——– d—–w- c:\program files (x86)\AVS4YOU
2011-05-25 10:17 . 2011-05-25 10:17 ——– d—–w- c:\program files (x86)\Common Files\AVSMedia
2011-05-25 09:08 . 2011-05-25 09:08 ——– dc—-w- c:\windows\system32\DRVSTORE
2011-05-25 09:08 . 2009-05-18 12:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-05-25 09:08 . 2008-04-17 11:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll
2011-05-25 09:06 . 2011-05-25 09:07 ——– d—–w- c:\program files (x86)\QuickTime
2011-05-25 09:06 . 2011-05-25 09:06 ——– d—–w- c:\program files (x86)\Apple Software Update
2011-05-25 09:06 . 2011-05-25 09:06 ——– d—–w- c:\program files\Common Files\Apple
2011-05-25 09:06 . 2011-05-25 09:06 ——– d—–w- c:\program files\Bonjour
2011-05-25 09:06 . 2011-05-25 09:06 ——– d—–w- c:\program files (x86)\Bonjour
2011-05-25 09:06 . 2011-05-25 09:08 ——– d—–w- c:\program files (x86)\Common Files\Apple
2011-05-25 09:06 . 2011-05-25 09:06 ——– d—–w- c:\programdata\Apple
2011-05-25 08:23 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-19 01:34 . 2011-04-09 06:58 142336 —-a-w- c:\windows\system32\poqexec.exe
2011-05-19 01:34 . 2011-04-09 05:56 123904 —-a-w- c:\windows\SysWow64\poqexec.exe
2011-05-18 08:32 . 2011-05-18 08:32 ——– d—–w- c:\program files (x86)\Microsoft.NET
2011-05-17 09:52 . 2011-05-17 09:52 ——– d—–w- c:\program files (x86)\MSXML 4.0
2011-05-14 14:38 . 2011-05-13 13:52 3017216 —-a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\Activision\Call of Duty® 4 - Modern Warfare™\iw3sp.exe
2011-05-14 14:28 . 2011-05-14 14:28 ——– d—–w- c:\program files (x86)\Activision
2011-05-14 14:20 . 2011-05-14 14:20 254528 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-14 14:20 . 2011-05-14 14:20 ——– d—–w- c:\program files (x86)\DAEMON Tools Lite
2011-05-14 14:19 . 2011-05-14 14:19 ——– d—–w- c:\programdata\DAEMON Tools Lite
2011-05-14 02:29 . 2011-05-14 02:29 ——– d—–w- c:\windows\SysWow64\Wat
2011-05-14 02:29 . 2011-05-14 02:29 ——– d—–w- c:\windows\system32\Wat
2011-05-14 02:11 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll
2011-05-14 02:11 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll
2011-05-14 02:03 . 2009-11-25 11:47 99176 —-a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-05-14 02:03 . 2009-11-25 11:47 49472 —-a-w- c:\windows\SysWow64\netfxperf.dll
2011-05-14 02:03 . 2009-11-25 11:47 48960 —-a-w- c:\windows\system32\netfxperf.dll
2011-05-14 02:03 . 2009-11-25 11:47 297808 —-a-w- c:\windows\SysWow64\mscoree.dll
2011-05-14 02:03 . 2009-11-25 11:47 295264 —-a-w- c:\windows\SysWow64\PresentationHost.exe
2011-05-14 02:03 . 2009-11-25 11:47 1130824 —-a-w- c:\windows\SysWow64\dfshim.dll
2011-05-14 02:03 . 2009-11-25 11:47 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2011-05-14 02:03 . 2009-11-25 11:47 444752 —-a-w- c:\windows\system32\mscoree.dll
2011-05-14 02:03 . 2009-11-25 11:47 320352 —-a-w- c:\windows\system32\PresentationHost.exe
2011-05-14 02:03 . 2009-11-25 11:47 1942856 —-a-w- c:\windows\system32\dfshim.dll
2011-05-14 02:03 . 2010-02-23 08:16 294912 —-a-w- c:\windows\system32\browserchoice.exe
2011-05-13 14:48 . 2011-05-13 14:48 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-05-13 14:00 . 2011-05-14 12:06 ——– d—–w- c:\programdata\VirtualizedApplications
2011-05-13 13:17 . 2011-05-13 13:17 ——– d—–w- c:\program files (x86)\The KMPlayer
2011-05-13 13:11 . 2011-05-13 13:11 ——– d—–w- c:\program files (x86)\Conduit
2011-05-13 13:10 . 2011-05-13 13:10 ——– d—–w- c:\program files (x86)\BitTorrent
2011-05-13 12:00 . 2011-04-09 06:13 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-05-13 11:59 . 2010-12-21 06:16 214016 —-a-w- c:\windows\system32\winsrv.dll
2011-05-13 11:58 . 2010-10-27 05:16 1739176 —-a-w- c:\windows\system32\ntdll.dll
2011-05-13 11:56 . 2011-05-13 11:56 ——– d—–w- c:\program files (x86)\Common Files\Symantec Shared
2011-05-11 10:37 . 2011-05-14 02:02 ——– d—–w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-05-10 18:35 . 2011-05-10 18:35 174200 —-a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-05-10 18:35 . 2011-05-10 18:35 ——– d—–w- c:\program files\Symantec
2011-05-10 18:35 . 2011-05-10 18:35 ——– d—–w- c:\program files\Common Files\Symantec Shared
2011-05-10 18:33 . 2011-05-10 18:35 ——– d—–w- c:\windows\system32\drivers\NISx64
2011-05-10 18:33 . 2011-05-10 18:33 ——– d—–w- c:\program files (x86)\Norton Internet Security
2011-05-10 18:28 . 2011-05-10 18:33 ——– d—–w- c:\programdata\Norton
2011-05-10 18:24 . 2011-05-10 18:35 ——– d—–w- c:\program files (x86)\NortonInstaller
2011-05-10 13:10 . 2011-05-10 13:10 ——– d—–w- c:\program files (x86)\BBC iPlayer Desktop
2011-05-10 13:08 . 2011-05-10 13:08 ——– d—–w- c:\programdata\ToshibaEurope
2011-05-10 13:08 . 2011-05-10 13:11 ——– d—–w- c:\users\Francesco
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-10 20:19 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-04-06 15:26 . 2011-04-06 15:26 96544 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:26 . 2011-04-06 15:26 69408 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:26 . 2011-04-06 15:26 237856 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:26 . 2011-04-06 15:26 119584 —-a-w- c:\windows\system32\dns-sd.exe
2011-04-06 15:20 . 2011-04-06 15:20 91424 —-a-w- c:\windows\SysWow64\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20 75040 —-a-w- c:\windows\SysWow64\jdns_sd.dll
2011-04-06 15:20 . 2011-04-06 15:20 197920 —-a-w- c:\windows\SysWow64\dnssdX.dll
2011-04-06 15:20 . 2011-04-06 15:20 107808 —-a-w- c:\windows\SysWow64\dns-sd.exe
2011-03-04 06:17 . 2011-05-14 11:42 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:17 . 2011-05-14 11:42 347648 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files (x86)\BitTorrentBar\tbBitT.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 —-a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2010-12-09 11:51 3911776 —-a-w- c:\program files (x86)\BitTorrentBar\tbBitT.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files (x86)\BitTorrentBar\tbBitT.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-09-02 1234216]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-03-03 352256]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-15 34160]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-05-01 2454840]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-27 421160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-05-11 124368]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20110518.001\BHDrvx64.sys [2011-04-19 1127032]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20110527.001\IDSvia64.sys [2011-03-15 476792]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\NISx64\1206000.01D\SYMNETS.SYS [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2010-08-27 1811456]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\McSACore.exe [2011-02-16 101048]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688]
S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-11 136824]
S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768]
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
.
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-05-11 1050072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-10 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-10 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-10 415256]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-28 11101800]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-07-28 2120808]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-05-30 13:08:50
ComboFix-quarantined-files.txt 2011-05-30 12:08
.
Pre-Run: 98,788,421,632 bytes free
Post-Run: 98,671,976,448 bytes free
.
- - End Of File - - 5EECD47AFF92DC433AAD951C8E39C271
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Hi! I've done as you said. ESET didn't found any threat so any log of threats has been produced at the eend of the scan. I can post only this log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6730 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 31/05/2011 11:02:02 mbam-log-2011-05-31 (11-02-02).txt Scan type: Quick scan Objects scanned: 161152 Time elapsed: 1 minute(s), 57 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\francesco\downloads\xvidsetup.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
Please do the following.

Visit ADOBEand download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java Runtime Environment (JRE) 6 Update 25 The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the Download button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement
  • Click Continue The page will refresh.
  • Click on the link to download Windows Offline Installation and Save the file to your Desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start(or My Computer) > Control Panel and double-click on Add or Remove Programs and remove all older versions of Java.
  • Click (highlight) any item with Java Runtime Environment (JRE, J2SE, Java™ SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u25-windows-i586-p.exe to install the newest version.
  • After the install is complete, go back to your Control Panel(using Classic View) and click the Java icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button.
    • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
    • Trace and Log Files
  • Click OK on Delete Temporary Files Window. Note: This deletes ALL the Downloaded Applications and Applets from the CACHE
  • Click OK to leave the Temporary Files Window.
  • Click OK to leave the Java Control Panel.
  • Delete jre-6u25-windows-i586-p.exe from your desktop.


NEXT
Please post a fresh OTL log and advise how the computer is running now and if there are any outstanding issues
I have updated acrobat and Java
this is the OTL post

OTL logfile created on: 6/3/2011 11:50:39 AM - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Francesco\Desktop\software
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.80 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 59.91% Memory free
7.60 Gb Paging File | 5.95 Gb Available in Paging File | 78.34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.04 Gb Total Space | 86.53 Gb Free Space | 58.05% Space Free | Partition Type: NTFS
Drive D: | 148.65 Gb Total Space | 140.70 Gb Free Space | 94.65% Space Free | Partition Type: NTFS

Computer Name: FRANCESCO-TOSH | User Name: Francesco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/30 08:59:48 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Francesco\Desktop\software\OTL(1).exe
PRC - [2011/04/17 01:45:11 | 000,130,008 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe
PRC - [2011/04/14 17:25:41 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/01/20 10:20:12 | 001,305,408 | —- | M] (DT Soft Ltd) – C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2010/09/02 19:25:46 | 001,234,216 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
PRC - [2010/08/27 18:20:14 | 001,811,456 | —- | M] (Realsil Microelectronics Inc.) – C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
PRC - [2010/08/15 20:54:50 | 000,034,160 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
PRC - [2010/06/03 17:09:00 | 000,304,560 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2010/05/04 13:07:22 | 000,503,080 | —- | M] (Nero AG) – c:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010/05/01 17:55:36 | 002,454,840 | —- | M] (TOSHIBA CORPORATION.) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
PRC - [2010/04/24 01:10:34 | 000,209,768 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/04/24 01:10:28 | 000,483,688 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/03/03 15:42:02 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/03 15:41:58 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/07/28 21:26:42 | 000,062,848 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009/03/10 19:51:20 | 000,046,448 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe


========== Modules (SafeList) ==========

MOD - [2011/05/30 08:59:48 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Francesco\Desktop\software\OTL(1).exe
MOD - [2011/04/08 16:56:28 | 000,018,176 | —- | M] (McAfee, Inc.) – c:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll
MOD - [2010/08/21 06:21:32 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/09/28 13:30:28 | 000,489,384 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe – (TosCoSrv)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/02/05 18:44:48 | 000,137,560 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe – (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2009/07/28 15:48:06 | 000,140,632 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\SysNative\TODDSrv.exe – (TODDSrv)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/04/17 01:45:11 | 000,130,008 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe – (NIS)
SRV - [2011/02/16 15:49:08 | 000,101,048 | —- | M] (McAfee, Inc.) [Auto | Running] – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe – (McAfee SiteAdvisor Service)
SRV - [2010/08/27 18:20:14 | 001,811,456 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2010/07/28 22:36:52 | 000,246,520 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [2010/05/11 10:40:52 | 000,124,368 | —- | M] (Toshiba Europe GmbH) [On_Demand | Stopped] – C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe – (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO)
SRV - [2010/05/04 13:07:22 | 000,503,080 | —- | M] (Nero AG) [Auto | Running] – c:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate)
SRV - [2010/04/24 01:10:34 | 000,209,768 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe – (sftvsa)
SRV - [2010/04/24 01:10:28 | 000,483,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe – (sftlist)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/03 15:42:02 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/03/03 15:41:58 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2010/01/28 17:44:40 | 000,249,200 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe – (cfWiMAXService)
SRV - [2009/10/06 10:21:50 | 000,051,512 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe – (TMachInfo)
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/03/10 19:51:20 | 000,046,448 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe – (ConfigFree Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/05/14 15:20:24 | 000,254,528 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV:64bit: - [2011/05/10 19:35:10 | 000,174,200 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2011/03/31 04:00:09 | 000,744,568 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.sys – (SRTSP)
DRV:64bit: - [2011/03/31 04:00:09 | 000,040,568 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.sys – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2011/03/22 01:39:49 | 000,382,584 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnets.sys – (SymNetS)
DRV:64bit: - [2011/03/15 03:31:23 | 000,912,504 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.sys – (SymEFA)
DRV:64bit: - [2011/03/11 07:22:41 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 07:22:40 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/27 07:47:10 | 000,450,680 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.sys – (SymDS)
DRV:64bit: - [2011/01/21 12:52:00 | 000,020,592 | —- | M] (Compal Electronics, INC.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CeKbFilter.sys – (CeKbFilter)
DRV:64bit: - [2010/11/16 02:45:33 | 000,171,128 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1206000.01D\ironx64.sys – (SymIRON)
DRV:64bit: - [2010/10/05 22:23:18 | 007,884,288 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2010/10/05 21:15:14 | 000,285,696 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2010/07/29 06:10:42 | 010,610,400 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/06/23 16:10:56 | 000,344,680 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010/04/28 12:32:20 | 000,932,384 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\rtl8192ce.sys – (RTL8192Ce)
DRV:64bit: - [2010/04/24 01:10:32 | 000,022,376 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftvollh.sys – (Sftvol)
DRV:64bit: - [2010/04/24 01:10:28 | 000,269,672 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftplaylh.sys – (Sftplay)
DRV:64bit: - [2010/04/24 01:10:28 | 000,025,960 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftredirlh.sys – (Sftredir)
DRV:64bit: - [2010/04/24 01:10:20 | 000,721,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftfslh.sys – (Sftfs)
DRV:64bit: - [2010/03/22 11:55:20 | 000,046,192 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\LPCFilter.sys – (LPCFilter)
DRV:64bit: - [2010/03/10 19:51:32 | 000,316,464 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2010/02/27 08:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2010/01/15 13:22:08 | 000,538,136 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/01/07 10:05:46 | 000,232,992 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/09/17 13:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/30 20:22:04 | 000,027,784 | —- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\tdcmdpst.sys – (tdcmdpst)
DRV:64bit: - [2009/07/14 16:31:18 | 000,026,840 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\TVALZ_O.SYS – (TVALZ)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/22 18:06:38 | 000,035,008 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\PGEffect.sys – (PGEffect)
DRV:64bit: - [2009/06/10 21:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2011/05/18 09:49:22 | 002,011,768 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110602.034\EX64.SYS – (NAVEX15)
DRV - [2011/05/18 09:49:22 | 000,117,880 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110602.034\ENG64.SYS – (NAVENG)
DRV - [2011/05/11 11:47:39 | 000,481,912 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2011/05/11 11:47:39 | 000,136,824 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/04/19 01:35:53 | 001,127,032 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20110518.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2011/03/15 03:29:00 | 000,476,792 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20110602.001\IDSviA64.sys – (IDSVia64)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPlgn\ [2011/05/10 19:35:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn\ [2011/05/10 19:34:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/05/25 09:22:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/25 10:07:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/05/29 22:11:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Francesco\AppData\Roaming\Mozilla\Extensions
[2011/05/29 22:07:05 | 000,000,000 | —D | M] (No name found) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions
[2011/05/13 14:11:11 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/05/13 14:11:11 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions\[removed]
[2011/05/29 12:46:34 | 000,000,000 | —D | M] (Diccionario de Español/España) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions\[removed]
[2011/05/29 12:53:29 | 000,000,000 | —D | M] (Dizionario italiano) – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\extensions\[removed]
[2011/05/13 14:11:11 | 000,000,863 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\searchplugins\conduit.xml
[2011/05/13 12:49:54 | 000,002,472 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Mozilla\Firefox\Profiles\0qmp24dp.default\searchplugins\safesearch.xml
[2011/06/03 11:43:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/03 11:43:14 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) –
[2011/05/25 09:22:25 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2011/05/10 19:34:50 | 000,000,000 | —D | M] (Norton Toolbar) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN
[2011/05/10 19:35:14 | 000,000,000 | —D | M] (Symantec IPS) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPLGN
() (No name found) – C:\USERS\FRANCESCO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0QMP24DP.DEFAULT\EXTENSIONS\[removed]
[2011/04/14 17:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/05/30 13:07:20 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [NBAgent] c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] C:\Program Files (x86)\Electronic Arts\EADM\Core.exe (Electronic Arts)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] File not found
O4 - Startup: C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FIFA 11 Registration.lnk = C:\Program Files (x86)\EA Sports\FIFA 11\Support\EAregister.exe (Leader Technologies)
O4 - Startup: C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/03 11:43:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/06/03 11:43:12 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/06/03 11:43:12 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/06/03 11:43:12 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/06/03 11:38:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/06/02 13:12:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2011/06/01 19:16:22 | 000,000,000 | —D | C] – C:\ProgramData\Electronic Arts
[2011/06/01 13:52:00 | 000,000,000 | —D | C] – C:\Users\Francesco\Documents\FIFA 11
[2011/06/01 13:48:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Electronic Arts
[2011/06/01 13:48:03 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Leadertech
[2011/06/01 13:44:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\EA Sports
[2011/06/01 13:44:06 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_41.dll
[2011/06/01 13:44:06 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_41.dll
[2011/06/01 13:44:06 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_41.dll
[2011/06/01 13:44:06 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_41.dll
[2011/06/01 13:44:05 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_40.dll
[2011/06/01 13:44:05 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_40.dll
[2011/06/01 13:44:05 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_4.dll
[2011/06/01 13:44:05 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_40.dll
[2011/06/01 13:44:05 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_4.dll
[2011/06/01 13:44:05 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_40.dll
[2011/06/01 13:44:05 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_4.dll
[2011/06/01 13:44:05 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_4.dll
[2011/06/01 13:44:05 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_3.dll
[2011/06/01 13:44:05 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_6.dll
[2011/06/01 13:44:05 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_6.dll
[2011/06/01 13:44:04 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_40.dll
[2011/06/01 13:44:03 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_3.dll
[2011/06/01 13:44:03 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_3.dll
[2011/06/01 13:44:03 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_2.dll
[2011/06/01 13:44:03 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2011/06/01 13:44:03 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_2.dll
[2011/06/01 13:44:03 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_3.dll
[2011/06/01 13:44:03 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_2.dll
[2011/06/01 13:44:03 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_3.dll
[2011/06/01 13:44:03 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_2.dll
[2011/06/01 13:44:03 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_1.dll
[2011/06/01 13:44:03 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_2.dll
[2011/06/01 13:44:03 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2011/06/01 13:44:03 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_5.dll
[2011/06/01 13:44:03 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_5.dll
[2011/06/01 13:44:02 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll
[2011/06/01 13:44:02 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2011/06/01 13:44:02 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2011/06/01 13:44:02 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2011/06/01 13:44:02 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2011/06/01 13:44:02 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2011/06/01 13:44:02 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2011/06/01 13:44:02 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2011/06/01 13:44:02 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2011/06/01 13:44:02 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2011/06/01 13:44:02 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2011/06/01 13:44:02 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2011/06/01 13:44:02 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2011/06/01 13:44:02 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2011/06/01 13:44:01 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2011/06/01 13:44:01 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2011/06/01 13:44:01 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2011/06/01 13:44:01 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2011/06/01 13:44:01 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2011/06/01 13:44:01 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2011/06/01 13:44:01 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2011/06/01 13:44:01 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2011/06/01 13:44:01 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2011/06/01 13:44:01 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2011/06/01 13:44:00 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2011/06/01 13:44:00 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2011/06/01 13:44:00 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2011/06/01 13:44:00 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2011/06/01 13:44:00 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2011/06/01 13:44:00 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2011/06/01 13:44:00 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2011/06/01 13:44:00 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2011/06/01 13:43:59 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2011/06/01 13:43:59 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2011/06/01 13:43:59 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2011/06/01 13:43:59 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2011/06/01 13:43:59 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2011/06/01 13:43:59 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2011/06/01 13:43:59 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2011/06/01 13:43:59 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2011/06/01 13:43:58 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2011/06/01 13:43:58 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2011/06/01 13:43:58 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2011/06/01 13:43:58 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2011/06/01 13:43:58 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2011/06/01 13:43:58 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2011/06/01 13:43:57 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2011/06/01 13:43:57 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2011/06/01 13:43:57 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2011/06/01 13:43:57 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2011/06/01 13:43:57 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2011/06/01 13:32:47 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Diagnostics
[2011/05/31 15:00:59 | 000,000,000 | —D | C] – C:\Users\Francesco\Desktop\parte 1 prova scritta
[2011/05/31 11:39:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/05/31 10:59:12 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Malwarebytes
[2011/05/31 10:58:51 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/31 10:58:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/31 10:58:51 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/31 10:58:48 | 000,024,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/05/31 10:58:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/05/30 15:26:48 | 000,000,000 | R–D | C] – C:\Users\Francesco\Desktop\software
[2011/05/30 13:18:58 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/30 13:08:52 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/05/30 13:01:59 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/05/30 13:01:59 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/05/30 13:01:59 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/05/30 13:01:52 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/05/30 13:00:57 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/30 13:00:50 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2011/05/30 12:55:00 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/30 09:32:02 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/05/29 23:47:35 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JabRef
[2011/05/29 23:47:34 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\JabRef 2.6
[2011/05/29 13:31:25 | 000,000,000 | R–D | C] – C:\MSOCache
[2011/05/28 23:06:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/05/28 23:06:50 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/05/27 15:13:44 | 000,000,000 | —D | C] – C:\ProgramData\eMule
[2011/05/27 15:12:52 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\eMule
[2011/05/27 15:12:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eMule
[2011/05/27 15:12:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\eMule
[2011/05/26 23:10:43 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Windows Live
[2011/05/26 23:10:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\{BB525367-5BD2-4E07-BC87-8244094814CD}
[2011/05/26 23:10:15 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Windows Live Writer
[2011/05/26 23:10:15 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Windows Live Writer
[2011/05/25 11:17:59 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2011/05/25 11:17:57 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\AVS4YOU
[2011/05/25 11:17:48 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2011/05/25 11:17:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2011/05/25 11:17:22 | 010,833,920 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\libmfxsw32.dll
[2011/05/25 11:17:20 | 010,915,840 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\libmfxhw32.dll
[2011/05/25 11:17:20 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\GdiPlus.dll
[2011/05/25 11:17:19 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3a.dll
[2011/05/25 11:17:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2011/05/25 11:17:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2011/05/25 10:08:54 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Apple Computer
[2011/05/25 10:08:54 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Apple Computer
[2011/05/25 10:08:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/25 10:08:23 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/05/25 10:08:23 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/05/25 10:08:23 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/05/25 10:08:23 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2011/05/25 10:08:04 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/25 10:08:03 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/05/25 10:08:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/25 10:08:03 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/05/25 10:07:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/25 10:06:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/25 10:06:55 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/25 10:06:44 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Apple
[2011/05/25 10:06:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/25 10:06:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/05/25 10:06:19 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/25 10:06:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/25 10:06:11 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/25 10:06:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/25 09:23:36 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/23 22:17:13 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\PackageAware
[2011/05/22 19:39:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\skypePM
[2011/05/22 19:38:42 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Skype
[2011/05/19 02:34:45 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/19 02:34:45 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/18 09:32:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/05/17 10:52:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2011/05/14 15:33:23 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2011/05/14 15:33:23 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2011/05/14 15:33:23 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2011/05/14 15:33:23 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2011/05/14 15:33:22 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2011/05/14 15:33:22 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2011/05/14 15:33:22 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2011/05/14 15:33:22 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2011/05/14 15:33:22 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2011/05/14 15:33:21 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2011/05/14 15:33:21 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2011/05/14 15:33:21 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2011/05/14 15:33:21 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2011/05/14 15:33:21 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2011/05/14 15:33:21 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2011/05/14 15:33:21 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2011/05/14 15:33:21 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2011/05/14 15:33:20 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2011/05/14 15:33:20 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2011/05/14 15:33:20 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2011/05/14 15:33:20 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2011/05/14 15:33:18 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2011/05/14 15:33:18 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2011/05/14 15:33:18 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2011/05/14 15:33:18 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2011/05/14 15:33:17 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2011/05/14 15:33:17 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2011/05/14 15:33:17 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2011/05/14 15:33:17 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2011/05/14 15:33:16 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2011/05/14 15:33:16 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2011/05/14 15:33:15 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2011/05/14 15:33:15 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2011/05/14 15:33:15 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2011/05/14 15:33:15 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2011/05/14 15:33:13 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2011/05/14 15:33:13 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2011/05/14 15:33:09 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2011/05/14 15:33:07 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2011/05/14 15:33:07 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2011/05/14 15:33:07 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2011/05/14 15:33:07 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2011/05/14 15:33:07 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2011/05/14 15:33:07 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2011/05/14 15:33:06 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2011/05/14 15:33:06 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2011/05/14 15:33:05 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2011/05/14 15:33:05 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2011/05/14 15:33:04 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2011/05/14 15:33:04 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2011/05/14 15:33:04 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2011/05/14 15:33:04 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2011/05/14 15:33:03 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2011/05/14 15:33:03 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2011/05/14 15:32:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/05/14 15:28:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Activision
[2011/05/14 15:20:24 | 000,254,528 | —- | C] (DT Soft Ltd) – C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011/05/14 15:20:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\DAEMON Tools Lite
[2011/05/14 15:19:42 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\DAEMON Tools Lite
[2011/05/14 15:19:42 | 000,000,000 | —D | C] – C:\ProgramData\DAEMON Tools Lite
[2011/05/14 13:06:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
[2011/05/14 03:29:01 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2011/05/14 03:29:01 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2011/05/14 03:03:58 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2011/05/14 03:03:58 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2011/05/14 03:03:58 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2011/05/14 03:03:58 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2011/05/14 03:03:58 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2011/05/14 03:03:58 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2011/05/14 03:03:58 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2011/05/14 03:03:58 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2011/05/14 03:03:45 | 000,294,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browserchoice.exe
[2011/05/13 15:48:07 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/13 15:00:42 | 000,000,000 | —D | C] – C:\ProgramData\VirtualizedApplications
[2011/05/13 14:25:11 | 000,000,000 | —D | C] – C:\Users\Francesco\Desktop\Call of duty 4 [PC-DVD] [English] [www.topetorrent.com]
[2011/05/13 14:17:34 | 000,000,000 | —D | C] – C:\Users\Francesco\Documents\The KMPlayer
[2011/05/13 14:17:18 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
[2011/05/13 14:17:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\The KMPlayer
[2011/05/13 14:11:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2011/05/13 14:11:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ConduitEngine
[2011/05/13 14:11:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitTorrentBar
[2011/05/13 14:10:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitTorrent
[2011/05/13 14:10:04 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\BitTorrent
[2011/05/13 13:01:41 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/05/13 13:01:41 | 002,614,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2011/05/13 13:01:39 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskschd.dll
[2011/05/13 13:01:39 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmicmiplugin.dll
[2011/05/13 13:01:39 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskschd.dll
[2011/05/13 13:01:39 | 000,473,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskcomp.dll
[2011/05/13 13:01:39 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskeng.exe
[2011/05/13 13:01:39 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskcomp.dll
[2011/05/13 13:01:39 | 000,285,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\schtasks.exe
[2011/05/13 13:01:39 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schtasks.exe
[2011/05/13 13:01:38 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2011/05/13 13:01:38 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/05/13 13:01:37 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sbe.dll
[2011/05/13 13:01:37 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sbe.dll
[2011/05/13 13:01:37 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2011/05/13 13:01:37 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/05/13 13:01:37 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2011/05/13 13:01:37 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2011/05/13 13:01:35 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2011/05/13 13:01:34 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/05/13 13:01:34 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/05/13 13:01:02 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/05/13 13:01:02 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/05/13 13:01:00 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/05/13 13:00:59 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/05/13 13:00:59 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/05/13 13:00:52 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/05/13 13:00:52 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/05/13 13:00:52 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/05/13 13:00:49 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/05/13 13:00:49 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/05/13 13:00:49 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/05/13 13:00:49 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\davclnt.dll
[2011/05/13 13:00:49 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/05/13 13:00:49 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/05/13 13:00:49 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/05/13 13:00:49 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/05/13 13:00:39 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/05/13 13:00:39 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/05/13 13:00:31 | 001,395,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42.dll
[2011/05/13 13:00:31 | 001,359,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42u.dll
[2011/05/13 13:00:30 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42u.dll
[2011/05/13 13:00:30 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42.dll
[2011/05/13 13:00:26 | 000,367,104 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/05/13 13:00:26 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/05/13 13:00:26 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/05/13 13:00:26 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/05/13 13:00:13 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/13 13:00:13 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/13 13:00:13 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/13 13:00:13 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/13 13:00:12 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/13 13:00:12 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/13 13:00:12 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/13 13:00:12 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/13 13:00:12 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/13 13:00:12 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/13 13:00:12 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/13 13:00:12 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/13 13:00:12 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/05/13 13:00:12 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/13 12:59:27 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/05/13 12:59:26 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/05/13 12:59:26 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/05/13 12:59:25 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/05/13 12:59:25 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/05/13 12:59:25 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/05/13 12:59:25 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/05/13 12:59:25 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/05/13 12:59:25 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/05/13 12:59:25 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/05/13 12:59:25 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/05/13 12:59:24 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/05/13 12:59:24 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/05/13 12:59:24 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/05/13 12:59:24 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/05/13 12:59:24 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/05/13 12:59:24 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/05/13 12:59:14 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2011/05/13 12:59:14 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2011/05/13 12:59:12 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnsapi.dll
[2011/05/13 12:59:12 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnscacheugc.exe
[2011/05/13 12:59:12 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dnscacheugc.exe
[2011/05/13 12:58:56 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/05/13 12:58:45 | 000,640,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2011/05/13 12:58:45 | 000,603,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2011/05/13 12:58:45 | 000,518,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2011/05/13 12:58:45 | 000,019,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kd1394.dll
[2011/05/13 12:58:44 | 000,556,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2011/05/13 12:58:44 | 000,020,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdusb.dll
[2011/05/13 12:58:44 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdcom.dll
[2011/05/13 12:58:42 | 003,138,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2011/05/13 12:58:42 | 002,690,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2011/05/13 12:58:41 | 001,097,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2011/05/13 12:58:41 | 001,034,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2011/05/13 12:58:40 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FXSCOVER.exe
[2011/05/13 12:58:40 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2011/05/13 12:58:40 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2011/05/13 12:58:38 | 002,566,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2011/05/13 12:58:37 | 001,686,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2011/05/13 12:58:37 | 000,187,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2011/05/13 12:58:37 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2011/05/13 12:58:37 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2011/05/13 12:58:36 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2011/05/13 12:58:36 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2011/05/13 12:58:32 | 000,112,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2011/05/13 12:58:26 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/05/13 12:58:26 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/05/13 12:56:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2011/05/13 12:49:12 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Mozilla
[2011/05/13 12:49:12 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Mozilla
[2011/05/13 12:49:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/05/11 11:38:09 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\SoftGrid Client
[2011/05/11 11:38:09 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\SoftGrid Client
[2011/05/11 11:37:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/05/11 11:37:29 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/05/11 11:37:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Application Virtualization Client
[2011/05/11 11:37:14 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\TP
[2011/05/10 19:35:38 | 000,000,000 | —D | C] – C:\Users\Francesco\Documents\Symantec
[2011/05/10 19:35:10 | 000,174,200 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/10 19:35:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/05/10 19:35:10 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/05/10 19:35:03 | 000,912,504 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.sys
[2011/05/10 19:35:03 | 000,744,568 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.sys
[2011/05/10 19:35:03 | 000,450,680 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.sys
[2011/05/10 19:35:03 | 000,382,584 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnets.sys
[2011/05/10 19:35:03 | 000,171,128 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\ironx64.sys
[2011/05/10 19:35:03 | 000,040,568 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.sys
[2011/05/10 19:34:50 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64\1206000.01D
[2011/05/10 19:33:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64
[2011/05/10 19:33:41 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2011/05/10 19:33:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Internet Security
[2011/05/10 19:28:23 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/05/10 19:24:55 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2011/05/10 19:24:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2011/05/10 14:13:03 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Toshiba
[2011/05/10 14:13:02 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\TOSHIBA_Corporation
[2011/05/10 14:11:45 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Nero
[2011/05/10 14:11:36 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Toshiba
[2011/05/10 14:11:15 | 000,000,000 | R–D | C] – C:\Users\Francesco\Searches
[2011/05/10 14:11:15 | 000,000,000 | R–D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/10 14:11:15 | 000,000,000 | -H-D | C] – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/10 14:11:07 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Identities
[2011/05/10 14:11:04 | 000,000,000 | R–D | C] – C:\Users\Francesco\Contacts
[2011/05/10 14:11:01 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\VirtualStore
[2011/05/10 14:10:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\BBC iPlayer Desktop
[2011/05/10 14:10:52 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Adobe
[2011/05/10 14:10:52 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Adobe
[2011/05/10 14:08:43 | 000,000,000 | —D | C] – C:\ProgramData\ToshibaEurope
[2011/05/10 14:08:26 | 000,000,000 | –SD | C] – C:\Users\Francesco\AppData\Roaming\Microsoft
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Videos
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Saved Games
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Pictures
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Music
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Links
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Favorites
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Downloads
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\My Documents
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\Desktop
[2011/05/10 14:08:26 | 000,000,000 | R–D | C] – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\AppData\Local\Temporary Internet Files
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Templates
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Start Menu
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\SendTo
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Recent
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\PrintHood
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\NetHood
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Documents\My Videos
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Documents\My Pictures
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Documents\My Music
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\My Documents
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Local Settings
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\AppData\Local\History
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Cookies
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\Application Data
[2011/05/10 14:08:26 | 000,000,000 | -HSD | C] – C:\Users\Francesco\AppData\Local\Application Data
[2011/05/10 14:08:26 | 000,000,000 | -H-D | C] – C:\Users\Francesco\AppData
[2011/05/10 14:08:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Temp
[2011/05/10 14:08:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Local\Microsoft
[2011/05/10 14:08:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Media Center Programs
[2011/05/10 14:08:26 | 000,000,000 | —D | C] – C:\Users\Francesco\AppData\Roaming\Macromedia

========== Files - Modified Within 30 Days ==========

[2011/06/03 11:49:50 | 000,016,304 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/03 11:49:50 | 000,016,304 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/03 11:43:01 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2011/06/03 11:43:01 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/06/03 11:43:01 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/06/03 11:43:01 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/06/03 11:41:58 | 000,002,046 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
[2011/06/03 11:41:17 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/03 11:41:11 | 3059,748,864 | -HS- | M] () – C:\hiberfil.sys
[2011/06/03 11:39:00 | 000,002,026 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/03 08:45:39 | 000,274,320 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/01 13:48:23 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\EA Download Manager.lnk
[2011/06/01 13:48:14 | 000,001,401 | —- | M] () – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FIFA 11 Registration.lnk
[2011/06/01 11:41:36 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/01 11:41:36 | 000,628,904 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/01 11:41:36 | 000,110,798 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/31 10:58:51 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/30 13:07:20 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/05/30 09:31:54 | 629,393,790 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/05/25 10:08:23 | 001,369,628 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\Cat.DB
[2011/05/22 19:39:26 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2011/05/22 19:38:39 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/21 17:22:22 | 000,002,320 | —- | M] () – C:\{A940746A-CBF7-4003-BF23-D565CD49AFEB}
[2011/05/21 17:20:28 | 000,002,424 | —- | M] () – C:\{12FD8E42-4F6C-49FF-B5B9-5EC3213011E7}
[2011/05/14 15:32:29 | 000,000,331 | —- | M] () – C:\Windows\game.ini
[2011/05/14 15:20:24 | 000,254,528 | —- | M] (DT Soft Ltd) – C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011/05/14 03:02:21 | 000,722,802 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/13 15:48:07 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/13 14:21:19 | 000,001,046 | —- | M] () – C:\Users\Francesco\Desktop\KMPlayer.lnk
[2011/05/13 12:49:06 | 000,001,149 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/10 19:35:10 | 000,174,200 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/10 19:35:10 | 000,007,488 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/10 19:35:10 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/10 19:35:09 | 000,002,572 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2011/05/10 19:15:33 | 000,001,448 | —- | M] () – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/10 15:06:31 | 000,039,252 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/05/10 15:06:31 | 000,039,252 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/05/10 15:03:49 | 000,000,000 | RHS- | M] () – C:\Windows\SysWow64\drivers\TOSHIBA_Satellite C660_13769-EN_PSC0QE-01100.MRK

========== Files Created - No Company Name ==========

[2011/06/03 11:39:00 | 000,002,026 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/03 11:38:59 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/02 13:13:15 | 000,002,543 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft PowerPoint Viewer .lnk
[2011/06/01 13:48:23 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\EA Download Manager.lnk
[2011/06/01 13:48:22 | 000,001,154 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Download Manager.lnk
[2011/06/01 13:48:14 | 000,001,401 | —- | C] () – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FIFA 11 Registration.lnk
[2011/05/31 10:58:51 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/31 10:46:30 | 000,000,044 | —- | C] () – C:\Users\Francesco\Desktop\Track08.cda
[2011/05/30 13:01:59 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/05/30 13:01:59 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/05/30 13:01:59 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/05/30 13:01:59 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/05/30 13:01:59 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/05/30 09:31:54 | 629,393,790 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/05/25 10:06:41 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/22 19:39:26 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/05/21 17:22:20 | 000,002,320 | —- | C] () – C:\{A940746A-CBF7-4003-BF23-D565CD49AFEB}
[2011/05/21 17:20:25 | 000,002,424 | —- | C] () – C:\{12FD8E42-4F6C-49FF-B5B9-5EC3213011E7}
[2011/05/14 15:32:28 | 000,000,331 | —- | C] () – C:\Windows\game.ini
[2011/05/13 14:17:18 | 000,001,046 | —- | C] () – C:\Users\Francesco\Desktop\KMPlayer.lnk
[2011/05/13 12:49:06 | 000,001,161 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/13 12:49:06 | 000,001,149 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/11 11:37:34 | 000,722,802 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/10 19:35:10 | 001,369,628 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\Cat.DB
[2011/05/10 19:35:10 | 000,007,488 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/10 19:35:10 | 000,000,855 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/10 19:35:09 | 000,002,572 | —- | C] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2011/05/10 19:35:03 | 000,007,492 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\iron.cat
[2011/05/10 19:35:03 | 000,007,462 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.cat
[2011/05/10 19:35:03 | 000,007,460 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.cat
[2011/05/10 19:35:03 | 000,007,458 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnet64.cat
[2011/05/10 19:35:03 | 000,007,458 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.cat
[2011/05/10 19:35:03 | 000,003,373 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa.inf
[2011/05/10 19:35:03 | 000,002,792 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds.inf
[2011/05/10 19:35:03 | 000,001,446 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnet.inf
[2011/05/10 19:35:03 | 000,001,438 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.inf
[2011/05/10 19:35:03 | 000,001,422 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.inf
[2011/05/10 19:35:03 | 000,000,772 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\iron.inf
[2011/05/10 19:35:03 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\isolate.ini
[2011/05/10 19:34:57 | 000,000,000 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.cat
[2011/05/10 19:15:33 | 000,001,448 | —- | C] () – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/10 15:03:49 | 000,000,000 | RHS- | C] () – C:\Windows\SysWow64\drivers\TOSHIBA_Satellite C660_13769-EN_PSC0QE-01100.MRK
[2011/05/10 14:11:18 | 000,001,454 | —- | C] () – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/10 14:10:57 | 000,001,000 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BBC iPlayer Desktop.lnk
[2011/05/10 14:08:26 | 000,002,046 | —- | C] () – C:\Users\Francesco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
[2011/05/10 14:08:26 | 000,000,290 | —- | C] () – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/10 14:08:26 | 000,000,272 | —- | C] () – C:\Users\Francesco\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/01/21 13:04:08 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2011/01/21 12:57:24 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2010/11/10 15:43:32 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/10 15:41:29 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2010/07/29 06:08:46 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/29 06:08:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/29 06:08:42 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/29 05:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/29 05:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2010/03/03 23:36:32 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\SPCtl.dll
[2009/07/14 06:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

< End of report >
Hi,

Just some housekeeping to do now:

P2P - I see you have P2P software emule/bittorrent toolbar installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT



You can delete the DDS and aswMBR logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT


Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.




If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI