This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Am I infected ? [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all, My WinXp Pro computer got real slow. I used Combofix which went through all steps but hanged while preparing a log file and I had to force a system shut down. Now when I start the computer I get a message saying "Error while loading C:Windows\system32\bit4cnsp.dll Impossible to find the specific modul". I press ok and the computer starts anyway. What is this dll ? Do I really need it ? I tried to do a scan in safe mode using my Karpesky Internet Scurity but F8 won't let me get into the safe mode. I've tried to upload a Hijackthis log with my post but I get: "Upload failed. You are not permitted to upload this type of file" ??? :angry: :pullhair: Thanks in advance.
:welcome:

We try to stress that Combofix is a very powerful tool and should not be run without supervision, and you ran it anyway. Just so you know, this forum, myself and sUbs will not be responsible for any damage that Combofix run on your own may have caused


Go to C:\ComboFix.txt and copy and paste the log in this thread for me to see
Hi Ken, Tkx for your answer. I made a mistake running Combofix without supervision but it's my fault and I'm not holding anyboady responsible for it ! As mentioned in my post Combofix hanged and did not generate any log, so srry I don't have a log to post. Meanwhile, I got rid of some unuseful start-up processes by using Autoruns and I don't get the missing module massage anymore and all seems ok. Could you please answer my other question in my first post "" I've tried to upload a Hijackthis log with my post but I get: "Upload failed. You are not permitted to upload this type of file" ??? """"" Could you or someone else eventually look at my Hijackthis log if I ever get it uploaded. Tkx again.
Good Morning,

Long story on Hijackthis, it was our main scanner of choice a few years back but then the author sold it to Trendmicro and they have somewhat dropped the ball on it so we have been using other better scanners that will show us much more than HJT ever did.


Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Hi Ken,

Boy that was a quick answer, tkx a lot :thumbup:

Here's the log you asked for, some enteries are in Italian …. Please feel free to ask about them if you need to.


DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 15:37:14 on 2012-07-27
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2046.1470 [GMT 2:00]
.
AV: Kaspersky Internet Security *Enabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmi\Microsoft IntelliType Pro\itype.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Outlook Express\msimn.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\programmi\kaspersky lab\kaspersky internet security 2012\ievkbd.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\programmi\java\jre6\bin\ssv.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\programmi\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmi\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\programmi\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmi\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [36X Raid Configurer] c:\windows\system32\JMRaidSetup.exe boot
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [itype] "c:\programmi\microsoft intellitype pro\itype.exe"
mRun: [avp] "c:\programmi\kaspersky lab\kaspersky internet security 2012\avp.exe"
mRun: [Alcmtr] ALCMTR.EXE
mRun: [QuickTime Task] "c:\programmi\quicktime\qttask.exe" -atboottime
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\fileco~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\menuav~1\progra~1\esecuz~1\micros~1.lnk - c:\programmi\microsoft office\office10\OSA.EXE
IE: Aggiungi ad Anti-Banner - c:\programmi\kaspersky lab\kaspersky internet security 2012\ie_banner_deny.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmi\messenger\msmsgs.exe
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\programmi\kaspersky lab\kaspersky internet security 2012\ievkbd.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\programmi\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\programmi\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {15D151C8-5180-43C1-9360-4D794663BD6E} - hxxp://www.crs.regione.lombardia.it/components/OcsKitCittadino.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3263F297-5CB9-4D8C-A2DB-CDFB8C69CB6D} - hxxp://www.crs.regione.lombardia.it/components/OcxCertUpdate.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {4384AA75-43AB-4095-84F9-C5B35EC62B5D} - hxxp://www.crs.regione.lombardia.it/components/OcxCrsInfo.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1195667983593
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1343024855187
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab
DPF: {877E14A6-0ACF-4509-8CF3-E4A0F4ED46F4} - hxxp://supportsiss.lispa.it/components/pdlc.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444552440000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{2983E573-0223-4249-BE99-F721190208B0} : DhcpNameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\programmi\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\fileco~1\skype\SKYPE4~1.DLL
Notify: klogon - c:\windows\system32\klogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 kl1;kl1;c:\windows\system32\drivers\kl1.sys [2011-3-4 133208]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2011-3-4 11352]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2010-12-10 565552]
R2 AVP;Servizio Kaspersky Anti-Virus;c:\programmi\kaspersky lab\kaspersky internet security 2012\avp.exe -r –> c:\programmi\kaspersky lab\kaspersky internet security 2012\avp.exe -r [?]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\all users\dati applicazioni\skype\toolbars\skype c2c service\c2c_service.exe [2012-7-5 3048136]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [2012-5-4 44416]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 34608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\programmi\skype\updater\Updater.exe [2012-6-7 160944]
S3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\drivers\a38usbxp.sys [2009-8-30 24832]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-11 250056]
.
=============== Created Last 30 ================
.
2012-07-25 15:53:35 ——– d—–w- c:\programmi\MagicTune Premium
2012-07-25 15:34:25 ——– d—–w- c:\programmi\MonitorDriver
2012-07-23 07:41:04 ——– d—–w- c:\programmi\DAEMON Tools Lite
2012-07-23 07:35:59 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-07-23 07:35:59 476976 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-07-22 17:12:01 ——– d-sha-r- C:\cmdcons
2012-07-22 16:08:14 388096 —-a-r- c:\documents and settings\ba\dati applicazioni\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-07-22 16:08:13 ——– d—–w- c:\programmi\Trend Micro
2012-07-21 08:26:06 ——– d—–w- c:\documents and settings\ba\dati applicazioni\Wise Registry Cleaner
2012-06-28 16:20:10 ——– d—–w- c:\documents and settings\ba\dati applicazioni\GPass
.
==================== Find3M ====================
.
2012-07-23 07:41:12 477240 —-a-w- c:\windows\system32\drivers\sptd.sys
2012-07-23 07:35:39 472880 —-a-w- c:\windows\system32\deployJava1.dll
2012-07-13 07:58:23 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-13 07:58:23 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-13 13:55:23 1866112 ——w- c:\windows\system32\win32k.sys
2012-06-05 15:49:58 1372672 ——w- c:\windows\system32\msxml6.dll
2012-06-05 15:49:58 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 15:35:26 222448 —-a-w- c:\windows\system32\muweb.dll
2012-06-04 04:32:40 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19:30 15896 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19:24 24088 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19:24 18968 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19:24 15896 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:18:58 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 13:18:58 18672 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:21:57 603136 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:06:12 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:40:29 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:40:29 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:14 385024 ——w- c:\windows\system32\html.iec
2012-05-05 03:14:55 2151936 ——w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14:55 2030080 ——w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46:59 139656 ——w- c:\windows\system32\drivers\rdpwd.sys
2010-12-22 12:34:27 81408 —-a-w- c:\programmi\taskkill.exe
2009-03-02 10:14:03 57344 –sh–w- c:\windows\system\MSNMessengerAPI.dll
.
============= FINISH: 15.38.32,95 ===============
Hi,

Have cousins in Piacenzia


Wise Registry Cleaner <–We don't recommend the use of registry cleaners, remove legit entries that can be removed and you will see no difference in system performance, remove the wrong entry or entries and you can make your system unbootable, so your call on if you want to keep this program or not, if not you can uninstall it via Add Remove Programs in the Control Panel



Ask Toolbar <–This program will change your browser settings so its up to you also to keep or remove this one


The rest of your log looks fine



ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
http://www.eset.com/onlinescan/
Hi Ken, Tkx for the answers. 1. " Ask Tool Bar " ? can't find it nowhere in my computer to get rid of it. 2. Scanned with ESET as your instructions. One infected file. Log result : C:\Programmi\Image-Line\FL Studio 8\Plugins\Fruity\Generators\Toxic Biohazard\Toxic Biohazard.dll probably a variant of Win32/Delf.LQXDKYX trojan Two more question PLS if I may: A. How do I get rid of recovery console installed by Combofix ? It's of no use, appears 2 sec on boot up and won't give you a chance to use it. B. Why can't I boot into safe mode ? F8 won't work. Do I have to reload/reconstruct BOOT.INI ? How ? Thank you again and again. See you in Piacenza maybe ?
Hi,

I will let you read this and decide if you still want to remove the Recovery Console, if you still do the last post has instructions
http://www.bleepingcomputer.com/forums/topic317419.html


Not sure why Safemode is not working, when where done I will link you to our windows forum that can help you.


Lets run this tool and make sure nothing else is detected and then we can use it to remove Ask , what ESET found was a false positive does not need to be removed


OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Hi Ken,

I followed instructions in the post you mentioned but have no deleting options for Recovery Consol.

Appreciate your help, tkx.

Here are te 2 logs from OTL:

OTL.TXT

OTL logfile created on: 29/07/2012 17.55.02 - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Documents and Settings\ba\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

2,00 Gb Total Physical Memory | 1,57 Gb Available Physical Memory | 78,69% Memory free
3,84 Gb Paging File | 3,61 Gb Available in Paging File | 93,90% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 139,73 Gb Total Space | 103,62 Gb Free Space | 74,16% Space Free | Partition Type: NTFS

Computer Name: BA-71362F87B12D | User Name: ba | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\ba\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Programmi\File comuni\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Programmi\File comuni\Apple\Apple Application Support\libxml2.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Skype C2C Service) – C:\Documents and Settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (SkypeUpdate) – C:\Programmi\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Apple Mobile Device) – C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AVP) – C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (IviRegMgr) – C:\Programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (ProtexisLicensing) – C:\Programmi\File comuni\Protexis\License Service\PSIService.exe ()
SRV - (UleadBurningHelper) – C:\Programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (CCALib8) – C:\Programmi\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (MDM) – C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (abopw3eo) – File not found
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (klim5) – C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (kl1) – C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (dc3d) – C:\WINDOWS\system32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (klmouflt) – C:\WINDOWS\system32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (WmXlCore) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmFilter) – C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (TBPanel) – C:\WINDOWS\System32\drivers\TBPanel.sys (Windows ® 2000 DDK provider)
DRV - (Cardex) – C:\WINDOWS\system32\drivers\TBPanel.sys (Windows ® 2000 DDK provider)
DRV - (JRAID) – C:\WINDOWS\system32\drivers\jraid.sys (JMicron Technology Corp.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (JGOGO) – C:\WINDOWS\system32\drivers\JGOGO.sys (JMicron )
DRV - (MarvinBus) – C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (FileDisk) – C:\WINDOWS\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (ACSSCR) – C:\WINDOWS\system32\drivers\a38usbxp.sys (Advanced Card Systems Ltd)
DRV - (prohlp02) – C:\WINDOWS\system32\drivers\prohlp02.sys (Protection Technology)
DRV - (sfhlp01) – C:\WINDOWS\system32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\system32\drivers\prodrv06.sys (Protection Technology)
DRV - (prosync1) – C:\WINDOWS\system32\drivers\prosync1.sys (Protection Technology)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\SearchScopes,DefaultScope = {B44F65E7-42A4-45D1-AC5E-626EBF781301}
IE - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms…ch&AF;=17240
IE - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\SearchScopes\{97F84025-5AB5-44F6-B776-1A58C57DEBFE}: "URL" = http://en.wikipedia.org/w/index.php?title=…h={searchTerms}
IE - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\SearchScopes\{B44F65E7-42A4-45D1-AC5E-626EBF781301}: "URL" = http://www.google.it/search?hl=it&q;={s…erms}&meta;=
IE - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programmi\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmi\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programmi\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programmi\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)


[2011/01/30 11.34.22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ba\Dati applicazioni\Mozilla\Extensions
[2009/08/27 19.13.19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ba\Dati applicazioni\Mozilla\Extensions\[removed]
[2009/03/24 18.13.39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ba\Dati applicazioni\Mozilla\Extensions\[removed]
File not found (No name found) – C:\PROGRAMMI\TOMTOM HOME 2\XUL\EXTENSIONS\[removed]

O1 HOSTS File: ([2012/07/22 19.24.40 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (@msdxmLC.dll,-1@1033,&Radio;) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\Msdxm6.ocx (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\JMRaidSetup.exe (Gigabyte Technology Corp.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avp] C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKU\.DEFAULT..\Run: [DWQueuedReporting] c:\Programmi\File comuni\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [DWQueuedReporting] c:\Programmi\File comuni\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: &Tastiera; Virtuale - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: C&ontrollo; URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programmi\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plu…Detection32.cab (Reg Error: Key error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Reg Error: Key error.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {15D151C8-5180-43C1-9360-4D794663BD6E} http://www.crs.regione.lombardia.it/compon…itCittadino.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3263F297-5CB9-4D8C-A2DB-CDFB8C69CB6D} http://www.crs.regione.lombardia.it/compon…xCertUpdate.cab (Reg Error: Key error.)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {4384AA75-43AB-4095-84F9-C5B35EC62B5D} http://www.crs.regione.lombardia.it/compon…/OcxCrsInfo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1195667983593 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1343024855187 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} https://www.icloud.com/system/iCloud.cab (iCloud Web App Plugin)
O16 - DPF: {877E14A6-0ACF-4509-8CF3-E4A0F4ED46F4} http://supportsiss.lispa.it/components/pdlc.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444552440000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.com/files/driveragent.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2983E573-0223-4249-BE99-F721190208B0}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programmi\File comuni\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programmi\File comuni\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\Msdxm6.ocx (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\Documents and Settings\ba\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ba\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/29 17.51.31 | 000,597,504 | —- | C] (OldTimer Tools) – C:\Documents and Settings\ba\Desktop\OTL.exe
[2012/07/29 10.39.24 | 000,000,000 | —D | C] – C:\Documents and Settings\ba\Desktop\ultima pag video
[2012/07/27 17.25.30 | 000,000,000 | —D | C] – C:\Documents and Settings\ba\Desktop\Hunger Pics
[2012/07/27 15.36.47 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\ba\Desktop\dds.scr
[2012/07/26 18.31.18 | 000,000,000 | —D | C] – C:\Documents and Settings\ba\Desktop\Arteiu - Sensibilità CD
[2012/07/25 17.53.35 | 000,000,000 | —D | C] – C:\Programmi\MagicTune Premium
[2012/07/25 17.34.25 | 000,000,000 | —D | C] – C:\Programmi\MonitorDriver
[2012/07/24 12.53.47 | 000,000,000 | —D | C] – C:\Documents and Settings\ba\Desktop\Roberto
[2012/07/23 12.37.28 | 000,000,000 | —D | C] – C:\Documents and Settings\ba\Desktop\Autoruns
[2012/07/23 09.41.04 | 000,000,000 | —D | C] – C:\Programmi\DAEMON Tools Lite
[2012/07/23 09.36.12 | 000,000,000 | —D | C] – C:\Programmi\File comuni\Java
[2012/07/23 09.35.59 | 000,476,976 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/07/23 09.35.59 | 000,157,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/07/23 09.35.59 | 000,149,296 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/07/23 09.35.59 | 000,149,296 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/07/23 09.35.59 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/07/23 09.09.08 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/07/22 19.21.58 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2012/07/22 19.12.01 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/07/22 19.10.14 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2012/07/22 18.55.14 | 000,000,000 | RH-D | C] – C:\Documents and Settings\ba\Recent
[2012/07/21 10.26.06 | 000,000,000 | —D | C] – C:\Documents and Settings\ba\Dati applicazioni\Wise Registry Cleaner
[2012/07/16 12.20.09 | 000,000,000 | —D | C] – C:\Documents and Settings\ba\Desktop\Dignità
[2012/07/13 10.53.06 | 000,000,000 | —D | C] – C:\Documents and Settings\ba\Desktop\Banche 2012
[2010/12/22 14.34.27 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Programmi\taskkill.exe
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/29 17.51.33 | 000,597,504 | —- | M] (OldTimer Tools) – C:\Documents and Settings\ba\Desktop\OTL.exe
[2012/07/29 16.27.32 | 000,563,896 | —- | M] () – C:\WINDOWS\System32\perfh010.dat
[2012/07/29 16.27.32 | 000,511,738 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/07/29 16.27.32 | 000,109,442 | —- | M] () – C:\WINDOWS\System32\perfc010.dat
[2012/07/29 16.27.32 | 000,091,940 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/07/29 16.23.41 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/29 16.23.27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/29 14.17.15 | 203,709,707 | —- | M] () – C:\Documents and Settings\ba\Desktop\Dignità Official Video.mp4
[2012/07/27 16.21.26 | 000,000,227 | —- | M] () – C:\Documents and Settings\ba\Desktop\indirizzo u tube.rtf
[2012/07/27 15.36.51 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\ba\Desktop\dds.scr
[2012/07/27 12.09.57 | 000,085,488 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2012/07/26 18.31.16 | 000,019,456 | —- | M] () – C:\Documents and Settings\ba\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/24 10.11.37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2012/07/23 17.41.42 | 000,116,189 | —- | M] () – C:\WINDOWS\System32\drivers\klin.dat
[2012/07/23 17.41.41 | 000,098,168 | —- | M] () – C:\WINDOWS\System32\drivers\klick.dat
[2012/07/23 09.35.40 | 000,157,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/07/23 09.35.40 | 000,149,296 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/07/23 09.35.40 | 000,149,296 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/07/23 09.35.40 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/07/23 09.35.39 | 000,476,976 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/07/23 09.35.39 | 000,472,880 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/07/22 19.24.40 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/07/22 10.39.48 | 000,357,400 | —- | M] () – C:\Documents and Settings\ba\Desktop\EN_Eclectic_Tips global.pdf
[2012/07/22 10.36.22 | 000,303,919 | —- | M] () – C:\Documents and Settings\ba\Desktop\Investing in Switzerland_en_1006942.pdf
[2012/07/22 10.35.21 | 000,226,476 | —- | M] () – C:\Documents and Settings\ba\Desktop\Portfolio principles_en_1035296.pdf
[2012/07/22 10.33.49 | 000,357,237 | —- | M] () – C:\Documents and Settings\ba\Desktop\Agribusiness_en_1076311.pdf
[2012/07/13 09.58.23 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/13 09.58.23 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/13 09.04.09 | 000,392,776 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/03 09.40.31 | 000,002,241 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/07/01 11.32.34 | 000,000,211 | —- | M] () – C:\Boot.bak
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/29 13.59.40 | 203,709,707 | —- | C] () – C:\Documents and Settings\ba\Desktop\Dignità Official Video.mp4
[2012/07/27 16.26.48 | 000,000,227 | —- | C] () – C:\Documents and Settings\ba\Desktop\indirizzo u tube.rtf
[2012/07/25 12.53.27 | 000,229,264 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
[2012/07/22 19.12.06 | 000,000,211 | —- | C] () – C:\Boot.bak
[2012/07/22 19.12.02 | 000,261,312 | RHS- | C] () – C:\cmldr
[2012/07/22 10.39.48 | 000,357,400 | —- | C] () – C:\Documents and Settings\ba\Desktop\EN_Eclectic_Tips global.pdf
[2012/07/22 10.36.22 | 000,303,919 | —- | C] () – C:\Documents and Settings\ba\Desktop\Investing in Switzerland_en_1006942.pdf
[2012/07/22 10.35.21 | 000,226,476 | —- | C] () – C:\Documents and Settings\ba\Desktop\Portfolio principles_en_1035296.pdf
[2012/07/22 10.33.49 | 000,357,237 | —- | C] () – C:\Documents and Settings\ba\Desktop\Agribusiness_en_1076311.pdf
[2012/05/02 11.07.02 | 000,069,100 | —- | C] () – C:\WINDOWS\hpoins05.dat
[2012/05/02 11.07.02 | 000,019,696 | —- | C] () – C:\WINDOWS\hpomdl05.dat
[2012/03/24 00.41.15 | 000,373,246 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-S-1-5-21-1177238915-1788223648-725345543-1003-0.dat
[2012/03/23 18.42.59 | 000,373,246 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-System.dat
[2012/02/15 20.59.52 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/13 12.31.21 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2011/12/05 18.01.53 | 000,017,408 | —- | C] () – C:\Documents and Settings\ba\Impostazioni locali\Dati applicazioni\WebpageIcons.db
[2011/12/03 21.49.35 | 000,000,000 | —- | C] () – C:\WINDOWS\Captive.INI
[2011/12/02 14.15.11 | 000,000,000 | —- | C] () – C:\WINDOWS\Alibi.INI
[2011/11/05 19.26.34 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2011/10/15 12.31.02 | 000,002,528 | —- | C] () – C:\Documents and Settings\ba\Dati applicazioni\$_hpcst$.hpc
[2011/10/12 11.13.32 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\LauncherAccess.dt
[2011/10/12 11.09.26 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/07/30 14.39.43 | 000,000,023 | —- | C] () – C:\WINDOWS\System32\sysmwwod.dll
[2011/07/03 11.24.04 | 000,000,030 | —- | C] () – C:\WINDOWS\INTURS.DAT
[2011/07/03 11.20.21 | 000,001,559 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2011/04/08 16.36.56 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\Gif89.dll
[2011/04/01 19.07.18 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2011/03/14 13.50.43 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2011/03/14 11.30.41 | 000,000,000 | —- | C] () – C:\WINDOWS\GameLauncher.INI
[2011/03/11 14.14.44 | 000,000,000 | —- | C] () – C:\WINDOWS\Twister.INI
[2011/03/11 13.43.54 | 000,029,763 | —- | C] () – C:\WINDOWS\System32\drivers\klopp.dat
[2011/03/08 21.05.30 | 000,000,000 | —- | C] () – C:\WINDOWS\Shadow.INI
[2011/03/03 20.40.32 | 000,000,000 | —- | C] () – C:\WINDOWS\PhantomOfVenice.INI
[2011/03/02 02.12.24 | 000,000,000 | —- | C] () – C:\WINDOWS\Secrets.INI
[2011/02/28 20.27.55 | 000,000,000 | —- | C] () – C:\WINDOWS\CastleMalloy.INI
[2011/02/27 18.05.44 | 000,000,474 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2011/02/27 13.37.15 | 000,000,000 | —- | C] () – C:\WINDOWS\Ransom.INI
[2011/01/17 10.55.35 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/01/04 19.17.05 | 000,001,399 | —- | C] () – C:\WINDOWS\yloader.INI
[2010/12/29 11.25.30 | 000,010,752 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2010/12/28 19.48.52 | 000,000,000 | —- | C] () – C:\Documents and Settings\ba\.y2
[2010/12/22 16.29.01 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/10 11.39.44 | 000,116,189 | —- | C] () – C:\WINDOWS\System32\drivers\klin.dat
[2010/12/10 11.39.44 | 000,098,168 | —- | C] () – C:\WINDOWS\System32\drivers\klick.dat
[2010/11/22 18.14.37 | 000,252,080 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/11/22 18.14.32 | 000,252,080 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/11/22 18.14.32 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2009/10/14 09.20.24 | 000,001,849 | —- | C] () – C:\Documents and Settings\ba\ICE1202040000244649P.rnw
[2009/08/30 17.40.06 | 000,002,144 | —- | C] () – C:\Documents and Settings\ba\certX.cer
[2009/08/30 17.34.44 | 000,000,364 | —- | C] () – C:\Documents and Settings\ba\dikeutil.ini
[2009/04/12 16.40.10 | 000,001,237 | —- | C] () – C:\Programmi\WinDVDSetup.iss
[2009/04/12 16.37.41 | 000,000,328 | —- | C] () – C:\Programmi\GuideMenuSetup.iss
[2008/09/04 09.21.52 | 000,001,353 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\QTSBandwidthCache
[2008/05/15 08.59.25 | 009,437,184 | —- | C] () – C:\Documents and Settings\ba\ntuser.bak
[2007/12/05 10.38.56 | 000,019,456 | —- | C] () – C:\Documents and Settings\ba\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/26 09.43.49 | 000,000,131 | —- | C] () – C:\Documents and Settings\ba\Impostazioni locali\Dati applicazioni\fusioncache.dat

========== LOP Check ==========

[2009/03/18 19.03.56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\2DBoy
[2008/11/08 11.21.01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Ableton
[2009/02/07 12.43.32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\AdventureChronicles1
[2010/12/27 15.25.30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Alawar Stargaze
[2011/11/03 14.05.33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Babylon
[2011/04/13 18.13.23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Big Fish Games
[2009/03/01 18.56.37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\blg
[2012/07/23 09.40.15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\DAEMON Tools Lite
[2010/12/29 11.21.10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Downloaded Installations
[2009/03/05 11.30.16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Flood Light Games
[2009/03/23 09.14.28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Ideas From the Deep
[2012/01/30 20.13.11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\IObit
[2011/03/14 11.32.51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\iWin Games
[2009/11/01 13.30.19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Legendo
[2009/08/30 17.15.33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Lombardia Integrata
[2009/09/17 10.52.42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Merscom
[2009/03/30 11.00.39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\MumboJumbo
[2009/02/11 14.05.02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Nick Chase A Detective Story
[2010/12/29 11.21.58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\ParetoLogic
[2012/02/02 02.01.17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Pinnacle
[2009/04/25 16.12.22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Pinnacle Studio Ultimate
[2010/05/03 19.08.08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\PlayFirst
[2009/02/15 12.30.53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\PlayPond
[2009/10/27 19.47.22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Sandlot Games
[2010/12/19 17.59.38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Skyline
[2010/08/14 10.21.38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Sony
[2011/03/24 18.45.19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Tages
[2009/04/12 16.39.17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Ulead Systems
[2009/03/23 13.08.29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/09/01 17.25.40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/15 15.40.43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/17 23.43.02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/11/05 19.00.50 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\.minecraft
[2008/11/08 11.21.02 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Ableton
[2009/09/14 12.05.26 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Artogon
[2009/09/22 18.46.30 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Aveyond 3
[2011/11/03 14.05.33 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Babylon
[2011/11/03 19.14.11 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\BabylonToolbar
[2010/12/06 15.23.52 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Big Fish Games
[2009/03/01 18.56.37 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\blg
[2009/02/10 18.34.28 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Coyotes Tale
[2009/03/15 21.49.36 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Crayon Physics Deluxe
[2011/03/26 12.49.58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\ba\Dati applicazioni\CrystalSpace
[2012/07/23 09.45.09 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\DAEMON Tools Lite
[2010/10/26 20.57.05 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\DAEMON Tools Pro
[2008/11/27 14.02.14 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\DNA
[2012/01/26 12.08.13 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\DVDVideoSoft
[2011/02/14 12.42.32 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\DVDVideoSoftIEHelpers
[2009/03/23 09.51.48 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Enigmo 2
[2011/04/01 19.03.02 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\FissaSearch
[2009/03/05 11.30.16 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Flood Light Games
[2010/05/02 12.50.58 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\FreeCAD
[2008/11/15 20.29.25 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Games
[2012/03/23 14.43.03 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Garmin
[2012/05/01 19.04.05 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\GetRightToGo
[2012/06/28 18.20.10 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\GPass
[2010/07/25 20.02.30 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\gtk-2.0
[2010/10/26 21.32.32 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\ImgBurn
[2012/05/01 22.24.42 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\ImTOO
[2009/04/12 17.27.09 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\InterVideo
[2012/05/01 17.56.55 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\iPodtoComputer
[2008/11/06 18.38.56 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Juce VST Host
[2011/02/10 23.37.25 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\KeePass
[2010/12/28 17.43.45 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Key Metric Software
[2010/12/29 11.29.15 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\LimeWire
[2009/08/30 17.15.33 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Lombardia Integrata
[2009/09/14 22.42.24 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\MA
[2009/09/17 10.52.42 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Merscom
[2009/11/01 19.03.18 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\MissTeriTale3
[2010/07/25 20.02.36 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\moovida-1
[2011/05/17 11.40.59 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\MSNStockQuote
[2011/01/24 10.44.40 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\MT2OFX
[2010/01/05 12.12.18 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\MySQL
[2010/01/04 11.34.05 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\OpenOffice.org
[2010/12/29 11.22.07 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\ParetoLogic
[2011/02/09 21.21.23 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Password Manager XP
[2011/11/06 10.26.23 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Peter Brinson and Kurosh ValaNejad
[2011/02/25 14.39.14 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\PlayFirst
[2012/03/15 18.29.55 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\PosteItaliane
[2012/02/02 02.04.56 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\proDAD
[2011/04/20 16.48.52 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\ProtectDisc
[2010/08/14 10.45.35 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Publish Providers
[2009/02/14 18.57.47 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Robin Crusoe
[2009/02/14 17.49.55 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\RobinsonCrusoe
[2010/12/24 11.55.18 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\ScummVM
[2008/07/26 11.20.45 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Skinux
[2011/06/06 11.33.37 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Smart PDF Converter Pro
[2012/07/25 09.07.56 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Sony
[2012/01/20 19.38.16 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Sony Creative Software
[2011/03/20 01.28.59 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\The Longest Journey
[2011/03/20 01.02.44 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\The Longest Journey Demo
[2010/12/25 14.04.15 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\tidysongs15.27F6A35B76E5883BF9E6FEE514586561E60595CA.1
[2010/12/28 12.08.41 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\tidysongs16
[2012/01/13 12.35.12 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\tiger-k
[2010/10/30 10.44.53 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\TitanicMystery
[2009/08/27 19.13.18 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\TomTom
[2009/04/13 11.26.36 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Ulead Systems
[2010/05/17 12.08.17 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Uniblue
[2012/05/01 19.04.09 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\uTorrent
[2011/03/23 20.29.51 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\VitySoft
[2012/07/21 10.26.06 | 000,000,000 | —D | M] – C:\Documents and Settings\ba\Dati applicazioni\Wise Registry Cleaner

========== Purity Check ==========



< End of report

XXXXXXXXXXXXXXXXXXXXXXX


OTL EXTRAS:

OTL Extras logfile created on: 29/07/2012 17.55.02 - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Documents and Settings\ba\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

2,00 Gb Total Physical Memory | 1,57 Gb Available Physical Memory | 78,69% Memory free
3,84 Gb Paging File | 3,61 Gb Available in Paging File | 93,90% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 139,73 Gb Total Space | 103,62 Gb Free Space | 74,16% Space Free | Partition Type: NTFS

Computer Name: BA-71362F87B12D | User Name: ba | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"9440:TCP" = 9440:TCP:*:Disabled:Limewire
"9440:UDP" = 9440:UDP:*:Disabled:Limewire

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.325\Italian\setup.exe" = C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.325\Italian\setup.exe:*:Enabled:Kaspersky Internet Security 7.0 Setup – (Kaspersky Lab)
"C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files\Kaspersky Internet Security 2009\Italian\setup.exe" = C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files\Kaspersky Internet Security 2009\Italian\setup.exe:*:Enabled:Kaspersky Internet Security 2009 Setup – (Kaspersky Lab)
"C:\Programmi\uTorrent\uTorrent.exe" = C:\Programmi\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Programmi\HP\Digital Imaging\bin\Hpqdirec.exe" = C:\Programmi\HP\Digital Imaging\bin\Hpqdirec.exe:*:Enabled:HP Director – (Hewlett-Packard Co.)
"C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe" = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe:*:Enabled:Image Zone – (Hewlett-Packard Co.)
"C:\Programmi\File comuni\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Programmi\File comuni\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Programmi\MagicTune Premium\MagicTune.exe" = C:\Programmi\MagicTune Premium\MagicTune.exe:*:Enabled:MagicTune


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{069730C2-755A-485B-A205-27A1AAFA836A}" = InstantShareAlert
"{0DC86BEC-5CE3-413A-BB61-C40A3D186B24}" = Scan
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0FF18B53-CA57-40BB-B562-21A27B662005}" = 1600
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{17079027-EB8A-42C6-9BF8-825B78889F6A}" = Garmin Communicator Plugin
"{17293791-C82E-476C-9997-9A0FF234A19B}" = HP Product Assistant
"{181821B7-82AA-44DA-9DAF-EF254CCB670A}" = Fax
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 33
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{32714140-CBC5-3FAF-BFC2-3A7376C3EECF}" = Microsoft .NET Framework 4 Client Profile ITA Language Pack
"{342C7C88-D335-4bc2-8CF1-281857629CE2}" = HP PSC & OfficeJet 4.7
"{350C9410-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{391E18CE-7D3B-45E9-A8F0-34E77F14F47A}" = ProductContext
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E908702-AF35-4611-9518-955DA24B7E07}" = Parser Microsoft XML e SDK
"{442BE28B-782B-4DC0-B490-E70A403B1C69}" = Readme
"{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{55CA4086-0D2C-30E3-A7B5-C76BA737CECE}" = Microsoft .NET Framework 3.5 Language Pack SP1 - ita
"{568EC2B2-438D-4E9C-9546-B50A00655657}" = Raccomandata online Vers. 2.0.0.1
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{5EB90C06-964F-4195-B83E-BD7E55C88415}" = Driver Pinnacle Video
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{655CB07D-C944-40BE-B93F-55957CAC7625}" = AiO_Scan
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{663E0F1B-0591-417B-B10E-58808927FEB9}" = Microsoft IntelliType Pro 8.0
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6C94A234-CA2C-4D3C-81E6-6AAA8069825D}" = Garmin WebUpdater
"{6D299DC3-31E2-45C6-8E36-263A2AB1CE8C}" = InterVideo WinDVD SE
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = Parser MSXML 4.0 SP2 e SDK
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{83104339-BF03-4ECA-910F-7B5344717EB5}" = GuideMenu
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{842F9881-E181-30B3-A152-008D61433274}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - ITA
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{85CFD253-38AE-4DB1-ACB7-F0F4C791990D}" = AiOSoftware
"{86BA3130-5938-3192-BBCF-6B0A2D86FA58}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - ITA
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{8EA79DBF-D637-448A-89D6-410A087A4493}" = Samsung_MonSetup
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{90120000-0020-0410-0000-0000000FF1CE}" = Pacchetto di compatibilità per Office System 2007
"{90280410-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional con FrontPage
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E8B4B58-C578-4785-8652-F2FDB8B7E7FD}" = OLAP CubeCellValue Excel AddIn
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A99C1048-A569-4B65-A3DD-3584B0A4AA69}" = Microsoft MSN MoneyCentral Stock Quotes Add-In for Excel
"{AC76BA86-7AD7-1040-7B44-A93000000001}" = Adobe Reader 9.3.2 - Italiano
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Pannello di controllo NVIDIA 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Driver grafico 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BD29EBAC-AD7D-4b27-B727-4CC6AC52D36B}" = MarketResearch
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}" = Pinnacle Instant DVD Recorder
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB449D5A-7710-47aa-B9F5-352B877C90E6}" = 1600_Help
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D42B6F90-1084-4C9B-AF28-958926E6E32E}" = LP_Flash
"{D9D1A2FD-56B2-4F21-B959-745FE43CAB8C}" = Vegas Pro 9.0
"{DFF56DFF-F703-467C-AF1D-B8FAA99C7416}" = Ulead DVD MovieFactory SE
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2D2B58B-B2FD-46D1-8319-DCE564079934}" = Microsoft .NET Framework 1.1 Italian Language Pack
"{F4C6CC40-1142-49be-A28C-7BBD36F0B41A}" = 1600Trb
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"7-Zip" = 7-Zip 4.62
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"APU" = CANON iMAGE GATEWAY Album Plugin Utility
"ASIO4ALL" = ASIO4ALL
"Audacity_is1" = Audacity 1.2.6
"beaTunes-2.1.13" = tagtraum industries beaTunes 2.1.13
"Bridge Squeezes Complete" = Bridge Squeezes Complete
"Bridge_Base_Online" = Bridge Base Online
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"CCleaner" = CCleaner (remove only)
"Collab" = Collab
"CRS Kit_is1" = CRS Kit 1.0
"CRS Manager_is1" = CRS Manager [removed]
"CSCLIB" = Canon Camera Support Core Library
"DAEMON Tools Lite" = DAEMON Tools Lite
"DV CIG Guide" = Guida di Registrazione a CANON iMAGE GATEWAY
"EOS Utility" = Canon Utilities EOS Utility
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"FL Studio 8" = FL Studio 8
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free Studio_is1" = Free Studio version 4.8
"Free YouTube Download_is1" = Free YouTube Download version 3.0.20.1228
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.15.1228
"HP Photo & Imaging" = HP Image Zone 4.7
"HPExtendedCapabilities" = HP Extended Capabilities 4.7
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"InstallShield_{6D299DC3-31E2-45C6-8E36-263A2AB1CE8C}" = InterVideo WinDVD SE
"InstallShield_{83104339-BF03-4ECA-910F-7B5344717EB5}" = Corel GuideMenu
"InstallWIX_{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"iolo technologies' System Mechanic 5 Professional" = iolo technologies' System Mechanic 5 Professional
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.6.0 (Basic)
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - ita" = Microsoft .NET Framework 3.5 - Language Pack SP1 (italiano)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile ITA Language Pack" = Microsoft .NET Framework 4 Client Profile - Language Pack (ITA)
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NeroVision!UninstallKey" = NeroVision Express 2
"NMPUninstallKey" = Nero Media Player
"PoiZone" = PoiZone
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SystemRequirementsLab" = System Requirements Lab
"Toxic Biohazard" = Toxic Biohazard
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"VDOTool_is1" = VDOTool 5.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR gestione archivi
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1177238915-1788223648-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 25/07/2012 6.44.04 | Computer Name = BA-71362F87B12D | Source = Application Hang | ID = 1002
Description = Applicazione in stallo iexplore.exe, versione 8.0.6001.18702, modulo
in stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.

Error - 25/07/2012 6.44.08 | Computer Name = BA-71362F87B12D | Source = Application Hang | ID = 1002
Description = Applicazione in stallo iexplore.exe, versione 8.0.6001.18702, modulo
in stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.

Error - 25/07/2012 6.44.11 | Computer Name = BA-71362F87B12D | Source = Application Hang | ID = 1002
Description = Applicazione in stallo iexplore.exe, versione 8.0.6001.18702, modulo
in stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.

Error - 26/07/2012 3.20.34 | Computer Name = BA-71362F87B12D | Source = PIUpdater | ID = 0
Description = 2012/07/26 09.20.33 671 STA 2476 llError : System.InvalidOperationException:
Impossibile eseguire l'operazione richiesta perché il contatore di prestazioni
del processo è disattivato.\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(PerformanceCounterLib
library)\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(String machineName,
Boolean isRemoteMachine)\r\n at System.Diagnostics.ProcessManager.GetProcessInfos(String
machineName)\r\n at System.Diagnostics.Process.EnsureState(State state)\r\n
at System.Diagnostics.Process.get_ProcessName()\r\n at PosteItaliane.PostaIbrida.Updater.UI.UIUpdater.PrevInstance()

Error - 26/07/2012 3.24.40 | Computer Name = BA-71362F87B12D | Source = Application Hang | ID = 1002
Description = Applicazione in stallo EXCEL.EXE, versione 10.0.6871.0, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.

Error - 26/07/2012 3.25.28 | Computer Name = BA-71362F87B12D | Source = PIUpdater | ID = 0
Description = 2012/07/26 09.25.28 515 STA 876 llError : System.InvalidOperationException:
Impossibile eseguire l'operazione richiesta perché il contatore di prestazioni
del processo è disattivato.\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(PerformanceCounterLib
library)\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(String machineName,
Boolean isRemoteMachine)\r\n at System.Diagnostics.ProcessManager.GetProcessInfos(String
machineName)\r\n at System.Diagnostics.Process.EnsureState(State state)\r\n
at System.Diagnostics.Process.get_ProcessName()\r\n at PosteItaliane.PostaIbrida.Updater.UI.UIUpdater.PrevInstance()

Error - 27/07/2012 5.45.18 | Computer Name = BA-71362F87B12D | Source = PIUpdater | ID = 0
Description = 2012/07/27 11.45.18 515 STA 2948 llError : System.InvalidOperationException:
Impossibile eseguire l'operazione richiesta perché il contatore di prestazioni
del processo è disattivato.\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(PerformanceCounterLib
library)\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(String machineName,
Boolean isRemoteMachine)\r\n at System.Diagnostics.ProcessManager.GetProcessInfos(String
machineName)\r\n at System.Diagnostics.Process.EnsureState(State state)\r\n
at System.Diagnostics.Process.get_ProcessName()\r\n at PosteItaliane.PostaIbrida.Updater.UI.UIUpdater.PrevInstance()

Error - 27/07/2012 10.27.15 | Computer Name = BA-71362F87B12D | Source = PIUpdater | ID = 0
Description = 2012/07/27 04.27.14 984 STA 2588 llError : System.InvalidOperationException:
Impossibile eseguire l'operazione richiesta perché il contatore di prestazioni
del processo è disattivato.\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(PerformanceCounterLib
library)\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(String machineName,
Boolean isRemoteMachine)\r\n at System.Diagnostics.ProcessManager.GetProcessInfos(String
machineName)\r\n at System.Diagnostics.Process.EnsureState(State state)\r\n
at System.Diagnostics.Process.get_ProcessName()\r\n at PosteItaliane.PostaIbrida.Updater.UI.UIUpdater.PrevInstance()

Error - 28/07/2012 6.53.00 | Computer Name = BA-71362F87B12D | Source = PIUpdater | ID = 0
Description = 2012/07/28 12.52.58 953 STA 3632 llError : System.InvalidOperationException:
Impossibile eseguire l'operazione richiesta perché il contatore di prestazioni
del processo è disattivato.\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(PerformanceCounterLib
library)\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(String machineName,
Boolean isRemoteMachine)\r\n at System.Diagnostics.ProcessManager.GetProcessInfos(String
machineName)\r\n at System.Diagnostics.Process.EnsureState(State state)\r\n
at System.Diagnostics.Process.get_ProcessName()\r\n at PosteItaliane.PostaIbrida.Updater.UI.UIUpdater.PrevInstance()

Error - 28/07/2012 13.03.08 | Computer Name = BA-71362F87B12D | Source = PIUpdater | ID = 0
Description = 2012/07/28 07.03.08 234 STA 3852 llError : System.InvalidOperationException:
Impossibile eseguire l'operazione richiesta perché il contatore di prestazioni
del processo è disattivato.\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(PerformanceCounterLib
library)\r\n at System.Diagnostics.NtProcessManager.GetProcessInfos(String machineName,
Boolean isRemoteMachine)\r\n at System.Diagnostics.ProcessManager.GetProcessInfos(String
machineName)\r\n at System.Diagnostics.Process.EnsureState(State state)\r\n
at System.Diagnostics.Process.get_ProcessName()\r\n at PosteItaliane.PostaIbrida.Updater.UI.UIUpdater.PrevInstance()

[ System Events ]
Error - 26/07/2012 2.58.32 | Computer Name = BA-71362F87B12D | Source = Dhcp | ID = 1002
Description = Il lease 192.168.0.2 dell'indirizzo IP della scheda di rete con indirizzo
001A4D52DB64 è stato negato dal server DHCP 192.168.0.1. Il server DHCP ha inviato
un messaggio DHCPNACK.

Error - 26/07/2012 12.24.47 | Computer Name = BA-71362F87B12D | Source = Tcpip | ID = 4199
Description = Il sistema ha rilevato un conflitto di indirizzi per l'indirizzo IP
192.168.0.2 con il sistema con indirizzo hardware di rete C4:3D:C7:C9:36:F7. le
operazioni di rete possono risultare compromesse.

Error - 27/07/2012 2.47.29 | Computer Name = BA-71362F87B12D | Source = Dhcp | ID = 1002
Description = Il lease 192.168.0.2 dell'indirizzo IP della scheda di rete con indirizzo
001A4D52DB64 è stato negato dal server DHCP 192.168.0.1. Il server DHCP ha inviato
un messaggio DHCPNACK.

Error - 27/07/2012 7.38.24 | Computer Name = BA-71362F87B12D | Source = Dhcp | ID = 1002
Description = Il lease 192.168.0.3 dell'indirizzo IP della scheda di rete con indirizzo
001A4D52DB64 è stato negato dal server DHCP 192.168.0.1. Il server DHCP ha inviato
un messaggio DHCPNACK.

Error - 28/07/2012 3.30.31 | Computer Name = BA-71362F87B12D | Source = Dhcp | ID = 1002
Description = Il lease 192.168.0.2 dell'indirizzo IP della scheda di rete con indirizzo
001A4D52DB64 è stato negato dal server DHCP 192.168.0.1. Il server DHCP ha inviato
un messaggio DHCPNACK.

Error - 28/07/2012 13.00.01 | Computer Name = BA-71362F87B12D | Source = Dhcp | ID = 1002
Description = Il lease 192.168.0.2 dell'indirizzo IP della scheda di rete con indirizzo
001A4D52DB64 è stato negato dal server DHCP 192.168.0.1. Il server DHCP ha inviato
un messaggio DHCPNACK.

Error - 29/07/2012 2.29.47 | Computer Name = BA-71362F87B12D | Source = Dhcp | ID = 1002
Description = Il lease 192.168.0.4 dell'indirizzo IP della scheda di rete con indirizzo
001A4D52DB64 è stato negato dal server DHCP 192.168.0.1. Il server DHCP ha inviato
un messaggio DHCPNACK.

Error - 29/07/2012 4.36.35 | Computer Name = BA-71362F87B12D | Source = Tcpip | ID = 4199
Description = Il sistema ha rilevato un conflitto di indirizzi per l'indirizzo IP
192.168.0.2 con il sistema con indirizzo hardware di rete C4:3D:C7:C9:36:F7. le
operazioni di rete possono risultare compromesse.

Error - 29/07/2012 7.49.50 | Computer Name = BA-71362F87B12D | Source = Dhcp | ID = 1002
Description = Il lease 192.168.0.2 dell'indirizzo IP della scheda di rete con indirizzo
001A4D52DB64 è stato negato dal server DHCP 192.168.0.1. Il server DHCP ha inviato
un messaggio DHCPNACK.

Error - 29/07/2012 8.07.04 | Computer Name = BA-71362F87B12D | Source = Dhcp | ID = 1002
Description = Il lease 192.168.0.2 dell'indirizzo IP della scheda di rete con indirizzo
001A4D52DB64 è stato negato dal server DHCP 192.168.0.1. Il server DHCP ha inviato
un messaggio DHCPNACK.


< End of report >
I would not remove the Recovery Console, most new computers you buy today come with one from the manufacturer, some of the older ones did not, if ever your system fails to boot you can always use it to repair your system, without it you would need your windows CD.

Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    O3 - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [purity]
    [resethosts]
    [CLEARALLRESTOREPOINTS]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces
Hi Ken, I did as you instructed. OTL gives me a message saying " Cannot create file C:\Windows\system32\drivers\etc\Hosts " . Then it hangs. Any suggestions ? Thanks.
Try this new script and we will deal with the hosts file a bit later
:processes
killallprocesses

:OTL
O3 - HKU\S-1-5-21-1177238915-1788223648-725345543-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.


:Services

:Reg

:Files
ipconfig /flushdns /c


:Commands
[purity]
[CLEARALLRESTOREPOINTS]
[emptytemp]
[start explorer]
[Reboot]
Hello Ken,

This time it went ok, here's the log. Thanks.

All processes killed
========== PROCESSES ==========
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-1177238915-1788223648-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Configurazione IP di Windows
Svuotata la cache del resolver DNS.
C:\Documents and Settings\ba\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\ba\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: All Users

User: ba
->Temp folder emptied: 34413544 bytes
->Temporary Internet Files folder emptied: 51017244 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 3024 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 405 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49286 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2148445 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8643043 bytes
RecycleBin emptied: 410795788 bytes

Total Files Cleaned = 484,00 mb


OTL by OldTimer - Version 3.2.55.0 log created on 07312012_164258

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • just run this program once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Hi Ken, Here's CKScanner log: CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\ba\preferiti\gioco tv\roku streaming player watch netflix, hulu plus, amazon instant video, crackle and more on roku player.url scanner sequence 3.NA.11.UWLBVD —– EOF —– Thanks a lot.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI