ACQUA
Topic Starter
Good day.
STEP 1: Here's my problem: my notebook HP win XP home SP3 with norton 360 installed detect after a minute from start up infection by Boot.Tidserv but can't remove, i think no other problem are there.
STEP 2: TOOL #1
OTL logfile created on: 30/10/2012 11.10.05 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Marco\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,37 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 70,53% Memory free
5,21 Gb Paging File | 4,11 Gb Available in Paging File | 78,83% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 120,17 Gb Total Space | 13,53 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
Drive D: | 7,81 Gb Total Space | 0,71 Gb Free Space | 9,05% Space Free | Partition Type: FAT32
Drive G: | 468,17 Gb Total Space | 468,07 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
Computer Name: NX9420 | User Name: Marco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Marco\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programmi\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
PRC - C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclMSBTSrv.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclBCBTSrv.exe (Nokia)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
PRC - C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SMINST\Scheduler.exe ()
PRC - C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
PRC - C:\Programmi\ProtectTools\Embedded Security Software\PSDrt.exe (Infineon Technologies AG)
PRC - C:\Programmi\File comuni\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Programmi\HPQ\Shared\HpqToaster.exe ()
PRC - C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
PRC - C:\Programmi\HPQ\HP ProtectTools Security Manager\pthosttr.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Programmi\ProtectTools\Embedded Security Software\SpTNA.exe (Infineon Technologies AG)
PRC - C:\Programmi\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Programmi\HPQ\HP ProtectTools Security Manager\PTServs.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Programmi\HPQ\IAM\Bin\asghost.exe (Cognizance Corporation)
PRC - C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
PRC - C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Programmi\Nokia\Nokia Suite\phonon4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\qjson.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtXmlPatterns4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtXml4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtWebKit4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtScript4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtSql4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtNetwork4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtOpenGL4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtGui4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtMultimediaKit1.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtDeclarative4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtCore4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qjpeg4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qico4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qgif4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\NService.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\CommonUpdateChecker.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\ssoengine.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\securestorage.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\mediaservice\dsengine.dll ()
MOD - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_62c33f82\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_02182746\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - C:\Programmi\Norton 360\Engine\20.2.0.19\wincfi39.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_7e932b30\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_17f28f88\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_e82ec838\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll ()
MOD - C:\WINDOWS\SMINST\Scheduler.exe ()
MOD - C:\Programmi\WIDCOMM\Software Bluetooth\BTKeyInd.dll ()
MOD - C:\Programmi\HPQ\Shared\HpqToaster.exe ()
MOD - C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll ()
MOD - c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_it_b77a5c561934e089\mscorlib.resources.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms.resources\1.0.5000.0_it_b77a5c561934e089\system.windows.forms.resources.dll ()
MOD - C:\WINDOWS\system32\HPBHEALR.DLL ()
========== Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (N360) – C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
SRV - (ServiceLayer) – C:\Programmi\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (MBAMService) – C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Programmi\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ServiceOMC) – C:\WINDOWS\system32\ServiceOMC.exe (Alcatel-Lucent)
SRV - (C-DillaCdaC11BA) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
SRV - (btwdins) – C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe (Broadcom Corporation.)
SRV - (LightScribeService) – C:\Programmi\File comuni\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (IDriverT) – c:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (MDM) – C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (71145046) – File not found
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121027.002\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121029.037\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Programmi\File comuni\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121029.037\NAVENG.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtsp.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121005.002\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\1402000.013\SymEFA.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\1402000.013\SymDS.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\1402000.013\ccSetx86.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\1402000.013\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\1402000.013\Ironx86.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtspx.sys (Symantec Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (SASDIFSV) – C:\Programmi\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Programmi\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (CdaC15BA) – C:\WINDOWS\system32\drivers\CDAC15BA.SYS (Macrovision Europe Ltd)
DRV - (Sentinel) – C:\WINDOWS\system32\drivers\sentinel.sys (SafeNet, Inc.)
DRV - (SNTNLUSB) – C:\WINDOWS\system32\drivers\SNTNLUSB.SYS (SafeNet, Inc.)
DRV - (w39n51) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Accelerometer) – C:\WINDOWS\system32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (hpdskflt) – C:\WINDOWS\system32\drivers\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (PersonalSecureDrive) – C:\WINDOWS\system32\drivers\psd.sys (Infineon Technologies AG)
DRV - (ATSWPDRV) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (GTIPCI21) – C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
IE - HKCU\..\SearchScopes,DefaultScope = {B89C806E-191D-4B7B-B5B1-5AD84BC6716B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{070B5976-6178-46B5-AFAD-CA1F6DCC0674}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SE…b&qsrc=2869
IE - HKCU\..\SearchScopes\{B89C806E-191D-4B7B-B5B1-5AD84BC6716B}: "URL" = http://www.google.it/#hl=it&source=hp&…fca69c98b5d77d7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmi\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programmi\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Programmi\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmi\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\IPSFFPlgn\ [2012/10/27 21.10.26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\coFFPlgn\ [2012/10/30 07.50.15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Programmi\Mozilla Thunderbird\components [2012/07/05 08.44.56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Programmi\Mozilla Thunderbird\plugins
[2011/04/25 07.13.26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Marco\Dati applicazioni\Mozilla\Extensions
[2011/04/25 07.13.26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Marco\Dati applicazioni\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
========== Chrome ==========
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\pdf.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.5.11_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Programmi\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Programmi\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U25 (Enabled) = C:\Programmi\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programmi\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programmi\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Programmi\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Programmi\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Programmi\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Programmi\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Ricerca Google = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Norton Identity Protection = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.0.18_0\
CHR - Extension: Gmail = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2004/08/19 09.00.00 | 000,000,768 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Supporto di collegamento per Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programmi\Norton 360\Engine\20.2.0.19\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CNavExtBho Class) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll File not found
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (HP Credential Manager for ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Programmi\HPQ\IAM\Bin\ItIeAddIN.dll (Infineon Technologies AG)
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Programmi\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [CognizanceTS] C:\Programmi\HPQ\IAM\Bin\AsTsVcc.dll (Cognizance Corporation)
O4 - HKLM..\Run: [Cpqset] C:\Programmi\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PTHOSTTR] C:\Programmi\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\CREATOR\Remind_XP.exe ()
O4 - HKLM..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [WatchDog] C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NokiaSuite.exe] C:\Programmi\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\BTTray.lnk = C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\DVD Check.lnk = C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Cerca con Google - res://C:\Programmi\Google\GoogleToolbar1.dll/cmsearch.html File not found
O8 - Extra context menu item: &Traduci parola in italiano - res://C:\Programmi\Google\GoogleToolbar1.dll/cmwordtrans.html File not found
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Link a ritroso - res://C:\Programmi\Google\GoogleToolbar1.dll/cmbacklinks.html File not found
O8 - Extra context menu item: Pagine simili - res://C:\Programmi\Google\GoogleToolbar1.dll/cmsimilar.html File not found
O8 - Extra context menu item: Versione cache della pagina - res://C:\Programmi\Google\GoogleToolbar1.dll/cmcache.html File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre6\bin\npjpi160_25.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1303454685312 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1303464635484 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F58BB799-D4B1-4D42-A126-4472CA12FDC3}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programmi\File comuni\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programmi\File comuni\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IfxWlxEN: DllName - (IfxWlxEN.dll) - C:\WINDOWS\System32\IfxWlxEN.dll (Infineon Technologies AG)
O20 - Winlogon\Notify\OneCard: DllName - (C:\Programmi\HPQ\IAM\Bin\AsWlnPkg.dll) - C:\Programmi\HPQ\IAM\Bin\AsWlnPkg.dll (Cognizance Corporation)
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programmi\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 21.07.00 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 13.01.00 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/10/30 10.58.19 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/30 03.20.38 | 000,000,000 | —D | C] – C:\NBRT
[2012/10/29 17.24.23 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2012/10/29 17.23.31 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NBRTWizard
[2012/10/29 17.23.31 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NBRTWizard\0501000.01A
[2012/10/29 17.23.27 | 000,000,000 | —D | C] – C:\Programmi\Norton Bootable Recovery Tool Wizard
[2012/10/29 17.23.27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Norton Bootable Recovery Tool Wizard
[2012/10/29 17.15.27 | 000,912,040 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/10/29 08.07.40 | 000,000,000 | —D | C] – C:\Programmi\ESET
[2012/10/27 21.09.36 | 000,142,496 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/10/27 21.09.36 | 000,000,000 | —D | C] – C:\Programmi\Symantec
[2012/10/27 21.09.10 | 000,000,000 | —D | C] – C:\Programmi\Norton 360
[2012/10/27 21.09.10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Norton 360
[2012/10/27 21.08.58 | 000,000,000 | —D | C] – C:\Programmi\NortonInstaller
[2012/10/27 16.02.32 | 001,932,256 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/27 15.40.47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware1
[2012/10/27 15.38.30 | 010,669,896 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.29.35 | 000,751,391 | —- | C] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/27 07.47.14 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Documenti\Downloads
[2012/10/27 07.06.28 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/10/26 22.37.24 | 000,177,496 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\59697464.sys
[2012/10/26 20.06.39 | 002,213,464 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe
[2012/10/26 07.24.04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.22.03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Google Chrome
[2012/10/26 07.20.01 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.19.30 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\SUPERAntiSpyware.com
[2012/10/26 07.19.25 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.19.07 | 000,000,000 | —D | C] – C:\Programmi\SUPERAntiSpyware
[2012/10/26 07.19.06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
[2012/10/26 07.17.05 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\Malwarebytes
[2012/10/26 07.16.48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware
[2012/10/26 07.16.47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
[2012/10/26 07.16.46 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/10/26 07.16.46 | 000,000,000 | —D | C] – C:\Programmi\Malwarebytes' Anti-Malware
[2012/10/26 07.09.50 | 021,170,696 | —- | C] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 07.09.04 | 010,669,952 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/25 19.38.36 | 002,957,840 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/25 19.07.50 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Marco\Recent
[2012/10/25 16.50.05 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\NPE
[2012/10/25 15.23.56 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\SPE
[2012/10/22 10.50.34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\BigFishGamesCache
[2012/10/22 07.48.48 | 000,000,000 | —D | C] – C:\Programmi\PC Connectivity Solution
[2012/10/13 07.32.18 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Desktop\Tajikistan
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp files -> C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/30 10.58.19 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/30 10.54.27 | 000,625,664 | —- | M] () – C:\Documents and Settings\Marco\Desktop\dds.scr
[2012/10/30 10.34.47 | 000,002,253 | —- | M] () – C:\Documents and Settings\Marco\Desktop\AutoCAD 2004.lnk
[2012/10/30 10.30.00 | 000,001,128 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/30 09.39.24 | 000,000,434 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
[2012/10/30 08.30.00 | 000,001,124 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/30 08.19.00 | 000,000,494 | —- | M] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/30 07.47.03 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/30 07.46.59 | 3623,276,544 | -HS- | M] () – C:\hiberfil.sys
[2012/10/29 17.24.39 | 000,633,238 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\Cat.DB
[2012/10/29 17.16.59 | 000,000,876 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Norton Installation Files.lnk
[2012/10/29 17.16.53 | 000,912,040 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/10/29 15.03.58 | 000,000,211 | —- | M] () – C:\boot.ini
[2012/10/29 14.34.09 | 000,232,776 | -H– | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/29 10.56.51 | 000,041,838 | —- | M] () – C:\Documents and Settings\Marco\Desktop\eset scan.JPG
[2012/10/28 13.09.22 | 002,957,840 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/28 02.00.00 | 000,000,494 | —- | M] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/27 21.13.03 | 000,010,074 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\VT20121008.022
[2012/10/27 21.09.36 | 000,142,496 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/10/27 21.09.36 | 000,007,446 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/10/27 21.09.36 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/10/27 21.09.33 | 000,001,783 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2012/10/27 16.02.33 | 001,932,256 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/27 15.40.47 | 000,000,756 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/27 15.38.32 | 010,669,896 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.31.15 | 002,194,704 | —- | M] () – C:\Documents and Settings\Marco\Desktop\tdsskiller.zip
[2012/10/27 15.29.35 | 000,751,391 | —- | M] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/27 11.30.49 | 000,001,158 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/26 22.37.24 | 000,177,496 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\59697464.sys
[2012/10/26 20.06.48 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe
[2012/10/26 07.22.02 | 000,001,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/26 07.19.15 | 000,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/10/26 07.09.52 | 021,170,696 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 07.09.05 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/25 15.28.07 | 000,000,168 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKsr
[2012/10/25 15.28.06 | 000,000,144 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKs
[2012/10/25 15.27.20 | 000,000,432 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\VRKaEc3r1e3CKs
[2012/10/24 06.57.25 | 000,000,056 | -H– | M] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/10/23 06.52.10 | 000,000,056 | -H– | M] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/10/22 22.56.23 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\isolate.ini
[2012/10/22 09.21.52 | 000,535,028 | —- | M] () – C:\Documents and Settings\Marco\Desktop\DSC_5779.JPG
[2012/10/22 07.51.24 | 000,001,717 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nokia Suite.lnk
[2012/10/22 07.48.31 | 000,633,433 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\Cat.DB
[2012/10/20 10.04.48 | 000,168,136 | —- | M] () – C:\Documents and Settings\Marco\Desktop\bmci.pdf
[2012/10/17 09.20.02 | 003,611,670 | —- | M] () – C:\Documents and Settings\Marco\Desktop\ParcoDushambè2.pdf
[2012/10/16 10.49.47 | 000,284,003 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Camerota castello _2011 Layout2 (1).pdf
[2012/10/16 07.07.59 | 000,010,074 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\VT20121008.022
[2012/10/16 06.58.44 | 000,000,056 | -H– | M] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/10/15 15.47.47 | 002,522,915 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Parco2m_1_2_2733_recover.dwg
[2012/10/15 06.47.02 | 000,000,056 | -H– | M] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/10/13 07.21.10 | 000,000,066 | —- | M] () – C:\WINDOWS\ccolwiz.ini
[2012/10/11 19.52.22 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/11 19.52.22 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/10 21.24.06 | 000,001,393 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2012/10/10 19.25.22 | 000,007,597 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtspx.cat
[2012/10/10 19.25.22 | 000,007,593 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.cat
[2012/10/10 19.25.22 | 000,001,387 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtspx.inf
[2012/10/08 18.52.50 | 000,007,593 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.cat
[2012/10/08 18.52.48 | 000,007,599 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.cat
[2012/10/08 18.00.02 | 000,586,400 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.sys
[2012/10/08 18.00.02 | 000,001,388 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.inf
[2012/10/03 18.40.36 | 000,927,904 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.sys
[2012/10/03 18.40.36 | 000,009,103 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymVTcer.dat
[2012/10/03 18.40.36 | 000,003,433 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.inf
[2012/10/03 18.40.20 | 000,368,288 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.sys
[2012/10/03 18.40.20 | 000,002,851 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.inf
[2012/10/03 18.19.14 | 000,134,304 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.sys
[2012/10/03 18.19.14 | 000,007,611 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.cat
[2012/10/03 18.19.14 | 000,000,827 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.inf
[2012/10/03 12.25.20 | 000,000,056 | -H– | M] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2012/10/01 21.25.43 | 000,034,024 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Disegno2tagik.dwg
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp files -> C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/30 10.54.27 | 000,625,664 | —- | C] () – C:\Documents and Settings\Marco\Desktop\dds.scr
[2012/10/29 17.23.31 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\NBRTWizard\0501000.01A\isolate.ini
[2012/10/29 17.16.57 | 000,000,876 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Norton Installation Files.lnk
[2012/10/29 10.56.51 | 000,041,838 | —- | C] () – C:\Documents and Settings\Marco\Desktop\eset scan.JPG
[2012/10/29 08.54.37 | 000,000,434 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
[2012/10/29 07.32.02 | 3623,276,544 | -HS- | C] () – C:\hiberfil.sys
[2012/10/27 21.09.36 | 000,007,446 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/10/27 21.09.36 | 000,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/10/27 21.09.33 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2012/10/27 15.31.14 | 002,194,704 | —- | C] () – C:\Documents and Settings\Marco\Desktop\tdsskiller.zip
[2012/10/26 07.22.01 | 000,001,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/26 07.19.54 | 000,000,494 | —- | C] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/26 07.19.53 | 000,001,128 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/26 07.19.53 | 000,001,124 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/26 07.19.53 | 000,000,494 | —- | C] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/26 07.19.15 | 000,001,642 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/10/26 07.16.48 | 000,000,756 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/25 14.00.52 | 000,000,168 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKsr
[2012/10/25 14.00.52 | 000,000,144 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKs
[2012/10/25 14.00.43 | 000,000,432 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\VRKaEc3r1e3CKs
[2012/10/24 06.57.25 | 000,000,056 | -H– | C] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/10/23 06.52.10 | 000,000,056 | -H– | C] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/10/22 09.21.51 | 000,535,028 | —- | C] () – C:\Documents and Settings\Marco\Desktop\DSC_5779.JPG
[2012/10/22 07.51.22 | 000,001,717 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nokia Suite.lnk
[2012/10/20 10.04.46 | 000,168,136 | —- | C] () – C:\Documents and Settings\Marco\Desktop\bmci.pdf
[2012/10/17 09.20.00 | 003,611,670 | —- | C] () – C:\Documents and Settings\Marco\Desktop\ParcoDushambè2.pdf
[2012/10/16 10.49.47 | 000,284,003 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Camerota castello _2011 Layout2 (1).pdf
[2012/10/16 06.58.44 | 000,000,056 | -H– | C] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/10/15 06.47.02 | 000,000,056 | -H– | C] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/10/12 13.58.51 | 002,522,915 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Parco2m_1_2_2733_recover.dwg
[2012/10/03 12.25.20 | 000,000,056 | -H– | C] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2012/09/03 02.44.11 | 000,418,058 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-S-1-5-21-3596313449-3792058534-325310585-1006-0.dat
[2012/09/03 02.44.07 | 000,210,378 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-System.dat
[2012/02/16 11.10.40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/30 08.50.56 | 000,000,126 | —- | C] () – C:\Documents and Settings\Marco\pknet.properties
[2012/01/29 22.46.10 | 000,000,233 | —- | C] () – C:\Documents and Settings\Marco\actalis_ellips_applet.cfg
[2012/01/24 16.01.36 | 000,000,664 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/01/04 10.15.50 | 000,260,531 | -H– | C] () – C:\WINDOWS\System32\ADINIT.dat
[2011/11/02 16.47.56 | 000,000,064 | —- | C] () – C:\WINDOWS\ZMatrixSS.ini
[2011/09/11 08.05.47 | 000,000,066 | —- | C] () – C:\WINDOWS\ccolwiz.ini
[2011/08/24 16.05.33 | 000,000,000 | —- | C] () – C:\WINDOWS\mtstack16.INI
[2011/07/20 08.36.20 | 000,016,384 | —- | C] () – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/14 10.10.01 | 000,000,026 | —- | C] () – C:\WINDOWS\Viewer.INI
[2011/05/09 09.45.45 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/25 07.12.36 | 000,000,000 | -H– | C] () – C:\WINDOWS\nsreg.dat
[2011/04/23 13.46.44 | 000,000,551 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/04/22 18.21.16 | 000,000,350 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2011/04/22 15.52.06 | 000,003,268 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2011/04/22 15.52.06 | 000,001,374 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2011/04/22 05.03.54 | 000,000,060 | -H– | C] () – C:\WINDOWS\System32\SYSDRV.DAT
[2011/04/21 21.15.31 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/04/21 21.15.31 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/04/21 21.15.31 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/04/21 21.15.31 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/04/21 21.15.31 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/04/21 21.15.31 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/04/21 21.13.09 | 000,000,134 | -H– | C] () – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\fusioncache.dat
========== ZeroAccess Check ==========
[2004/08/30 12.15.14 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 03.13.50 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 11.51.43 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 03.13.56 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/06/26 16.06.48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Autodesk
[2012/09/01 16.29.57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\HILTI
[2011/04/22 04.44.04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Infineon
[2012/07/02 07.03.30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Nokia
[2012/03/14 07.44.30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\NokiaInstallerCache
[2012/01/16 22.31.36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\NokiaMusic
[2012/01/16 22.22.48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\OviInstallerCache
[2012/01/18 17.23.37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\PC Suite
[2012/04/23 09.05.14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\PCSettings
[2011/11/02 16.48.15 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\.ZMatrix
[2011/06/26 15.29.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Autodesk
[2012/10/26 10.14.54 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Dropbox
[2011/04/22 14.45.16 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\ElevatedDiagnostics
[2012/09/01 18.13.00 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\HILTI
[2011/04/22 04.44.12 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Infineon
[2011/04/22 10.27.37 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\InterVideo
[2012/09/01 17.19.50 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\IsolatedStorage
[2012/01/16 23.30.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Nokia
[2012/01/16 23.30.32 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Nokia Suite
[2012/01/18 17.24.55 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\PC Suite
[2006/02/28 14.19.07 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\SampleView
[2012/10/25 15.23.56 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\SPE
[2011/04/25 07.12.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Thunderbird
[2011/10/24 11.18.20 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Tific
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2004/08/19 14.00.00 | 000,354,809 | -H– | M] () MD5=09CE322E74E2A687F447F6BDFC895840 – C:\I386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2004/08/19 09.00.00 | 001,034,752 | -H– | M] (Microsoft Corporation) MD5=178D42BD8FC34A9837417A6CE1D6BB7B – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008/04/14 03.14.07 | 001,036,288 | —- | M] (Microsoft Corporation) MD5=70D7F99D95615C3C278367756287DB71 – C:\WINDOWS\explorer.exe
[2008/04/14 03.14.07 | 001,036,288 | —- | M] (Microsoft Corporation) MD5=70D7F99D95615C3C278367756287DB71 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2005/11/03 14.14.42 | 000,000,025 | —- | M] () MD5=B814E2783ABDAB5BBA1D97388A30D2D2 – C:\System.sav\util\tlbxbak\Tools\Explorer.exe
[2005/11/03 14.14.42 | 000,000,025 | —- | M] () MD5=B814E2783ABDAB5BBA1D97388A30D2D2 – C:\WinXP\Explorer.exe
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/10/30 07.48.14 | 000,076,846 | —- | M] () MD5=67DA799D76245BF6DBD19A8F42CB9F17 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.HTM >
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\cs\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.25.42 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\da\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\el\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.08 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\fi\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2003/09/15 12.06.02 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\hu\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.42 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ko\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\nl\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.58 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\no\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\pl\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\pt-BR\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ru\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.27.14 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\sv\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.27.20 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\th\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\tr\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\zh-CHS\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\zh-CHT\Help\wwhelp\wwhimpl\java\html\explorer.htm
< MD5 for: EXPLORER.SC_ >
[2004/08/19 14.00.00 | 000,000,181 | -H– | M] () MD5=5C6C24A90F391A3D958CAD1605FD5FDB – C:\I386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2004/08/19 09.00.00 | 000,000,080 | -H– | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CH_ >
[2004/08/19 14.00.00 | 000,224,335 | -H– | M] () MD5=573075BA8B480677694144B0CEA0623F – C:\I386\IEXPLORE.CH_
< MD5 for: IEXPLORE.CHM >
[2009/02/25 01.48.52 | 000,572,668 | -H– | M] () MD5=45B07BA08E9F89AD5D3B76E1C8828846 – C:\WINDOWS\Help\iexplore.chm
[2004/08/19 09.00.00 | 000,230,062 | -H– | M] () MD5=5E98814B178B42C0F67A899F63DE6029 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2004/08/19 14.00.00 | 000,037,905 | -H– | M] () MD5=71849A6EAF126BCF6314B4CE684DDD61 – C:\I386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2008/04/14 03.14.09 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=173E49AEBB665C0577D751BA55F84B6C – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2012/09/29 18.54.26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Programmi\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 13.09.26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Programmi\Internet Explorer\iexplore.exe
[2009/03/08 13.09.26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/19 09.00.00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=C49ED6E4358FFAECFE70FC8F3C67D224 – C:\WINDOWS\ie8\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13.27.36 | 000,016,384 | -H– | M] (Microsoft Corporation) MD5=D7B502FCEADFEBCC61205F4CF6539AD4 – C:\Programmi\Internet Explorer\iexplore.exe.mui
[2009/03/08 13.27.36 | 000,016,384 | -H– | M] (Microsoft Corporation) MD5=D7B502FCEADFEBCC61205F4CF6539AD4 – C:\Programmi\Internet Explorer\it-IT\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-1BA17782.PF >
[2012/10/30 08.45.27 | 000,148,102 | —- | M] () MD5=84F4788E6F4CF2C1368AFF3D87B82B0F – C:\WINDOWS\Prefetch\IEXPLORE.EXE-1BA17782.pf
< MD5 for: IEXPLORE.HL_ >
[2004/08/19 14.00.00 | 000,063,047 | -H– | M] () MD5=DAB62AE467B3B7106C2347025846C9AC – C:\I386\IEXPLORE.HL_
< MD5 for: IEXPLORE.HLP >
[2004/08/19 09.00.00 | 000,159,620 | —- | M] () MD5=D7656D207B13C79303D246C5BCE452EA – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/19 09.00.00 | 000,007,228 | -H– | M] () MD5=02FE0E4D45682D11EEA9931D79ED9A5F – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES._ >
[2004/08/19 14.00.00 | 000,002,067 | -H– | M] () MD5=B33493B43FC585F4CDD5DF0A37718689 – C:\I386\SERVICES._
< MD5 for: SERVICES.ASFX >
[2012/07/27 21.51.42 | 000,002,605 | -H– | M] () MD5=5A2C5D0DA3EAAB2AA77F16947D0E14FF – C:\Programmi\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx
< MD5 for: SERVICES.ASFX15 >
[2011/06/06 12.55.32 | 000,000,614 | RH– | M] () MD5=DCAF5E14A41328B2A5976377D7DDD969 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA70401B744AA0100000010\10.1.0\services.asfx15
< MD5 for: SERVICES.CFG >
[2012/07/27 21.51.34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Programmi\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12.55.30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA70401B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.DAT >
[2011/04/25 20.39.06 | 000,010,240 | —- | M] () MD5=30DDE7E2E0ED717BB5A43B312028FCB1 – C:\Documents and Settings\Marco\Dati applicazioni\Adobe\Acrobat\10.0\Security\services.dat
< MD5 for: SERVICES.EX_ >
[2004/08/19 14.00.00 | 000,050,027 | -H– | M] () MD5=9358FD486E309E1B94B770A3C1C7AEB0 – C:\I386\SERVICES.EX_
< MD5 for: SERVICES.EXE >
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\system32\services.exe
[2009/02/09 10.50.05 | 000,111,104 | -H– | M] (Microsoft Corporation) MD5=BCF1770A35BDA3BD13A9E2054F15F37E – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/09 12.14.45 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=C79FEAE2F68982259907AB52B0F2676F – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 03.14.19 | 000,109,056 | —- | M] (Microsoft Corporation) MD5=DAC0440C89B1EA4E35684896D5BF856E – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/14 03.14.19 | 000,109,056 | —- | M] (Microsoft Corporation) MD5=DAC0440C89B1EA4E35684896D5BF856E – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2004/08/19 09.00.00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=E77F6FA2A15390F1727F4C1C55B69DA6 – C:\WINDOWS\$NtUninstallKB956572_0$\services.exe
< MD5 for: SERVICES.MS_ >
[2004/08/19 14.00.00 | 000,003,649 | -H– | M] () MD5=CB3B5F917890D80DBA1F29F4DB3682B6 – C:\I386\SERVICES.MS_
< MD5 for: SERVICES.MSC >
[2004/08/19 09.00.00 | 000,033,085 | —- | M] () MD5=B2361B9E56F37FCF691B3700420561D9 – C:\WINDOWS\system32\services.msc
< MD5 for: WINLOGON.EX_ >
[2004/08/19 14.00.00 | 000,261,187 | -H– | M] () MD5=2B9D78E921AFDEA9A939886DCDF56C2E – C:\I386\WINLOGON.EX_
< MD5 for: WINLOGON.EXE >
[2004/08/19 09.00.00 | 000,504,832 | -H– | M] (Microsoft Corporation) MD5=4166454E2BCFCC20D1B8A5AC9FEAB243 – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/29 18.54.26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Programmi\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 03.14.24 | 000,510,464 | —- | M] (Microsoft Corporation) MD5=9259170D29B5A256735FCB8B80280857 – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 03.14.24 | 000,510,464 | —- | M] (Microsoft Corporation) MD5=9259170D29B5A256735FCB8B80280857 – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2012/10/29 15.03.58 | 000,000,211 | —- | M] () – C:\boot.ini
[1999/04/13 00.12.26 | 000,000,512 | -H– | M] () – C:\Boot32.w2k
[2004/08/19 09.00.00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[1998/10/05 16.32.06 | 000,000,512 | -H– | M] () – C:\bootsec
[1999/04/07 03.34.04 | 000,001,536 | -H– | M] () – C:\BOOTSEC.32
[2011/09/27 13.47.37 | 010,267,648 | -H– | M] () – C:\Documento recuperato 1.doc
[2011/11/27 16.22.50 | 000,012,286 | -H– | M] () – C:\Documento recuperato 1.txt
[2012/07/05 07.01.29 | 000,000,007 | -H– | M] () – C:\Documento recuperato 10.txt
[2012/07/05 07.01.30 | 000,014,552 | -H– | M] () – C:\Documento recuperato 11.txt
[2012/07/05 07.01.31 | 000,000,002 | -H– | M] () – C:\Documento recuperato 12.txt
[2012/07/06 06.54.24 | 000,003,283 | -H– | M] () – C:\Documento recuperato 13.txt
[2012/07/06 06.54.25 | 000,000,005 | -H– | M] () – C:\Documento recuperato 14.txt
[2012/07/06 06.54.30 | 000,003,241 | -H– | M] () – C:\Documento recuperato 15.txt
[2012/07/06 06.54.35 | 000,000,002 | -H– | M] () – C:\Documento recuperato 16.txt
[2012/09/03 12.06.25 | 000,000,025 | -H– | M] () – C:\Documento recuperato 17.txt
[2012/09/21 08.54.37 | 000,017,053 | -H– | M] () – C:\Documento recuperato 18.txt
[2012/09/21 08.54.37 | 000,000,008 | -H– | M] () – C:\Documento recuperato 19.txt
[2012/01/20 07.56.53 | 000,113,888 | -H– | M] () – C:\Documento recuperato 2.txt
[2012/09/21 08.54.39 | 000,016,200 | -H– | M] () – C:\Documento recuperato 20.txt
[2012/09/21 08.54.39 | 000,000,002 | -H– | M] () – C:\Documento recuperato 21.txt
[2012/10/04 12.11.22 | 000,002,274 | -H– | M] () – C:\Documento recuperato 22.txt
[2012/10/05 06.49.43 | 000,003,525 | -H– | M] () – C:\Documento recuperato 23.txt
[2012/10/10 20.35.33 | 000,008,185 | -H– | M] () – C:\Documento recuperato 24.txt
[2012/10/10 20.35.37 | 000,008,039 | -H– | M] () – C:\Documento recuperato 25.txt
[2012/10/10 20.35.37 | 000,000,002 | -H– | M] () – C:\Documento recuperato 26.txt
[2012/10/12 16.12.54 | 000,033,199 | -H– | M] () – C:\Documento recuperato 27.txt
[2012/01/20 07.56.56 | 000,090,956 | -H– | M] () – C:\Documento recuperato 3.txt
[2012/04/06 20.06.01 | 000,006,820 | -H– | M] () – C:\Documento recuperato 4.txt
[2012/01/20 15.51.33 | 000,091,914 | -H– | M] () – C:\Documento recuperato 5.txt
[2012/04/06 20.06.01 | 000,015,179 | -H– | M] () – C:\Documento recuperato 6.txt
[2012/04/12 06.41.22 | 000,023,706 | -H– | M] () – C:\Documento recuperato 7.txt
[2012/04/12 06.41.23 | 000,023,488 | -H– | M] () – C:\Documento recuperato 8.txt
[2012/07/05 07.01.29 | 000,015,670 | -H– | M] () – C:\Documento recuperato 9.txt
[2011/11/27 16.22.48 | 000,012,310 | -H– | M] () – C:\Documento recuperato.txt
[2012/05/14 16.34.21 | 000,007,530 | -H– | M] () – C:\dps.pad
[2012/10/30 07.46.59 | 3623,276,544 | -HS- | M] () – C:\hiberfil.sys
[2011/04/22 15.57.10 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/04/22 15.57.10 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/19 09.00.00 | 000,047,564 | -HS- | M] () – C:\NTDETECT.COM
[2011/04/22 13.06.21 | 000,251,600 | -HS- | M] () – C:\NTLDR
[2012/10/30 07.46.58 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2012/01/29 22.52.30 | 000,004,135 | -H– | M] () – C:\SIAsecure.tok
[2012/10/26 22.37.25 | 000,004,448 | —- | M] () – C:\TDSSKiller.2.8.13.0_26.10.2012_21.06.51_log.txt
[2012/10/27 07.07.22 | 000,205,910 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.05.46_log.txt
[2012/10/27 07.09.00 | 000,103,546 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.07.26_log.txt
[2012/10/27 07.13.39 | 000,004,448 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.13.14_log.txt
[2012/10/27 07.46.15 | 000,119,466 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.25.51_log.txt
[2012/10/27 09.59.07 | 000,333,992 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_09.10.16_log.txt
[2012/10/27 14.33.27 | 000,003,756 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_15.33.16_log.txt
[2012/10/27 15.00.56 | 000,117,594 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_15.33.54_log.txt
[2012/10/27 19.17.33 | 000,214,298 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_16.36.03_log.txt
[2012/10/27 20.23.13 | 000,101,692 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_21.22.24_log.txt
[2012/10/28 09.49.31 | 000,199,028 | —- | M] () – C:\TDSSKiller.2.8.13.0_28.10.2012_09.47.52_log.txt
[2012/07/31 15.25.05 | 000,000,056 | -H– | M] () – C:\{006D62A9-6D48-4907-B430-A4444814C43B}
[2012/10/23 06.52.10 | 000,000,056 | -H– | M] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/06/29 09.13.00 | 000,000,056 | -H– | M] () – C:\{081B71FB-F92A-4957-9E68-F27A9D5E74E1}
[2012/10/16 06.58.44 | 000,000,056 | -H– | M] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/08/01 15.35.32 | 000,000,056 | -H– | M] () – C:\{3018C3D5-465E-46AC-9C65-0F81523A07E0}
[2012/09/16 06.34.58 | 000,000,056 | -H– | M] () – C:\{39546EFA-056C-4EAE-8F50-3901877259E9}
[2011/10/13 07.25.27 | 000,000,056 | -H– | M] () – C:\{3C0B3BE5-289E-4FBF-B9CC-0D4A558E55F2}
[2012/09/23 09.05.53 | 000,000,056 | -H– | M] () – C:\{43E7740E-4CA8-42A6-86AC-83A8FD6B4EE3}
[2012/05/17 13.21.22 | 000,000,056 | -H– | M] () – C:\{4610592A-EACB-4EB9-BAFF-E784857A831C}
[2012/06/21 10.16.58 | 000,000,056 | -H– | M] () – C:\{57A154CD-5FAA-40F5-BFB7-429C78669257}
[2012/07/03 07.16.59 | 000,000,056 | -H– | M] () – C:\{6DE2C036-3841-4D67-9DE9-BA8A3EA0C6DA}
[2012/07/01 14.40.33 | 000,000,056 | -H– | M] () – C:\{793858B2-B508-4A28-BB5D-C51A58BE807C}
[2012/09/29 13.38.59 | 000,000,056 | -H– | M] () – C:\{83F285CB-260B-4833-BFD9-92B53722461F}
[2012/10/24 06.57.25 | 000,000,056 | -H– | M] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/07/10 13.23.10 | 000,000,056 | -H– | M] () – C:\{963DE796-D4F2-4CCA-9DDD-0AB4C1914C8F}
[2012/01/20 08.29.21 | 000,000,792 | -H– | M] () – C:\{B0D18835-8531-4EDB-8F9D-38EFFCC3EE0B}
[2011/05/12 10.44.37 | 000,009,744 | -H– | M] () – C:\{B1C62062-28E6-4362-B45B-6521E079B3BB}
[2012/09/05 07.04.50 | 000,000,056 | -H– | M] () – C:\{B2B91FFD-9E59-4990-A725-90BD0079A7D3}
[2012/07/07 14.30.03 | 000,000,056 | -H– | M] () – C:\{B5F69271-2FB9-40BF-B4C9-D7BA4774C1F2}
[2012/08/14 08.08.21 | 000,000,056 | -H– | M] () – C:\{B8BB83CD-F8B3-48CE-BFA9-341D8A4AC483}
[2012/08/06 06.36.08 | 000,000,056 | -H– | M] () – C:\{BC8CAC7B-6E48-4BAD-866D-1ECEEA29FEC1}
[2012/10/15 06.47.02 | 000,000,056 | -H– | M] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/07/13 08.07.08 | 000,000,056 | -H– | M] () – C:\{C61D3825-40EE-44C9-9D08-1EBFE16D6084}
[2012/05/08 09.51.11 | 000,000,056 | -H– | M] () – C:\{D93B4F7D-7E8C-4094-8298-B34D94A96438}
[2012/07/15 16.59.41 | 000,000,056 | -H– | M] () – C:\{F4AD72CA-903F-410B-A856-7DB0AB3CB554}
[2012/05/09 12.38.30 | 000,000,056 | -H– | M] () – C:\{F8D856C8-3CA1-47E0-BF2A-36150EBA317E}
[2012/02/06 08.27.40 | 000,000,288 | -H– | M] () – C:\{FCCB1DBD-1D2D-4897-BB34-CBF584FCF98E}
[2012/09/04 06.39.47 | 000,000,056 | -H– | M] () – C:\{FDA14E6F-1144-49AE-9ED0-B5F3E8AA994B}
[2012/10/03 12.25.20 | 000,000,056 | -H– | M] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2011/09/27 10.08.35 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 1.doc
[2011/11/27 16.22.50 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 1.txt
[2012/07/06 06.54.35 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 16.txt
[2012/09/03 12.06.25 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 17.txt
[2012/09/21 08.54.39 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 21.txt
[2012/10/05 06.49.43 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 23.txt
[2012/10/10 20.35.37 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 25.txt
[2012/10/10 20.35.37 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 26.txt
[2012/10/12 16.12.54 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 27.txt
[2012/01/20 15.51.33 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 5.txt
[2012/04/12 06.41.22 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 7.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14.39.28 | 000,026,040 | -H– | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13.53.56 | 000,026,489 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14.39.28 | 000,029,779 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13.58.52 | 000,030,808 | -H– | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/30 12.07.18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13.06.10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2002/01/10 09.08.34 | 000,046,592 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpprn02.dll
[2004/06/01 13.55.56 | 000,061,952 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp35z.dll
[2008/07/06 11.50.03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2003/05/25 17.46.42 | 000,065,536 | —- | M] (Happy Dude) – C:\WINDOWS\ZMatrixSS.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/30 13.54.42 | 000,094,208 | -H– | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/30 13.54.42 | 000,638,976 | -H– | M] () – C:\WINDOWS\System32\config\software.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/21 21.16.13 | 000,000,123 | -HS- | M] () – C:\Documents and Settings\Marco\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/30 12.13.52 | 000,000,079 | —- | M] () – C:\Documents and Settings\Marco\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\Mostra Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/10/27 16.02.33 | 001,932,256 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/26 07.09.05 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/27 15.38.32 | 010,669,896 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.29.35 | 000,751,391 | —- | M] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/29 17.16.53 | 000,912,040 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/01/16 23.20.22 | 092,199,288 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Nokia_Suite_webinstaller_ALL.exe
[2012/10/28 13.09.22 | 002,957,840 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/30 10.58.19 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/26 07.09.52 | 021,170,696 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 20.06.48 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-10-10 20:30:32
< >
[2004/08/19 09.00.00 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\desktop.ini
[2004/08/30 12.26.48 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2012/10/26 07.19.53 | 000,000,494 | —- | C] () – C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/26 07.19.53 | 000,001,124 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2012/10/26 07.19.53 | 000,001,128 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2012/10/26 07.19.54 | 000,000,494 | —- | C] () – C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/29 08.54.37 | 000,000,434 | -H– | C] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
< End of report >
OTL Extras logfile created on: 30/10/2012 11.10.05 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Marco\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,37 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 70,53% Memory free
5,21 Gb Paging File | 4,11 Gb Available in Paging File | 78,83% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 120,17 Gb Total Space | 13,53 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
Drive D: | 7,81 Gb Total Space | 0,71 Gb Free Space | 9,05% Space Free | Partition Type: FAT32
Drive G: | 468,17 Gb Total Space | 468,07 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
Computer Name: NX9420 | User Name: Marco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\WINDOWS\SMINST\Scheduler.exe" = C:\WINDOWS\SMINST\Scheduler.exe:*:Enabled:Scheduler – ()
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Documents and Settings\Marco\Dati applicazioni\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Marco\Dati applicazioni\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"E:\D-Link.exe" = E:\D-Link.exe:*:Enabled:D-Link Click'n Connect
"C:\Programmi\Skype\Phone\Skype.exe" = C:\Programmi\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0315DA0A-C9CD-4FCA-A762-CE25FB8954AB}" = PCXTools OMC 810 22.1a
"{0515803B-5068-4599-8666-963E143C7381}" = HP Smart Card Security for ProtectTools 5.00 D4
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{0906982B-A432-4C06-8F01-C01BE1143779}" = Nokia Connectivity Cable Driver
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1F89F212-2052-414A-8B7E-D8604C431BDF}" = HP User Guides 0013
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{2298055A-F5E6-4332-9A15-C5D99870E72F}" = HP Embedded Security for ProtectTools
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 25
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33EBF075-8593-4698-BDAF-CF8DED80BB5B}" = Nokia Suite
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.00 B2
"{350C9410-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DF12C94-8D3D-43D4-AF3C-754F51CB89CD}" = HP Install Network Printer Wizard
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = HP Integrated Module with Bluetooth wireless technology
"{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = Installer HP Backup and Recovery Manager
"{404C18ED-873A-4191-BA03-30F627445418}" = Sentinel Protection Installer 7.3.0
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 C1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50D25574-2C48-4AEC-8FFC-32AEAD2EAEFF}" = Nokia Ovi Player
"{5783F2D7-0201-0410-0002-0060B0CE6BBA}" = AutoCAD 2004
"{5783F2D7-0211-0409-0000-0060B0CE6BBA}" = AutoCAD Express Tools Volumes 1-9
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6C943D33-4B89-49A7-9126-2C59EBE64B81}" = StruM.I.S.NET
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{70B31335-50EE-4834-8431-27412CDE62BD}" = Nokia_Multimedia_Common_Components_2_5
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75ECB75A-522C-4312-8DE7-597CDA9D96A3}" = HP Mobile Data Protection System
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110410-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{90120000-0020-0410-0000-0000000FF1CE}" = Pacchetto di compatibilità per Office System 2007
"{914E1AB1-DCA0-4A7D-935F-B58C4B887A2B}" = HP ProtectTools Security Manager 2.00 B3
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A7AD8CEF-72D7-4FE4-8A14-DDD09DC86074}" = HP Notebook Accessories Product Tour
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AC76BA86-7AD7-1040-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Italiano
"{AE052EF7-2640-48D7-8915-69B810D975CB}" = HP BIOS Configuration for ProtectTools 2.00 C2
"{AE1B3F7B-CF35-4195-9D30-ED08A4BA892E}" = ATI Catalyst Control Center
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B9F4C05D-E42F-4E9A-A73F-FDD9355319FB}" = HP Credential Manager for ProtectTools
"{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}" = PC Connectivity Solution
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F2D2B58B-B2FD-46D1-8319-DCE564079934}" = Microsoft .NET Framework 1.1 Italian Language Pack
"{FF94AAB0-EC20-484C-A470-FFC06561F227}" = Strucad V14
"17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382" = Pacchetto driver Windows - Nokia pccsmcfd “LegacyDriver” (05/31/2012 7.1.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"ATI Display Driver" = ATI Display Driver
"Autodesk Express Viewer" = Autodesk Express Viewer
"Baldur's Gate" = Baldur's Gate
"CdaC13Ba" = SafeCast Shared Components
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA_hpq0033m" = HDAUDIO Soft Data Fax Modem with SmartCP
"ESET Online Scanner" = ESET Online Scanner v3
"ie8" = Windows Internet Explorer 8
"InstallShield_{6C943D33-4B89-49A7-9126-2C59EBE64B81}" = StruCad Estimating
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FF94AAB0-EC20-484C-A470-FFC06561F227}" = Strucad V14
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versione 1.65.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Thunderbird 15.0.1 (x86 it)" = Mozilla Thunderbird 15.0.1 (x86 it)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"N360" = Norton 360
"NBRTWizard" = Norton Bootable Recovery Tool Wizard
"Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM
"NeroVision!UninstallKey" = Ahead NeroVision Express
"NMIX!UninstallKey" = Ahead NeroMIX
"NMPUninstallKey" = Ahead NeroMediaPlayer
"Nokia Suite" = Nokia Suite
"ST6UNST #1" = PacchettoComune
"ST6UNST #2" = Profili_v6
"ST6UNST #3" = Telaio2D
"ST6UNST #4" = TraveConDwg Ver. 7.4
"ST6UNST #5" = Muro
"ST6UNST #6" = 1CAMP
"ST6UNST #7" = ConfiguraDvbTco
"ST6UNST #8" = VcaSlu
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Zip Repair Tool_is1" = Zip Repair Tool v.3.2
"ZMatrix_is1" = ZMatrix 1.5.2
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Cened+" = Cened+
"Dropbox" = Dropbox
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 29/10/2012 9.36.25 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.
Error - 29/10/2012 9.36.25 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 29/10/2012 10.10.27 | Computer Name = NX9420 | Source = LoadPerf | ID =
3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 29/10/2012 10.10.27 | Computer Name = NX9420 | Source = LoadPerf | ID =
3009
Error - 29/10/2012 11.23.36 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.
Error - 29/10/2012 11.23.36 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 29/10/2012 11.24.23 | Computer Name = NX9420 | Source = LoadPerf | ID =
3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 29/10/2012 11.24.23 | Computer Name = NX9420 | Source = LoadPerf | ID =
3009
Error - 30/10/2012 2.47.26 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.
Error - 30/10/2012 2.47.26 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 30/10/2012 2.49.37 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 30/10/2012 2.49.37 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 30/10/2012 2.49.56 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.
Error - 30/10/2012 2.49.56 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error encountered while reading event logs.
< End of report >
Can someone help me? MANY THANKS in advance
STEP 1: Here's my problem: my notebook HP win XP home SP3 with norton 360 installed detect after a minute from start up infection by Boot.Tidserv but can't remove, i think no other problem are there.
STEP 2: TOOL #1
OTL logfile created on: 30/10/2012 11.10.05 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Marco\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,37 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 70,53% Memory free
5,21 Gb Paging File | 4,11 Gb Available in Paging File | 78,83% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 120,17 Gb Total Space | 13,53 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
Drive D: | 7,81 Gb Total Space | 0,71 Gb Free Space | 9,05% Space Free | Partition Type: FAT32
Drive G: | 468,17 Gb Total Space | 468,07 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
Computer Name: NX9420 | User Name: Marco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Marco\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programmi\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
PRC - C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclMSBTSrv.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclBCBTSrv.exe (Nokia)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
PRC - C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SMINST\Scheduler.exe ()
PRC - C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
PRC - C:\Programmi\ProtectTools\Embedded Security Software\PSDrt.exe (Infineon Technologies AG)
PRC - C:\Programmi\File comuni\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Programmi\HPQ\Shared\HpqToaster.exe ()
PRC - C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
PRC - C:\Programmi\HPQ\HP ProtectTools Security Manager\pthosttr.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Programmi\ProtectTools\Embedded Security Software\SpTNA.exe (Infineon Technologies AG)
PRC - C:\Programmi\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Programmi\HPQ\HP ProtectTools Security Manager\PTServs.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Programmi\HPQ\IAM\Bin\asghost.exe (Cognizance Corporation)
PRC - C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
PRC - C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Programmi\Nokia\Nokia Suite\phonon4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\qjson.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtXmlPatterns4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtXml4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtWebKit4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtScript4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtSql4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtNetwork4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtOpenGL4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtGui4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtMultimediaKit1.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtDeclarative4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtCore4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qjpeg4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qico4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qgif4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\NService.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\CommonUpdateChecker.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\ssoengine.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\securestorage.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\mediaservice\dsengine.dll ()
MOD - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_62c33f82\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_02182746\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - C:\Programmi\Norton 360\Engine\20.2.0.19\wincfi39.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_7e932b30\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_17f28f88\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_e82ec838\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll ()
MOD - C:\WINDOWS\SMINST\Scheduler.exe ()
MOD - C:\Programmi\WIDCOMM\Software Bluetooth\BTKeyInd.dll ()
MOD - C:\Programmi\HPQ\Shared\HpqToaster.exe ()
MOD - C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll ()
MOD - c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_it_b77a5c561934e089\mscorlib.resources.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms.resources\1.0.5000.0_it_b77a5c561934e089\system.windows.forms.resources.dll ()
MOD - C:\WINDOWS\system32\HPBHEALR.DLL ()
========== Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (N360) – C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
SRV - (ServiceLayer) – C:\Programmi\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (MBAMService) – C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Programmi\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ServiceOMC) – C:\WINDOWS\system32\ServiceOMC.exe (Alcatel-Lucent)
SRV - (C-DillaCdaC11BA) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
SRV - (btwdins) – C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe (Broadcom Corporation.)
SRV - (LightScribeService) – C:\Programmi\File comuni\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (IDriverT) – c:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (MDM) – C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (71145046) – File not found
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121027.002\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121029.037\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Programmi\File comuni\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121029.037\NAVENG.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtsp.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121005.002\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\1402000.013\SymEFA.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\1402000.013\SymDS.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\1402000.013\ccSetx86.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\1402000.013\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\1402000.013\Ironx86.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtspx.sys (Symantec Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (SASDIFSV) – C:\Programmi\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Programmi\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (CdaC15BA) – C:\WINDOWS\system32\drivers\CDAC15BA.SYS (Macrovision Europe Ltd)
DRV - (Sentinel) – C:\WINDOWS\system32\drivers\sentinel.sys (SafeNet, Inc.)
DRV - (SNTNLUSB) – C:\WINDOWS\system32\drivers\SNTNLUSB.SYS (SafeNet, Inc.)
DRV - (w39n51) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Accelerometer) – C:\WINDOWS\system32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (hpdskflt) – C:\WINDOWS\system32\drivers\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (PersonalSecureDrive) – C:\WINDOWS\system32\drivers\psd.sys (Infineon Technologies AG)
DRV - (ATSWPDRV) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (GTIPCI21) – C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
IE - HKCU\..\SearchScopes,DefaultScope = {B89C806E-191D-4B7B-B5B1-5AD84BC6716B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{070B5976-6178-46B5-AFAD-CA1F6DCC0674}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SE…b&qsrc=2869
IE - HKCU\..\SearchScopes\{B89C806E-191D-4B7B-B5B1-5AD84BC6716B}: "URL" = http://www.google.it/#hl=it&source=hp&…fca69c98b5d77d7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmi\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programmi\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Programmi\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmi\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\IPSFFPlgn\ [2012/10/27 21.10.26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\coFFPlgn\ [2012/10/30 07.50.15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Programmi\Mozilla Thunderbird\components [2012/07/05 08.44.56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Programmi\Mozilla Thunderbird\plugins
[2011/04/25 07.13.26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Marco\Dati applicazioni\Mozilla\Extensions
[2011/04/25 07.13.26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Marco\Dati applicazioni\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
========== Chrome ==========
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\pdf.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.5.11_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Programmi\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Programmi\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U25 (Enabled) = C:\Programmi\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programmi\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programmi\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Programmi\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Programmi\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Programmi\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Programmi\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Ricerca Google = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Norton Identity Protection = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.0.18_0\
CHR - Extension: Gmail = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2004/08/19 09.00.00 | 000,000,768 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Supporto di collegamento per Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programmi\Norton 360\Engine\20.2.0.19\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CNavExtBho Class) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll File not found
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (HP Credential Manager for ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Programmi\HPQ\IAM\Bin\ItIeAddIN.dll (Infineon Technologies AG)
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Programmi\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [CognizanceTS] C:\Programmi\HPQ\IAM\Bin\AsTsVcc.dll (Cognizance Corporation)
O4 - HKLM..\Run: [Cpqset] C:\Programmi\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PTHOSTTR] C:\Programmi\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\CREATOR\Remind_XP.exe ()
O4 - HKLM..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [WatchDog] C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NokiaSuite.exe] C:\Programmi\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\BTTray.lnk = C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\DVD Check.lnk = C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Cerca con Google - res://C:\Programmi\Google\GoogleToolbar1.dll/cmsearch.html File not found
O8 - Extra context menu item: &Traduci parola in italiano - res://C:\Programmi\Google\GoogleToolbar1.dll/cmwordtrans.html File not found
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Link a ritroso - res://C:\Programmi\Google\GoogleToolbar1.dll/cmbacklinks.html File not found
O8 - Extra context menu item: Pagine simili - res://C:\Programmi\Google\GoogleToolbar1.dll/cmsimilar.html File not found
O8 - Extra context menu item: Versione cache della pagina - res://C:\Programmi\Google\GoogleToolbar1.dll/cmcache.html File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre6\bin\npjpi160_25.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1303454685312 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1303464635484 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F58BB799-D4B1-4D42-A126-4472CA12FDC3}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programmi\File comuni\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programmi\File comuni\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IfxWlxEN: DllName - (IfxWlxEN.dll) - C:\WINDOWS\System32\IfxWlxEN.dll (Infineon Technologies AG)
O20 - Winlogon\Notify\OneCard: DllName - (C:\Programmi\HPQ\IAM\Bin\AsWlnPkg.dll) - C:\Programmi\HPQ\IAM\Bin\AsWlnPkg.dll (Cognizance Corporation)
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programmi\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 21.07.00 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 13.01.00 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/10/30 10.58.19 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/30 03.20.38 | 000,000,000 | —D | C] – C:\NBRT
[2012/10/29 17.24.23 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2012/10/29 17.23.31 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NBRTWizard
[2012/10/29 17.23.31 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NBRTWizard\0501000.01A
[2012/10/29 17.23.27 | 000,000,000 | —D | C] – C:\Programmi\Norton Bootable Recovery Tool Wizard
[2012/10/29 17.23.27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Norton Bootable Recovery Tool Wizard
[2012/10/29 17.15.27 | 000,912,040 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/10/29 08.07.40 | 000,000,000 | —D | C] – C:\Programmi\ESET
[2012/10/27 21.09.36 | 000,142,496 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/10/27 21.09.36 | 000,000,000 | —D | C] – C:\Programmi\Symantec
[2012/10/27 21.09.10 | 000,000,000 | —D | C] – C:\Programmi\Norton 360
[2012/10/27 21.09.10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Norton 360
[2012/10/27 21.08.58 | 000,000,000 | —D | C] – C:\Programmi\NortonInstaller
[2012/10/27 16.02.32 | 001,932,256 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/27 15.40.47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware1
[2012/10/27 15.38.30 | 010,669,896 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.29.35 | 000,751,391 | —- | C] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/27 07.47.14 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Documenti\Downloads
[2012/10/27 07.06.28 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/10/26 22.37.24 | 000,177,496 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\59697464.sys
[2012/10/26 20.06.39 | 002,213,464 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe
[2012/10/26 07.24.04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.22.03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Google Chrome
[2012/10/26 07.20.01 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.19.30 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\SUPERAntiSpyware.com
[2012/10/26 07.19.25 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.19.07 | 000,000,000 | —D | C] – C:\Programmi\SUPERAntiSpyware
[2012/10/26 07.19.06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
[2012/10/26 07.17.05 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\Malwarebytes
[2012/10/26 07.16.48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware
[2012/10/26 07.16.47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
[2012/10/26 07.16.46 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/10/26 07.16.46 | 000,000,000 | —D | C] – C:\Programmi\Malwarebytes' Anti-Malware
[2012/10/26 07.09.50 | 021,170,696 | —- | C] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 07.09.04 | 010,669,952 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/25 19.38.36 | 002,957,840 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/25 19.07.50 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Marco\Recent
[2012/10/25 16.50.05 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\NPE
[2012/10/25 15.23.56 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\SPE
[2012/10/22 10.50.34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\BigFishGamesCache
[2012/10/22 07.48.48 | 000,000,000 | —D | C] – C:\Programmi\PC Connectivity Solution
[2012/10/13 07.32.18 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Desktop\Tajikistan
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp files -> C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/30 10.58.19 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/30 10.54.27 | 000,625,664 | —- | M] () – C:\Documents and Settings\Marco\Desktop\dds.scr
[2012/10/30 10.34.47 | 000,002,253 | —- | M] () – C:\Documents and Settings\Marco\Desktop\AutoCAD 2004.lnk
[2012/10/30 10.30.00 | 000,001,128 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/30 09.39.24 | 000,000,434 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
[2012/10/30 08.30.00 | 000,001,124 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/30 08.19.00 | 000,000,494 | —- | M] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/30 07.47.03 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/30 07.46.59 | 3623,276,544 | -HS- | M] () – C:\hiberfil.sys
[2012/10/29 17.24.39 | 000,633,238 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\Cat.DB
[2012/10/29 17.16.59 | 000,000,876 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Norton Installation Files.lnk
[2012/10/29 17.16.53 | 000,912,040 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/10/29 15.03.58 | 000,000,211 | —- | M] () – C:\boot.ini
[2012/10/29 14.34.09 | 000,232,776 | -H– | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/29 10.56.51 | 000,041,838 | —- | M] () – C:\Documents and Settings\Marco\Desktop\eset scan.JPG
[2012/10/28 13.09.22 | 002,957,840 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/28 02.00.00 | 000,000,494 | —- | M] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/27 21.13.03 | 000,010,074 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\VT20121008.022
[2012/10/27 21.09.36 | 000,142,496 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/10/27 21.09.36 | 000,007,446 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/10/27 21.09.36 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/10/27 21.09.33 | 000,001,783 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2012/10/27 16.02.33 | 001,932,256 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/27 15.40.47 | 000,000,756 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/27 15.38.32 | 010,669,896 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.31.15 | 002,194,704 | —- | M] () – C:\Documents and Settings\Marco\Desktop\tdsskiller.zip
[2012/10/27 15.29.35 | 000,751,391 | —- | M] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/27 11.30.49 | 000,001,158 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/26 22.37.24 | 000,177,496 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\59697464.sys
[2012/10/26 20.06.48 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe
[2012/10/26 07.22.02 | 000,001,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/26 07.19.15 | 000,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/10/26 07.09.52 | 021,170,696 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 07.09.05 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/25 15.28.07 | 000,000,168 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKsr
[2012/10/25 15.28.06 | 000,000,144 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKs
[2012/10/25 15.27.20 | 000,000,432 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\VRKaEc3r1e3CKs
[2012/10/24 06.57.25 | 000,000,056 | -H– | M] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/10/23 06.52.10 | 000,000,056 | -H– | M] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/10/22 22.56.23 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\isolate.ini
[2012/10/22 09.21.52 | 000,535,028 | —- | M] () – C:\Documents and Settings\Marco\Desktop\DSC_5779.JPG
[2012/10/22 07.51.24 | 000,001,717 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nokia Suite.lnk
[2012/10/22 07.48.31 | 000,633,433 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\Cat.DB
[2012/10/20 10.04.48 | 000,168,136 | —- | M] () – C:\Documents and Settings\Marco\Desktop\bmci.pdf
[2012/10/17 09.20.02 | 003,611,670 | —- | M] () – C:\Documents and Settings\Marco\Desktop\ParcoDushambè2.pdf
[2012/10/16 10.49.47 | 000,284,003 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Camerota castello _2011 Layout2 (1).pdf
[2012/10/16 07.07.59 | 000,010,074 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\VT20121008.022
[2012/10/16 06.58.44 | 000,000,056 | -H– | M] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/10/15 15.47.47 | 002,522,915 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Parco2m_1_2_2733_recover.dwg
[2012/10/15 06.47.02 | 000,000,056 | -H– | M] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/10/13 07.21.10 | 000,000,066 | —- | M] () – C:\WINDOWS\ccolwiz.ini
[2012/10/11 19.52.22 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/11 19.52.22 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/10 21.24.06 | 000,001,393 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2012/10/10 19.25.22 | 000,007,597 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtspx.cat
[2012/10/10 19.25.22 | 000,007,593 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.cat
[2012/10/10 19.25.22 | 000,001,387 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtspx.inf
[2012/10/08 18.52.50 | 000,007,593 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.cat
[2012/10/08 18.52.48 | 000,007,599 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.cat
[2012/10/08 18.00.02 | 000,586,400 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.sys
[2012/10/08 18.00.02 | 000,001,388 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.inf
[2012/10/03 18.40.36 | 000,927,904 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.sys
[2012/10/03 18.40.36 | 000,009,103 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymVTcer.dat
[2012/10/03 18.40.36 | 000,003,433 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.inf
[2012/10/03 18.40.20 | 000,368,288 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.sys
[2012/10/03 18.40.20 | 000,002,851 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.inf
[2012/10/03 18.19.14 | 000,134,304 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.sys
[2012/10/03 18.19.14 | 000,007,611 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.cat
[2012/10/03 18.19.14 | 000,000,827 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.inf
[2012/10/03 12.25.20 | 000,000,056 | -H– | M] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2012/10/01 21.25.43 | 000,034,024 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Disegno2tagik.dwg
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp files -> C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/30 10.54.27 | 000,625,664 | —- | C] () – C:\Documents and Settings\Marco\Desktop\dds.scr
[2012/10/29 17.23.31 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\NBRTWizard\0501000.01A\isolate.ini
[2012/10/29 17.16.57 | 000,000,876 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Norton Installation Files.lnk
[2012/10/29 10.56.51 | 000,041,838 | —- | C] () – C:\Documents and Settings\Marco\Desktop\eset scan.JPG
[2012/10/29 08.54.37 | 000,000,434 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
[2012/10/29 07.32.02 | 3623,276,544 | -HS- | C] () – C:\hiberfil.sys
[2012/10/27 21.09.36 | 000,007,446 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/10/27 21.09.36 | 000,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/10/27 21.09.33 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2012/10/27 15.31.14 | 002,194,704 | —- | C] () – C:\Documents and Settings\Marco\Desktop\tdsskiller.zip
[2012/10/26 07.22.01 | 000,001,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/26 07.19.54 | 000,000,494 | —- | C] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/26 07.19.53 | 000,001,128 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/26 07.19.53 | 000,001,124 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/26 07.19.53 | 000,000,494 | —- | C] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/26 07.19.15 | 000,001,642 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/10/26 07.16.48 | 000,000,756 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/25 14.00.52 | 000,000,168 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKsr
[2012/10/25 14.00.52 | 000,000,144 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKs
[2012/10/25 14.00.43 | 000,000,432 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\VRKaEc3r1e3CKs
[2012/10/24 06.57.25 | 000,000,056 | -H– | C] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/10/23 06.52.10 | 000,000,056 | -H– | C] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/10/22 09.21.51 | 000,535,028 | —- | C] () – C:\Documents and Settings\Marco\Desktop\DSC_5779.JPG
[2012/10/22 07.51.22 | 000,001,717 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nokia Suite.lnk
[2012/10/20 10.04.46 | 000,168,136 | —- | C] () – C:\Documents and Settings\Marco\Desktop\bmci.pdf
[2012/10/17 09.20.00 | 003,611,670 | —- | C] () – C:\Documents and Settings\Marco\Desktop\ParcoDushambè2.pdf
[2012/10/16 10.49.47 | 000,284,003 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Camerota castello _2011 Layout2 (1).pdf
[2012/10/16 06.58.44 | 000,000,056 | -H– | C] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/10/15 06.47.02 | 000,000,056 | -H– | C] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/10/12 13.58.51 | 002,522,915 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Parco2m_1_2_2733_recover.dwg
[2012/10/03 12.25.20 | 000,000,056 | -H– | C] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2012/09/03 02.44.11 | 000,418,058 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-S-1-5-21-3596313449-3792058534-325310585-1006-0.dat
[2012/09/03 02.44.07 | 000,210,378 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-System.dat
[2012/02/16 11.10.40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/30 08.50.56 | 000,000,126 | —- | C] () – C:\Documents and Settings\Marco\pknet.properties
[2012/01/29 22.46.10 | 000,000,233 | —- | C] () – C:\Documents and Settings\Marco\actalis_ellips_applet.cfg
[2012/01/24 16.01.36 | 000,000,664 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/01/04 10.15.50 | 000,260,531 | -H– | C] () – C:\WINDOWS\System32\ADINIT.dat
[2011/11/02 16.47.56 | 000,000,064 | —- | C] () – C:\WINDOWS\ZMatrixSS.ini
[2011/09/11 08.05.47 | 000,000,066 | —- | C] () – C:\WINDOWS\ccolwiz.ini
[2011/08/24 16.05.33 | 000,000,000 | —- | C] () – C:\WINDOWS\mtstack16.INI
[2011/07/20 08.36.20 | 000,016,384 | —- | C] () – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/14 10.10.01 | 000,000,026 | —- | C] () – C:\WINDOWS\Viewer.INI
[2011/05/09 09.45.45 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/25 07.12.36 | 000,000,000 | -H– | C] () – C:\WINDOWS\nsreg.dat
[2011/04/23 13.46.44 | 000,000,551 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/04/22 18.21.16 | 000,000,350 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2011/04/22 15.52.06 | 000,003,268 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2011/04/22 15.52.06 | 000,001,374 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2011/04/22 05.03.54 | 000,000,060 | -H– | C] () – C:\WINDOWS\System32\SYSDRV.DAT
[2011/04/21 21.15.31 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/04/21 21.15.31 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/04/21 21.15.31 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/04/21 21.15.31 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/04/21 21.15.31 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/04/21 21.15.31 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/04/21 21.13.09 | 000,000,134 | -H– | C] () – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\fusioncache.dat
========== ZeroAccess Check ==========
[2004/08/30 12.15.14 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 03.13.50 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 11.51.43 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 03.13.56 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/06/26 16.06.48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Autodesk
[2012/09/01 16.29.57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\HILTI
[2011/04/22 04.44.04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Infineon
[2012/07/02 07.03.30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Nokia
[2012/03/14 07.44.30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\NokiaInstallerCache
[2012/01/16 22.31.36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\NokiaMusic
[2012/01/16 22.22.48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\OviInstallerCache
[2012/01/18 17.23.37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\PC Suite
[2012/04/23 09.05.14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\PCSettings
[2011/11/02 16.48.15 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\.ZMatrix
[2011/06/26 15.29.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Autodesk
[2012/10/26 10.14.54 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Dropbox
[2011/04/22 14.45.16 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\ElevatedDiagnostics
[2012/09/01 18.13.00 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\HILTI
[2011/04/22 04.44.12 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Infineon
[2011/04/22 10.27.37 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\InterVideo
[2012/09/01 17.19.50 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\IsolatedStorage
[2012/01/16 23.30.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Nokia
[2012/01/16 23.30.32 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Nokia Suite
[2012/01/18 17.24.55 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\PC Suite
[2006/02/28 14.19.07 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\SampleView
[2012/10/25 15.23.56 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\SPE
[2011/04/25 07.12.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Thunderbird
[2011/10/24 11.18.20 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Tific
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2004/08/19 14.00.00 | 000,354,809 | -H– | M] () MD5=09CE322E74E2A687F447F6BDFC895840 – C:\I386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2004/08/19 09.00.00 | 001,034,752 | -H– | M] (Microsoft Corporation) MD5=178D42BD8FC34A9837417A6CE1D6BB7B – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008/04/14 03.14.07 | 001,036,288 | —- | M] (Microsoft Corporation) MD5=70D7F99D95615C3C278367756287DB71 – C:\WINDOWS\explorer.exe
[2008/04/14 03.14.07 | 001,036,288 | —- | M] (Microsoft Corporation) MD5=70D7F99D95615C3C278367756287DB71 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2005/11/03 14.14.42 | 000,000,025 | —- | M] () MD5=B814E2783ABDAB5BBA1D97388A30D2D2 – C:\System.sav\util\tlbxbak\Tools\Explorer.exe
[2005/11/03 14.14.42 | 000,000,025 | —- | M] () MD5=B814E2783ABDAB5BBA1D97388A30D2D2 – C:\WinXP\Explorer.exe
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/10/30 07.48.14 | 000,076,846 | —- | M] () MD5=67DA799D76245BF6DBD19A8F42CB9F17 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.HTM >
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\cs\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.25.42 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\da\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\el\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.08 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\fi\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2003/09/15 12.06.02 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\hu\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.42 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ko\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\nl\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.58 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\no\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\pl\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\pt-BR\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ru\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.27.14 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\sv\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.27.20 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\th\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\tr\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\zh-CHS\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\zh-CHT\Help\wwhelp\wwhimpl\java\html\explorer.htm
< MD5 for: EXPLORER.SC_ >
[2004/08/19 14.00.00 | 000,000,181 | -H– | M] () MD5=5C6C24A90F391A3D958CAD1605FD5FDB – C:\I386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2004/08/19 09.00.00 | 000,000,080 | -H– | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CH_ >
[2004/08/19 14.00.00 | 000,224,335 | -H– | M] () MD5=573075BA8B480677694144B0CEA0623F – C:\I386\IEXPLORE.CH_
< MD5 for: IEXPLORE.CHM >
[2009/02/25 01.48.52 | 000,572,668 | -H– | M] () MD5=45B07BA08E9F89AD5D3B76E1C8828846 – C:\WINDOWS\Help\iexplore.chm
[2004/08/19 09.00.00 | 000,230,062 | -H– | M] () MD5=5E98814B178B42C0F67A899F63DE6029 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2004/08/19 14.00.00 | 000,037,905 | -H– | M] () MD5=71849A6EAF126BCF6314B4CE684DDD61 – C:\I386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2008/04/14 03.14.09 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=173E49AEBB665C0577D751BA55F84B6C – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2012/09/29 18.54.26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Programmi\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 13.09.26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Programmi\Internet Explorer\iexplore.exe
[2009/03/08 13.09.26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/19 09.00.00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=C49ED6E4358FFAECFE70FC8F3C67D224 – C:\WINDOWS\ie8\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13.27.36 | 000,016,384 | -H– | M] (Microsoft Corporation) MD5=D7B502FCEADFEBCC61205F4CF6539AD4 – C:\Programmi\Internet Explorer\iexplore.exe.mui
[2009/03/08 13.27.36 | 000,016,384 | -H– | M] (Microsoft Corporation) MD5=D7B502FCEADFEBCC61205F4CF6539AD4 – C:\Programmi\Internet Explorer\it-IT\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-1BA17782.PF >
[2012/10/30 08.45.27 | 000,148,102 | —- | M] () MD5=84F4788E6F4CF2C1368AFF3D87B82B0F – C:\WINDOWS\Prefetch\IEXPLORE.EXE-1BA17782.pf
< MD5 for: IEXPLORE.HL_ >
[2004/08/19 14.00.00 | 000,063,047 | -H– | M] () MD5=DAB62AE467B3B7106C2347025846C9AC – C:\I386\IEXPLORE.HL_
< MD5 for: IEXPLORE.HLP >
[2004/08/19 09.00.00 | 000,159,620 | —- | M] () MD5=D7656D207B13C79303D246C5BCE452EA – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/19 09.00.00 | 000,007,228 | -H– | M] () MD5=02FE0E4D45682D11EEA9931D79ED9A5F – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES._ >
[2004/08/19 14.00.00 | 000,002,067 | -H– | M] () MD5=B33493B43FC585F4CDD5DF0A37718689 – C:\I386\SERVICES._
< MD5 for: SERVICES.ASFX >
[2012/07/27 21.51.42 | 000,002,605 | -H– | M] () MD5=5A2C5D0DA3EAAB2AA77F16947D0E14FF – C:\Programmi\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx
< MD5 for: SERVICES.ASFX15 >
[2011/06/06 12.55.32 | 000,000,614 | RH– | M] () MD5=DCAF5E14A41328B2A5976377D7DDD969 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA70401B744AA0100000010\10.1.0\services.asfx15
< MD5 for: SERVICES.CFG >
[2012/07/27 21.51.34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Programmi\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12.55.30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA70401B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.DAT >
[2011/04/25 20.39.06 | 000,010,240 | —- | M] () MD5=30DDE7E2E0ED717BB5A43B312028FCB1 – C:\Documents and Settings\Marco\Dati applicazioni\Adobe\Acrobat\10.0\Security\services.dat
< MD5 for: SERVICES.EX_ >
[2004/08/19 14.00.00 | 000,050,027 | -H– | M] () MD5=9358FD486E309E1B94B770A3C1C7AEB0 – C:\I386\SERVICES.EX_
< MD5 for: SERVICES.EXE >
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\system32\services.exe
[2009/02/09 10.50.05 | 000,111,104 | -H– | M] (Microsoft Corporation) MD5=BCF1770A35BDA3BD13A9E2054F15F37E – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/09 12.14.45 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=C79FEAE2F68982259907AB52B0F2676F – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 03.14.19 | 000,109,056 | —- | M] (Microsoft Corporation) MD5=DAC0440C89B1EA4E35684896D5BF856E – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/14 03.14.19 | 000,109,056 | —- | M] (Microsoft Corporation) MD5=DAC0440C89B1EA4E35684896D5BF856E – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2004/08/19 09.00.00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=E77F6FA2A15390F1727F4C1C55B69DA6 – C:\WINDOWS\$NtUninstallKB956572_0$\services.exe
< MD5 for: SERVICES.MS_ >
[2004/08/19 14.00.00 | 000,003,649 | -H– | M] () MD5=CB3B5F917890D80DBA1F29F4DB3682B6 – C:\I386\SERVICES.MS_
< MD5 for: SERVICES.MSC >
[2004/08/19 09.00.00 | 000,033,085 | —- | M] () MD5=B2361B9E56F37FCF691B3700420561D9 – C:\WINDOWS\system32\services.msc
< MD5 for: WINLOGON.EX_ >
[2004/08/19 14.00.00 | 000,261,187 | -H– | M] () MD5=2B9D78E921AFDEA9A939886DCDF56C2E – C:\I386\WINLOGON.EX_
< MD5 for: WINLOGON.EXE >
[2004/08/19 09.00.00 | 000,504,832 | -H– | M] (Microsoft Corporation) MD5=4166454E2BCFCC20D1B8A5AC9FEAB243 – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/29 18.54.26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Programmi\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 03.14.24 | 000,510,464 | —- | M] (Microsoft Corporation) MD5=9259170D29B5A256735FCB8B80280857 – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 03.14.24 | 000,510,464 | —- | M] (Microsoft Corporation) MD5=9259170D29B5A256735FCB8B80280857 – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2012/10/29 15.03.58 | 000,000,211 | —- | M] () – C:\boot.ini
[1999/04/13 00.12.26 | 000,000,512 | -H– | M] () – C:\Boot32.w2k
[2004/08/19 09.00.00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[1998/10/05 16.32.06 | 000,000,512 | -H– | M] () – C:\bootsec
[1999/04/07 03.34.04 | 000,001,536 | -H– | M] () – C:\BOOTSEC.32
[2011/09/27 13.47.37 | 010,267,648 | -H– | M] () – C:\Documento recuperato 1.doc
[2011/11/27 16.22.50 | 000,012,286 | -H– | M] () – C:\Documento recuperato 1.txt
[2012/07/05 07.01.29 | 000,000,007 | -H– | M] () – C:\Documento recuperato 10.txt
[2012/07/05 07.01.30 | 000,014,552 | -H– | M] () – C:\Documento recuperato 11.txt
[2012/07/05 07.01.31 | 000,000,002 | -H– | M] () – C:\Documento recuperato 12.txt
[2012/07/06 06.54.24 | 000,003,283 | -H– | M] () – C:\Documento recuperato 13.txt
[2012/07/06 06.54.25 | 000,000,005 | -H– | M] () – C:\Documento recuperato 14.txt
[2012/07/06 06.54.30 | 000,003,241 | -H– | M] () – C:\Documento recuperato 15.txt
[2012/07/06 06.54.35 | 000,000,002 | -H– | M] () – C:\Documento recuperato 16.txt
[2012/09/03 12.06.25 | 000,000,025 | -H– | M] () – C:\Documento recuperato 17.txt
[2012/09/21 08.54.37 | 000,017,053 | -H– | M] () – C:\Documento recuperato 18.txt
[2012/09/21 08.54.37 | 000,000,008 | -H– | M] () – C:\Documento recuperato 19.txt
[2012/01/20 07.56.53 | 000,113,888 | -H– | M] () – C:\Documento recuperato 2.txt
[2012/09/21 08.54.39 | 000,016,200 | -H– | M] () – C:\Documento recuperato 20.txt
[2012/09/21 08.54.39 | 000,000,002 | -H– | M] () – C:\Documento recuperato 21.txt
[2012/10/04 12.11.22 | 000,002,274 | -H– | M] () – C:\Documento recuperato 22.txt
[2012/10/05 06.49.43 | 000,003,525 | -H– | M] () – C:\Documento recuperato 23.txt
[2012/10/10 20.35.33 | 000,008,185 | -H– | M] () – C:\Documento recuperato 24.txt
[2012/10/10 20.35.37 | 000,008,039 | -H– | M] () – C:\Documento recuperato 25.txt
[2012/10/10 20.35.37 | 000,000,002 | -H– | M] () – C:\Documento recuperato 26.txt
[2012/10/12 16.12.54 | 000,033,199 | -H– | M] () – C:\Documento recuperato 27.txt
[2012/01/20 07.56.56 | 000,090,956 | -H– | M] () – C:\Documento recuperato 3.txt
[2012/04/06 20.06.01 | 000,006,820 | -H– | M] () – C:\Documento recuperato 4.txt
[2012/01/20 15.51.33 | 000,091,914 | -H– | M] () – C:\Documento recuperato 5.txt
[2012/04/06 20.06.01 | 000,015,179 | -H– | M] () – C:\Documento recuperato 6.txt
[2012/04/12 06.41.22 | 000,023,706 | -H– | M] () – C:\Documento recuperato 7.txt
[2012/04/12 06.41.23 | 000,023,488 | -H– | M] () – C:\Documento recuperato 8.txt
[2012/07/05 07.01.29 | 000,015,670 | -H– | M] () – C:\Documento recuperato 9.txt
[2011/11/27 16.22.48 | 000,012,310 | -H– | M] () – C:\Documento recuperato.txt
[2012/05/14 16.34.21 | 000,007,530 | -H– | M] () – C:\dps.pad
[2012/10/30 07.46.59 | 3623,276,544 | -HS- | M] () – C:\hiberfil.sys
[2011/04/22 15.57.10 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/04/22 15.57.10 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/19 09.00.00 | 000,047,564 | -HS- | M] () – C:\NTDETECT.COM
[2011/04/22 13.06.21 | 000,251,600 | -HS- | M] () – C:\NTLDR
[2012/10/30 07.46.58 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2012/01/29 22.52.30 | 000,004,135 | -H– | M] () – C:\SIAsecure.tok
[2012/10/26 22.37.25 | 000,004,448 | —- | M] () – C:\TDSSKiller.2.8.13.0_26.10.2012_21.06.51_log.txt
[2012/10/27 07.07.22 | 000,205,910 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.05.46_log.txt
[2012/10/27 07.09.00 | 000,103,546 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.07.26_log.txt
[2012/10/27 07.13.39 | 000,004,448 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.13.14_log.txt
[2012/10/27 07.46.15 | 000,119,466 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.25.51_log.txt
[2012/10/27 09.59.07 | 000,333,992 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_09.10.16_log.txt
[2012/10/27 14.33.27 | 000,003,756 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_15.33.16_log.txt
[2012/10/27 15.00.56 | 000,117,594 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_15.33.54_log.txt
[2012/10/27 19.17.33 | 000,214,298 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_16.36.03_log.txt
[2012/10/27 20.23.13 | 000,101,692 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_21.22.24_log.txt
[2012/10/28 09.49.31 | 000,199,028 | —- | M] () – C:\TDSSKiller.2.8.13.0_28.10.2012_09.47.52_log.txt
[2012/07/31 15.25.05 | 000,000,056 | -H– | M] () – C:\{006D62A9-6D48-4907-B430-A4444814C43B}
[2012/10/23 06.52.10 | 000,000,056 | -H– | M] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/06/29 09.13.00 | 000,000,056 | -H– | M] () – C:\{081B71FB-F92A-4957-9E68-F27A9D5E74E1}
[2012/10/16 06.58.44 | 000,000,056 | -H– | M] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/08/01 15.35.32 | 000,000,056 | -H– | M] () – C:\{3018C3D5-465E-46AC-9C65-0F81523A07E0}
[2012/09/16 06.34.58 | 000,000,056 | -H– | M] () – C:\{39546EFA-056C-4EAE-8F50-3901877259E9}
[2011/10/13 07.25.27 | 000,000,056 | -H– | M] () – C:\{3C0B3BE5-289E-4FBF-B9CC-0D4A558E55F2}
[2012/09/23 09.05.53 | 000,000,056 | -H– | M] () – C:\{43E7740E-4CA8-42A6-86AC-83A8FD6B4EE3}
[2012/05/17 13.21.22 | 000,000,056 | -H– | M] () – C:\{4610592A-EACB-4EB9-BAFF-E784857A831C}
[2012/06/21 10.16.58 | 000,000,056 | -H– | M] () – C:\{57A154CD-5FAA-40F5-BFB7-429C78669257}
[2012/07/03 07.16.59 | 000,000,056 | -H– | M] () – C:\{6DE2C036-3841-4D67-9DE9-BA8A3EA0C6DA}
[2012/07/01 14.40.33 | 000,000,056 | -H– | M] () – C:\{793858B2-B508-4A28-BB5D-C51A58BE807C}
[2012/09/29 13.38.59 | 000,000,056 | -H– | M] () – C:\{83F285CB-260B-4833-BFD9-92B53722461F}
[2012/10/24 06.57.25 | 000,000,056 | -H– | M] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/07/10 13.23.10 | 000,000,056 | -H– | M] () – C:\{963DE796-D4F2-4CCA-9DDD-0AB4C1914C8F}
[2012/01/20 08.29.21 | 000,000,792 | -H– | M] () – C:\{B0D18835-8531-4EDB-8F9D-38EFFCC3EE0B}
[2011/05/12 10.44.37 | 000,009,744 | -H– | M] () – C:\{B1C62062-28E6-4362-B45B-6521E079B3BB}
[2012/09/05 07.04.50 | 000,000,056 | -H– | M] () – C:\{B2B91FFD-9E59-4990-A725-90BD0079A7D3}
[2012/07/07 14.30.03 | 000,000,056 | -H– | M] () – C:\{B5F69271-2FB9-40BF-B4C9-D7BA4774C1F2}
[2012/08/14 08.08.21 | 000,000,056 | -H– | M] () – C:\{B8BB83CD-F8B3-48CE-BFA9-341D8A4AC483}
[2012/08/06 06.36.08 | 000,000,056 | -H– | M] () – C:\{BC8CAC7B-6E48-4BAD-866D-1ECEEA29FEC1}
[2012/10/15 06.47.02 | 000,000,056 | -H– | M] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/07/13 08.07.08 | 000,000,056 | -H– | M] () – C:\{C61D3825-40EE-44C9-9D08-1EBFE16D6084}
[2012/05/08 09.51.11 | 000,000,056 | -H– | M] () – C:\{D93B4F7D-7E8C-4094-8298-B34D94A96438}
[2012/07/15 16.59.41 | 000,000,056 | -H– | M] () – C:\{F4AD72CA-903F-410B-A856-7DB0AB3CB554}
[2012/05/09 12.38.30 | 000,000,056 | -H– | M] () – C:\{F8D856C8-3CA1-47E0-BF2A-36150EBA317E}
[2012/02/06 08.27.40 | 000,000,288 | -H– | M] () – C:\{FCCB1DBD-1D2D-4897-BB34-CBF584FCF98E}
[2012/09/04 06.39.47 | 000,000,056 | -H– | M] () – C:\{FDA14E6F-1144-49AE-9ED0-B5F3E8AA994B}
[2012/10/03 12.25.20 | 000,000,056 | -H– | M] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2011/09/27 10.08.35 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 1.doc
[2011/11/27 16.22.50 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 1.txt
[2012/07/06 06.54.35 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 16.txt
[2012/09/03 12.06.25 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 17.txt
[2012/09/21 08.54.39 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 21.txt
[2012/10/05 06.49.43 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 23.txt
[2012/10/10 20.35.37 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 25.txt
[2012/10/10 20.35.37 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 26.txt
[2012/10/12 16.12.54 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 27.txt
[2012/01/20 15.51.33 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 5.txt
[2012/04/12 06.41.22 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 7.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14.39.28 | 000,026,040 | -H– | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13.53.56 | 000,026,489 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14.39.28 | 000,029,779 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13.58.52 | 000,030,808 | -H– | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/30 12.07.18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13.06.10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2002/01/10 09.08.34 | 000,046,592 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpprn02.dll
[2004/06/01 13.55.56 | 000,061,952 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp35z.dll
[2008/07/06 11.50.03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2003/05/25 17.46.42 | 000,065,536 | —- | M] (Happy Dude) – C:\WINDOWS\ZMatrixSS.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/30 13.54.42 | 000,094,208 | -H– | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/30 13.54.42 | 000,638,976 | -H– | M] () – C:\WINDOWS\System32\config\software.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/21 21.16.13 | 000,000,123 | -HS- | M] () – C:\Documents and Settings\Marco\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/30 12.13.52 | 000,000,079 | —- | M] () – C:\Documents and Settings\Marco\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\Mostra Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/10/27 16.02.33 | 001,932,256 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/26 07.09.05 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/27 15.38.32 | 010,669,896 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.29.35 | 000,751,391 | —- | M] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/29 17.16.53 | 000,912,040 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/01/16 23.20.22 | 092,199,288 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Nokia_Suite_webinstaller_ALL.exe
[2012/10/28 13.09.22 | 002,957,840 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/30 10.58.19 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/26 07.09.52 | 021,170,696 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 20.06.48 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-10-10 20:30:32
< >
[2004/08/19 09.00.00 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\desktop.ini
[2004/08/30 12.26.48 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2012/10/26 07.19.53 | 000,000,494 | —- | C] () – C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/26 07.19.53 | 000,001,124 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2012/10/26 07.19.53 | 000,001,128 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2012/10/26 07.19.54 | 000,000,494 | —- | C] () – C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/29 08.54.37 | 000,000,434 | -H– | C] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
< End of report >
OTL Extras logfile created on: 30/10/2012 11.10.05 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Marco\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,37 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 70,53% Memory free
5,21 Gb Paging File | 4,11 Gb Available in Paging File | 78,83% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 120,17 Gb Total Space | 13,53 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
Drive D: | 7,81 Gb Total Space | 0,71 Gb Free Space | 9,05% Space Free | Partition Type: FAT32
Drive G: | 468,17 Gb Total Space | 468,07 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
Computer Name: NX9420 | User Name: Marco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\WINDOWS\SMINST\Scheduler.exe" = C:\WINDOWS\SMINST\Scheduler.exe:*:Enabled:Scheduler – ()
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Documents and Settings\Marco\Dati applicazioni\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Marco\Dati applicazioni\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"E:\D-Link.exe" = E:\D-Link.exe:*:Enabled:D-Link Click'n Connect
"C:\Programmi\Skype\Phone\Skype.exe" = C:\Programmi\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0315DA0A-C9CD-4FCA-A762-CE25FB8954AB}" = PCXTools OMC 810 22.1a
"{0515803B-5068-4599-8666-963E143C7381}" = HP Smart Card Security for ProtectTools 5.00 D4
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{0906982B-A432-4C06-8F01-C01BE1143779}" = Nokia Connectivity Cable Driver
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1F89F212-2052-414A-8B7E-D8604C431BDF}" = HP User Guides 0013
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{2298055A-F5E6-4332-9A15-C5D99870E72F}" = HP Embedded Security for ProtectTools
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 25
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33EBF075-8593-4698-BDAF-CF8DED80BB5B}" = Nokia Suite
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.00 B2
"{350C9410-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DF12C94-8D3D-43D4-AF3C-754F51CB89CD}" = HP Install Network Printer Wizard
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = HP Integrated Module with Bluetooth wireless technology
"{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = Installer HP Backup and Recovery Manager
"{404C18ED-873A-4191-BA03-30F627445418}" = Sentinel Protection Installer 7.3.0
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 C1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50D25574-2C48-4AEC-8FFC-32AEAD2EAEFF}" = Nokia Ovi Player
"{5783F2D7-0201-0410-0002-0060B0CE6BBA}" = AutoCAD 2004
"{5783F2D7-0211-0409-0000-0060B0CE6BBA}" = AutoCAD Express Tools Volumes 1-9
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6C943D33-4B89-49A7-9126-2C59EBE64B81}" = StruM.I.S.NET
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{70B31335-50EE-4834-8431-27412CDE62BD}" = Nokia_Multimedia_Common_Components_2_5
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75ECB75A-522C-4312-8DE7-597CDA9D96A3}" = HP Mobile Data Protection System
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110410-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{90120000-0020-0410-0000-0000000FF1CE}" = Pacchetto di compatibilità per Office System 2007
"{914E1AB1-DCA0-4A7D-935F-B58C4B887A2B}" = HP ProtectTools Security Manager 2.00 B3
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A7AD8CEF-72D7-4FE4-8A14-DDD09DC86074}" = HP Notebook Accessories Product Tour
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AC76BA86-7AD7-1040-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Italiano
"{AE052EF7-2640-48D7-8915-69B810D975CB}" = HP BIOS Configuration for ProtectTools 2.00 C2
"{AE1B3F7B-CF35-4195-9D30-ED08A4BA892E}" = ATI Catalyst Control Center
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B9F4C05D-E42F-4E9A-A73F-FDD9355319FB}" = HP Credential Manager for ProtectTools
"{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}" = PC Connectivity Solution
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F2D2B58B-B2FD-46D1-8319-DCE564079934}" = Microsoft .NET Framework 1.1 Italian Language Pack
"{FF94AAB0-EC20-484C-A470-FFC06561F227}" = Strucad V14
"17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382" = Pacchetto driver Windows - Nokia pccsmcfd “LegacyDriver” (05/31/2012 7.1.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"ATI Display Driver" = ATI Display Driver
"Autodesk Express Viewer" = Autodesk Express Viewer
"Baldur's Gate" = Baldur's Gate
"CdaC13Ba" = SafeCast Shared Components
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA_hpq0033m" = HDAUDIO Soft Data Fax Modem with SmartCP
"ESET Online Scanner" = ESET Online Scanner v3
"ie8" = Windows Internet Explorer 8
"InstallShield_{6C943D33-4B89-49A7-9126-2C59EBE64B81}" = StruCad Estimating
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FF94AAB0-EC20-484C-A470-FFC06561F227}" = Strucad V14
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versione 1.65.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Thunderbird 15.0.1 (x86 it)" = Mozilla Thunderbird 15.0.1 (x86 it)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"N360" = Norton 360
"NBRTWizard" = Norton Bootable Recovery Tool Wizard
"Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM
"NeroVision!UninstallKey" = Ahead NeroVision Express
"NMIX!UninstallKey" = Ahead NeroMIX
"NMPUninstallKey" = Ahead NeroMediaPlayer
"Nokia Suite" = Nokia Suite
"ST6UNST #1" = PacchettoComune
"ST6UNST #2" = Profili_v6
"ST6UNST #3" = Telaio2D
"ST6UNST #4" = TraveConDwg Ver. 7.4
"ST6UNST #5" = Muro
"ST6UNST #6" = 1CAMP
"ST6UNST #7" = ConfiguraDvbTco
"ST6UNST #8" = VcaSlu
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Zip Repair Tool_is1" = Zip Repair Tool v.3.2
"ZMatrix_is1" = ZMatrix 1.5.2
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Cened+" = Cened+
"Dropbox" = Dropbox
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 29/10/2012 9.36.25 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.
Error - 29/10/2012 9.36.25 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 29/10/2012 10.10.27 | Computer Name = NX9420 | Source = LoadPerf | ID =
3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 29/10/2012 10.10.27 | Computer Name = NX9420 | Source = LoadPerf | ID =
3009
Error - 29/10/2012 11.23.36 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.
Error - 29/10/2012 11.23.36 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 29/10/2012 11.24.23 | Computer Name = NX9420 | Source = LoadPerf | ID =
3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 29/10/2012 11.24.23 | Computer Name = NX9420 | Source = LoadPerf | ID =
3009
Error - 30/10/2012 2.47.26 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.
Error - 30/10/2012 2.47.26 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 30/10/2012 2.49.37 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 30/10/2012 2.49.37 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 30/10/2012 2.49.56 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.
Error - 30/10/2012 2.49.56 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error encountered while reading event logs.
< End of report >
Can someone help me? MANY THANKS in advance