This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Boot.Tidserv [Closed]

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good day.

STEP 1: Here's my problem: my notebook HP win XP home SP3 with norton 360 installed detect after a minute from start up infection by Boot.Tidserv but can't remove, i think no other problem are there.

STEP 2: TOOL #1

OTL logfile created on: 30/10/2012 11.10.05 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Marco\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

3,37 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 70,53% Memory free
5,21 Gb Paging File | 4,11 Gb Available in Paging File | 78,83% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 120,17 Gb Total Space | 13,53 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
Drive D: | 7,81 Gb Total Space | 0,71 Gb Free Space | 9,05% Space Free | Partition Type: FAT32
Drive G: | 468,17 Gb Total Space | 468,07 Gb Free Space | 99,98% Space Free | Partition Type: NTFS

Computer Name: NX9420 | User Name: Marco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Marco\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programmi\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
PRC - C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclMSBTSrv.exe (Nokia)
PRC - C:\Programmi\PC Connectivity Solution\Transports\NclBCBTSrv.exe (Nokia)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
PRC - C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SMINST\Scheduler.exe ()
PRC - C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
PRC - C:\Programmi\ProtectTools\Embedded Security Software\PSDrt.exe (Infineon Technologies AG)
PRC - C:\Programmi\File comuni\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Programmi\HPQ\Shared\HpqToaster.exe ()
PRC - C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
PRC - C:\Programmi\HPQ\HP ProtectTools Security Manager\pthosttr.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Programmi\ProtectTools\Embedded Security Software\SpTNA.exe (Infineon Technologies AG)
PRC - C:\Programmi\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Programmi\HPQ\HP ProtectTools Security Manager\PTServs.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Programmi\HPQ\IAM\Bin\asghost.exe (Cognizance Corporation)
PRC - C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
PRC - C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Programmi\Nokia\Nokia Suite\phonon4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\qjson.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtXmlPatterns4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtXml4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtWebKit4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtScript4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtSql4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtNetwork4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtOpenGL4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtGui4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtMultimediaKit1.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtDeclarative4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\QtCore4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qjpeg4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qico4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\Imageformats\qgif4.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\NService.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\CommonUpdateChecker.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\ssoengine.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\securestorage.dll ()
MOD - C:\Programmi\Nokia\Nokia Suite\mediaservice\dsengine.dll ()
MOD - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_62c33f82\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_02182746\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - C:\Programmi\Norton 360\Engine\20.2.0.19\wincfi39.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_7e932b30\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_17f28f88\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_e82ec838\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll ()
MOD - C:\WINDOWS\SMINST\Scheduler.exe ()
MOD - C:\Programmi\WIDCOMM\Software Bluetooth\BTKeyInd.dll ()
MOD - C:\Programmi\HPQ\Shared\HpqToaster.exe ()
MOD - C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll ()
MOD - c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_it_b77a5c561934e089\mscorlib.resources.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms.resources\1.0.5000.0_it_b77a5c561934e089\system.windows.forms.resources.dll ()
MOD - C:\WINDOWS\system32\HPBHEALR.DLL ()


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (N360) – C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
SRV - (ServiceLayer) – C:\Programmi\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (MBAMService) – C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Programmi\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ServiceOMC) – C:\WINDOWS\system32\ServiceOMC.exe (Alcatel-Lucent)
SRV - (C-DillaCdaC11BA) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
SRV - (btwdins) – C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe (Broadcom Corporation.)
SRV - (LightScribeService) – C:\Programmi\File comuni\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (IDriverT) – c:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (MDM) – C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (71145046) – File not found
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121027.002\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121029.037\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Programmi\File comuni\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121029.037\NAVENG.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtsp.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121005.002\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\1402000.013\SymEFA.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\1402000.013\SymDS.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\1402000.013\ccSetx86.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\1402000.013\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\1402000.013\Ironx86.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtspx.sys (Symantec Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (SASDIFSV) – C:\Programmi\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Programmi\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (CdaC15BA) – C:\WINDOWS\system32\drivers\CDAC15BA.SYS (Macrovision Europe Ltd)
DRV - (Sentinel) – C:\WINDOWS\system32\drivers\sentinel.sys (SafeNet, Inc.)
DRV - (SNTNLUSB) – C:\WINDOWS\system32\drivers\SNTNLUSB.SYS (SafeNet, Inc.)
DRV - (w39n51) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Accelerometer) – C:\WINDOWS\system32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (hpdskflt) – C:\WINDOWS\system32\drivers\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (PersonalSecureDrive) – C:\WINDOWS\system32\drivers\psd.sys (Infineon Technologies AG)
DRV - (ATSWPDRV) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (GTIPCI21) – C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
IE - HKCU\..\SearchScopes,DefaultScope = {B89C806E-191D-4B7B-B5B1-5AD84BC6716B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{070B5976-6178-46B5-AFAD-CA1F6DCC0674}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SE…b&qsrc=2869
IE - HKCU\..\SearchScopes\{B89C806E-191D-4B7B-B5B1-5AD84BC6716B}: "URL" = http://www.google.it/#hl=it&source=hp&…fca69c98b5d77d7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmi\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programmi\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Programmi\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmi\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\IPSFFPlgn\ [2012/10/27 21.10.26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\coFFPlgn\ [2012/10/30 07.50.15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Programmi\Mozilla Thunderbird\components [2012/07/05 08.44.56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Programmi\Mozilla Thunderbird\plugins

[2011/04/25 07.13.26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Marco\Dati applicazioni\Mozilla\Extensions
[2011/04/25 07.13.26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Marco\Dati applicazioni\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Programmi\Google\Chrome\Application\22.0.1229.96\pdf.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.5.11_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Programmi\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Programmi\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U25 (Enabled) = C:\Programmi\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programmi\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programmi\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Programmi\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Programmi\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Programmi\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Programmi\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Ricerca Google = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Norton Identity Protection = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.0.18_0\
CHR - Extension: Gmail = C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2004/08/19 09.00.00 | 000,000,768 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Supporto di collegamento per Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programmi\Norton 360\Engine\20.2.0.19\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CNavExtBho Class) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll File not found
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (HP Credential Manager for ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Programmi\HPQ\IAM\Bin\ItIeAddIN.dll (Infineon Technologies AG)
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programmi\Norton 360\Engine\20.2.0.19\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Programmi\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [CognizanceTS] C:\Programmi\HPQ\IAM\Bin\AsTsVcc.dll (Cognizance Corporation)
O4 - HKLM..\Run: [Cpqset] C:\Programmi\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PTHOSTTR] C:\Programmi\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\CREATOR\Remind_XP.exe ()
O4 - HKLM..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [WatchDog] C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NokiaSuite.exe] C:\Programmi\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\BTTray.lnk = C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\DVD Check.lnk = C:\Programmi\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Cerca con Google - res://C:\Programmi\Google\GoogleToolbar1.dll/cmsearch.html File not found
O8 - Extra context menu item: &Traduci parola in italiano - res://C:\Programmi\Google\GoogleToolbar1.dll/cmwordtrans.html File not found
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Link a ritroso - res://C:\Programmi\Google\GoogleToolbar1.dll/cmbacklinks.html File not found
O8 - Extra context menu item: Pagine simili - res://C:\Programmi\Google\GoogleToolbar1.dll/cmsimilar.html File not found
O8 - Extra context menu item: Versione cache della pagina - res://C:\Programmi\Google\GoogleToolbar1.dll/cmcache.html File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre6\bin\npjpi160_25.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1303454685312 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1303464635484 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F58BB799-D4B1-4D42-A126-4472CA12FDC3}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programmi\File comuni\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programmi\File comuni\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IfxWlxEN: DllName - (IfxWlxEN.dll) - C:\WINDOWS\System32\IfxWlxEN.dll (Infineon Technologies AG)
O20 - Winlogon\Notify\OneCard: DllName - (C:\Programmi\HPQ\IAM\Bin\AsWlnPkg.dll) - C:\Programmi\HPQ\IAM\Bin\AsWlnPkg.dll (Cognizance Corporation)
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programmi\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 21.07.00 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 13.01.00 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/30 10.58.19 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/30 03.20.38 | 000,000,000 | —D | C] – C:\NBRT
[2012/10/29 17.24.23 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2012/10/29 17.23.31 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NBRTWizard
[2012/10/29 17.23.31 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NBRTWizard\0501000.01A
[2012/10/29 17.23.27 | 000,000,000 | —D | C] – C:\Programmi\Norton Bootable Recovery Tool Wizard
[2012/10/29 17.23.27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Norton Bootable Recovery Tool Wizard
[2012/10/29 17.15.27 | 000,912,040 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/10/29 08.07.40 | 000,000,000 | —D | C] – C:\Programmi\ESET
[2012/10/27 21.09.36 | 000,142,496 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/10/27 21.09.36 | 000,000,000 | —D | C] – C:\Programmi\Symantec
[2012/10/27 21.09.10 | 000,000,000 | —D | C] – C:\Programmi\Norton 360
[2012/10/27 21.09.10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Norton 360
[2012/10/27 21.08.58 | 000,000,000 | —D | C] – C:\Programmi\NortonInstaller
[2012/10/27 16.02.32 | 001,932,256 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/27 15.40.47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware1
[2012/10/27 15.38.30 | 010,669,896 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.29.35 | 000,751,391 | —- | C] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/27 07.47.14 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Documenti\Downloads
[2012/10/27 07.06.28 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/10/26 22.37.24 | 000,177,496 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\59697464.sys
[2012/10/26 20.06.39 | 002,213,464 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe
[2012/10/26 07.24.04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.22.03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Google Chrome
[2012/10/26 07.20.01 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.19.30 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\SUPERAntiSpyware.com
[2012/10/26 07.19.25 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Google
[2012/10/26 07.19.07 | 000,000,000 | —D | C] – C:\Programmi\SUPERAntiSpyware
[2012/10/26 07.19.06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
[2012/10/26 07.17.05 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\Malwarebytes
[2012/10/26 07.16.48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware
[2012/10/26 07.16.47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
[2012/10/26 07.16.46 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/10/26 07.16.46 | 000,000,000 | —D | C] – C:\Programmi\Malwarebytes' Anti-Malware
[2012/10/26 07.09.50 | 021,170,696 | —- | C] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 07.09.04 | 010,669,952 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/25 19.38.36 | 002,957,840 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/25 19.07.50 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Marco\Recent
[2012/10/25 16.50.05 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\NPE
[2012/10/25 15.23.56 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Dati applicazioni\SPE
[2012/10/22 10.50.34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dati applicazioni\BigFishGamesCache
[2012/10/22 07.48.48 | 000,000,000 | —D | C] – C:\Programmi\PC Connectivity Solution
[2012/10/13 07.32.18 | 000,000,000 | —D | C] – C:\Documents and Settings\Marco\Desktop\Tajikistan
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp files -> C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/30 10.58.19 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/30 10.54.27 | 000,625,664 | —- | M] () – C:\Documents and Settings\Marco\Desktop\dds.scr
[2012/10/30 10.34.47 | 000,002,253 | —- | M] () – C:\Documents and Settings\Marco\Desktop\AutoCAD 2004.lnk
[2012/10/30 10.30.00 | 000,001,128 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/30 09.39.24 | 000,000,434 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
[2012/10/30 08.30.00 | 000,001,124 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/30 08.19.00 | 000,000,494 | —- | M] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/30 07.47.03 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/30 07.46.59 | 3623,276,544 | -HS- | M] () – C:\hiberfil.sys
[2012/10/29 17.24.39 | 000,633,238 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\Cat.DB
[2012/10/29 17.16.59 | 000,000,876 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Norton Installation Files.lnk
[2012/10/29 17.16.53 | 000,912,040 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/10/29 15.03.58 | 000,000,211 | —- | M] () – C:\boot.ini
[2012/10/29 14.34.09 | 000,232,776 | -H– | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/29 10.56.51 | 000,041,838 | —- | M] () – C:\Documents and Settings\Marco\Desktop\eset scan.JPG
[2012/10/28 13.09.22 | 002,957,840 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/28 02.00.00 | 000,000,494 | —- | M] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/27 21.13.03 | 000,010,074 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\VT20121008.022
[2012/10/27 21.09.36 | 000,142,496 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/10/27 21.09.36 | 000,007,446 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/10/27 21.09.36 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/10/27 21.09.33 | 000,001,783 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2012/10/27 16.02.33 | 001,932,256 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/27 15.40.47 | 000,000,756 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/27 15.38.32 | 010,669,896 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.31.15 | 002,194,704 | —- | M] () – C:\Documents and Settings\Marco\Desktop\tdsskiller.zip
[2012/10/27 15.29.35 | 000,751,391 | —- | M] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/27 11.30.49 | 000,001,158 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/26 22.37.24 | 000,177,496 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\59697464.sys
[2012/10/26 20.06.48 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe
[2012/10/26 07.22.02 | 000,001,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/26 07.19.15 | 000,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/10/26 07.09.52 | 021,170,696 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 07.09.05 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/25 15.28.07 | 000,000,168 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKsr
[2012/10/25 15.28.06 | 000,000,144 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKs
[2012/10/25 15.27.20 | 000,000,432 | —- | M] () – C:\Documents and Settings\All Users\Dati applicazioni\VRKaEc3r1e3CKs
[2012/10/24 06.57.25 | 000,000,056 | -H– | M] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/10/23 06.52.10 | 000,000,056 | -H– | M] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/10/22 22.56.23 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\isolate.ini
[2012/10/22 09.21.52 | 000,535,028 | —- | M] () – C:\Documents and Settings\Marco\Desktop\DSC_5779.JPG
[2012/10/22 07.51.24 | 000,001,717 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nokia Suite.lnk
[2012/10/22 07.48.31 | 000,633,433 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\Cat.DB
[2012/10/20 10.04.48 | 000,168,136 | —- | M] () – C:\Documents and Settings\Marco\Desktop\bmci.pdf
[2012/10/17 09.20.02 | 003,611,670 | —- | M] () – C:\Documents and Settings\Marco\Desktop\ParcoDushambè2.pdf
[2012/10/16 10.49.47 | 000,284,003 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Camerota castello _2011 Layout2 (1).pdf
[2012/10/16 07.07.59 | 000,010,074 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\VT20121008.022
[2012/10/16 06.58.44 | 000,000,056 | -H– | M] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/10/15 15.47.47 | 002,522,915 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Parco2m_1_2_2733_recover.dwg
[2012/10/15 06.47.02 | 000,000,056 | -H– | M] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/10/13 07.21.10 | 000,000,066 | —- | M] () – C:\WINDOWS\ccolwiz.ini
[2012/10/11 19.52.22 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/11 19.52.22 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/10 21.24.06 | 000,001,393 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2012/10/10 19.25.22 | 000,007,597 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtspx.cat
[2012/10/10 19.25.22 | 000,007,593 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.cat
[2012/10/10 19.25.22 | 000,001,387 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtspx.inf
[2012/10/08 18.52.50 | 000,007,593 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.cat
[2012/10/08 18.52.48 | 000,007,599 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.cat
[2012/10/08 18.00.02 | 000,586,400 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.sys
[2012/10/08 18.00.02 | 000,001,388 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\srtsp.inf
[2012/10/03 18.40.36 | 000,927,904 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.sys
[2012/10/03 18.40.36 | 000,009,103 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymVTcer.dat
[2012/10/03 18.40.36 | 000,003,433 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymEFA.inf
[2012/10/03 18.40.20 | 000,368,288 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.sys
[2012/10/03 18.40.20 | 000,002,851 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\SymDS.inf
[2012/10/03 18.19.14 | 000,134,304 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.sys
[2012/10/03 18.19.14 | 000,007,611 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.cat
[2012/10/03 18.19.14 | 000,000,827 | R— | M] () – C:\WINDOWS\System32\drivers\N360\1402000.013\ccSetx86.inf
[2012/10/03 12.25.20 | 000,000,056 | -H– | M] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2012/10/01 21.25.43 | 000,034,024 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Disegno2tagik.dwg
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp files -> C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/30 10.54.27 | 000,625,664 | —- | C] () – C:\Documents and Settings\Marco\Desktop\dds.scr
[2012/10/29 17.23.31 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\NBRTWizard\0501000.01A\isolate.ini
[2012/10/29 17.16.57 | 000,000,876 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Norton Installation Files.lnk
[2012/10/29 10.56.51 | 000,041,838 | —- | C] () – C:\Documents and Settings\Marco\Desktop\eset scan.JPG
[2012/10/29 08.54.37 | 000,000,434 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
[2012/10/29 07.32.02 | 3623,276,544 | -HS- | C] () – C:\hiberfil.sys
[2012/10/27 21.09.36 | 000,007,446 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/10/27 21.09.36 | 000,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/10/27 21.09.33 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2012/10/27 15.31.14 | 002,194,704 | —- | C] () – C:\Documents and Settings\Marco\Desktop\tdsskiller.zip
[2012/10/26 07.22.01 | 000,001,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/26 07.19.54 | 000,000,494 | —- | C] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/26 07.19.53 | 000,001,128 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/26 07.19.53 | 000,001,124 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/26 07.19.53 | 000,000,494 | —- | C] () – C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/26 07.19.15 | 000,001,642 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/10/26 07.16.48 | 000,000,756 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/25 14.00.52 | 000,000,168 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKsr
[2012/10/25 14.00.52 | 000,000,144 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\-VRKaEc3r1e3CKs
[2012/10/25 14.00.43 | 000,000,432 | —- | C] () – C:\Documents and Settings\All Users\Dati applicazioni\VRKaEc3r1e3CKs
[2012/10/24 06.57.25 | 000,000,056 | -H– | C] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/10/23 06.52.10 | 000,000,056 | -H– | C] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/10/22 09.21.51 | 000,535,028 | —- | C] () – C:\Documents and Settings\Marco\Desktop\DSC_5779.JPG
[2012/10/22 07.51.22 | 000,001,717 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nokia Suite.lnk
[2012/10/20 10.04.46 | 000,168,136 | —- | C] () – C:\Documents and Settings\Marco\Desktop\bmci.pdf
[2012/10/17 09.20.00 | 003,611,670 | —- | C] () – C:\Documents and Settings\Marco\Desktop\ParcoDushambè2.pdf
[2012/10/16 10.49.47 | 000,284,003 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Camerota castello _2011 Layout2 (1).pdf
[2012/10/16 06.58.44 | 000,000,056 | -H– | C] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/10/15 06.47.02 | 000,000,056 | -H– | C] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/10/12 13.58.51 | 002,522,915 | —- | C] () – C:\Documents and Settings\Marco\Desktop\Parco2m_1_2_2733_recover.dwg
[2012/10/03 12.25.20 | 000,000,056 | -H– | C] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2012/09/03 02.44.11 | 000,418,058 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-S-1-5-21-3596313449-3792058534-325310585-1006-0.dat
[2012/09/03 02.44.07 | 000,210,378 | —- | C] () – C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-System.dat
[2012/02/16 11.10.40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/30 08.50.56 | 000,000,126 | —- | C] () – C:\Documents and Settings\Marco\pknet.properties
[2012/01/29 22.46.10 | 000,000,233 | —- | C] () – C:\Documents and Settings\Marco\actalis_ellips_applet.cfg
[2012/01/24 16.01.36 | 000,000,664 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/01/04 10.15.50 | 000,260,531 | -H– | C] () – C:\WINDOWS\System32\ADINIT.dat
[2011/11/02 16.47.56 | 000,000,064 | —- | C] () – C:\WINDOWS\ZMatrixSS.ini
[2011/09/11 08.05.47 | 000,000,066 | —- | C] () – C:\WINDOWS\ccolwiz.ini
[2011/08/24 16.05.33 | 000,000,000 | —- | C] () – C:\WINDOWS\mtstack16.INI
[2011/07/20 08.36.20 | 000,016,384 | —- | C] () – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/14 10.10.01 | 000,000,026 | —- | C] () – C:\WINDOWS\Viewer.INI
[2011/05/09 09.45.45 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/25 07.12.36 | 000,000,000 | -H– | C] () – C:\WINDOWS\nsreg.dat
[2011/04/23 13.46.44 | 000,000,551 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/04/22 18.21.16 | 000,000,350 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2011/04/22 15.52.06 | 000,003,268 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2011/04/22 15.52.06 | 000,001,374 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2011/04/22 05.03.54 | 000,000,060 | -H– | C] () – C:\WINDOWS\System32\SYSDRV.DAT
[2011/04/21 21.15.31 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/04/21 21.15.31 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/04/21 21.15.31 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/04/21 21.15.31 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/04/21 21.15.31 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/04/21 21.15.31 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/04/21 21.13.09 | 000,000,134 | -H– | C] () – C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\fusioncache.dat

========== ZeroAccess Check ==========

[2004/08/30 12.15.14 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 03.13.50 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 11.51.43 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 03.13.56 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011/06/26 16.06.48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Autodesk
[2012/09/01 16.29.57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\HILTI
[2011/04/22 04.44.04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Infineon
[2012/07/02 07.03.30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\Nokia
[2012/03/14 07.44.30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\NokiaInstallerCache
[2012/01/16 22.31.36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\NokiaMusic
[2012/01/16 22.22.48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\OviInstallerCache
[2012/01/18 17.23.37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\PC Suite
[2012/04/23 09.05.14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dati applicazioni\PCSettings
[2011/11/02 16.48.15 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\.ZMatrix
[2011/06/26 15.29.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Autodesk
[2012/10/26 10.14.54 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Dropbox
[2011/04/22 14.45.16 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\ElevatedDiagnostics
[2012/09/01 18.13.00 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\HILTI
[2011/04/22 04.44.12 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Infineon
[2011/04/22 10.27.37 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\InterVideo
[2012/09/01 17.19.50 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\IsolatedStorage
[2012/01/16 23.30.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Nokia
[2012/01/16 23.30.32 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Nokia Suite
[2012/01/18 17.24.55 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\PC Suite
[2006/02/28 14.19.07 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\SampleView
[2012/10/25 15.23.56 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\SPE
[2011/04/25 07.12.31 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Thunderbird
[2011/10/24 11.18.20 | 000,000,000 | —D | M] – C:\Documents and Settings\Marco\Dati applicazioni\Tific

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2004/08/19 14.00.00 | 000,354,809 | -H– | M] () MD5=09CE322E74E2A687F447F6BDFC895840 – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2004/08/19 09.00.00 | 001,034,752 | -H– | M] (Microsoft Corporation) MD5=178D42BD8FC34A9837417A6CE1D6BB7B – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008/04/14 03.14.07 | 001,036,288 | —- | M] (Microsoft Corporation) MD5=70D7F99D95615C3C278367756287DB71 – C:\WINDOWS\explorer.exe
[2008/04/14 03.14.07 | 001,036,288 | —- | M] (Microsoft Corporation) MD5=70D7F99D95615C3C278367756287DB71 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2005/11/03 14.14.42 | 000,000,025 | —- | M] () MD5=B814E2783ABDAB5BBA1D97388A30D2D2 – C:\System.sav\util\tlbxbak\Tools\Explorer.exe
[2005/11/03 14.14.42 | 000,000,025 | —- | M] () MD5=B814E2783ABDAB5BBA1D97388A30D2D2 – C:\WinXP\Explorer.exe

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/10/30 07.48.14 | 000,076,846 | —- | M] () MD5=67DA799D76245BF6DBD19A8F42CB9F17 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.HTM >
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\cs\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.25.42 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\da\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\el\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.08 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\fi\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2003/09/15 12.06.02 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\hu\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.42 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ko\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\nl\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.26.58 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\no\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\pl\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\pt-BR\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\ru\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.27.14 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\sv\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.27.20 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\th\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/20 15.42.18 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\tr\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\zh-CHS\Help\wwhelp\wwhimpl\java\html\explorer.htm
[2005/01/19 16.44.52 | 000,002,057 | -H– | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Programmi\ATI Technologies\ATI.ACE\zh-CHT\Help\wwhelp\wwhimpl\java\html\explorer.htm

< MD5 for: EXPLORER.SC_ >
[2004/08/19 14.00.00 | 000,000,181 | -H– | M] () MD5=5C6C24A90F391A3D958CAD1605FD5FDB – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/08/19 09.00.00 | 000,000,080 | -H– | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CH_ >
[2004/08/19 14.00.00 | 000,224,335 | -H– | M] () MD5=573075BA8B480677694144B0CEA0623F – C:\I386\IEXPLORE.CH_

< MD5 for: IEXPLORE.CHM >
[2009/02/25 01.48.52 | 000,572,668 | -H– | M] () MD5=45B07BA08E9F89AD5D3B76E1C8828846 – C:\WINDOWS\Help\iexplore.chm
[2004/08/19 09.00.00 | 000,230,062 | -H– | M] () MD5=5E98814B178B42C0F67A899F63DE6029 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2004/08/19 14.00.00 | 000,037,905 | -H– | M] () MD5=71849A6EAF126BCF6314B4CE684DDD61 – C:\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2008/04/14 03.14.09 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=173E49AEBB665C0577D751BA55F84B6C – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2012/09/29 18.54.26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Programmi\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 13.09.26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Programmi\Internet Explorer\iexplore.exe
[2009/03/08 13.09.26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/19 09.00.00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=C49ED6E4358FFAECFE70FC8F3C67D224 – C:\WINDOWS\ie8\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13.27.36 | 000,016,384 | -H– | M] (Microsoft Corporation) MD5=D7B502FCEADFEBCC61205F4CF6539AD4 – C:\Programmi\Internet Explorer\iexplore.exe.mui
[2009/03/08 13.27.36 | 000,016,384 | -H– | M] (Microsoft Corporation) MD5=D7B502FCEADFEBCC61205F4CF6539AD4 – C:\Programmi\Internet Explorer\it-IT\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-1BA17782.PF >
[2012/10/30 08.45.27 | 000,148,102 | —- | M] () MD5=84F4788E6F4CF2C1368AFF3D87B82B0F – C:\WINDOWS\Prefetch\IEXPLORE.EXE-1BA17782.pf

< MD5 for: IEXPLORE.HL_ >
[2004/08/19 14.00.00 | 000,063,047 | -H– | M] () MD5=DAB62AE467B3B7106C2347025846C9AC – C:\I386\IEXPLORE.HL_

< MD5 for: IEXPLORE.HLP >
[2004/08/19 09.00.00 | 000,159,620 | —- | M] () MD5=D7656D207B13C79303D246C5BCE452EA – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/19 09.00.00 | 000,007,228 | -H– | M] () MD5=02FE0E4D45682D11EEA9931D79ED9A5F – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES._ >
[2004/08/19 14.00.00 | 000,002,067 | -H– | M] () MD5=B33493B43FC585F4CDD5DF0A37718689 – C:\I386\SERVICES._

< MD5 for: SERVICES.ASFX >
[2012/07/27 21.51.42 | 000,002,605 | -H– | M] () MD5=5A2C5D0DA3EAAB2AA77F16947D0E14FF – C:\Programmi\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx

< MD5 for: SERVICES.ASFX15 >
[2011/06/06 12.55.32 | 000,000,614 | RH– | M] () MD5=DCAF5E14A41328B2A5976377D7DDD969 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA70401B744AA0100000010\10.1.0\services.asfx15

< MD5 for: SERVICES.CFG >
[2012/07/27 21.51.34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Programmi\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12.55.30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA70401B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.DAT >
[2011/04/25 20.39.06 | 000,010,240 | —- | M] () MD5=30DDE7E2E0ED717BB5A43B312028FCB1 – C:\Documents and Settings\Marco\Dati applicazioni\Adobe\Acrobat\10.0\Security\services.dat

< MD5 for: SERVICES.EX_ >
[2004/08/19 14.00.00 | 000,050,027 | -H– | M] () MD5=9358FD486E309E1B94B770A3C1C7AEB0 – C:\I386\SERVICES.EX_

< MD5 for: SERVICES.EXE >
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/09 12.22.49 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=26845F272435302E0F3322E660A24F7D – C:\WINDOWS\system32\services.exe
[2009/02/09 10.50.05 | 000,111,104 | -H– | M] (Microsoft Corporation) MD5=BCF1770A35BDA3BD13A9E2054F15F37E – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/09 12.14.45 | 000,111,104 | —- | M] (Microsoft Corporation) MD5=C79FEAE2F68982259907AB52B0F2676F – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 03.14.19 | 000,109,056 | —- | M] (Microsoft Corporation) MD5=DAC0440C89B1EA4E35684896D5BF856E – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/14 03.14.19 | 000,109,056 | —- | M] (Microsoft Corporation) MD5=DAC0440C89B1EA4E35684896D5BF856E – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2004/08/19 09.00.00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=E77F6FA2A15390F1727F4C1C55B69DA6 – C:\WINDOWS\$NtUninstallKB956572_0$\services.exe

< MD5 for: SERVICES.MS_ >
[2004/08/19 14.00.00 | 000,003,649 | -H– | M] () MD5=CB3B5F917890D80DBA1F29F4DB3682B6 – C:\I386\SERVICES.MS_

< MD5 for: SERVICES.MSC >
[2004/08/19 09.00.00 | 000,033,085 | —- | M] () MD5=B2361B9E56F37FCF691B3700420561D9 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EX_ >
[2004/08/19 14.00.00 | 000,261,187 | -H– | M] () MD5=2B9D78E921AFDEA9A939886DCDF56C2E – C:\I386\WINLOGON.EX_

< MD5 for: WINLOGON.EXE >
[2004/08/19 09.00.00 | 000,504,832 | -H– | M] (Microsoft Corporation) MD5=4166454E2BCFCC20D1B8A5AC9FEAB243 – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/29 18.54.26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Programmi\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 03.14.24 | 000,510,464 | —- | M] (Microsoft Corporation) MD5=9259170D29B5A256735FCB8B80280857 – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 03.14.24 | 000,510,464 | —- | M] (Microsoft Corporation) MD5=9259170D29B5A256735FCB8B80280857 – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2012/10/29 15.03.58 | 000,000,211 | —- | M] () – C:\boot.ini
[1999/04/13 00.12.26 | 000,000,512 | -H– | M] () – C:\Boot32.w2k
[2004/08/19 09.00.00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[1998/10/05 16.32.06 | 000,000,512 | -H– | M] () – C:\bootsec
[1999/04/07 03.34.04 | 000,001,536 | -H– | M] () – C:\BOOTSEC.32
[2011/09/27 13.47.37 | 010,267,648 | -H– | M] () – C:\Documento recuperato 1.doc
[2011/11/27 16.22.50 | 000,012,286 | -H– | M] () – C:\Documento recuperato 1.txt
[2012/07/05 07.01.29 | 000,000,007 | -H– | M] () – C:\Documento recuperato 10.txt
[2012/07/05 07.01.30 | 000,014,552 | -H– | M] () – C:\Documento recuperato 11.txt
[2012/07/05 07.01.31 | 000,000,002 | -H– | M] () – C:\Documento recuperato 12.txt
[2012/07/06 06.54.24 | 000,003,283 | -H– | M] () – C:\Documento recuperato 13.txt
[2012/07/06 06.54.25 | 000,000,005 | -H– | M] () – C:\Documento recuperato 14.txt
[2012/07/06 06.54.30 | 000,003,241 | -H– | M] () – C:\Documento recuperato 15.txt
[2012/07/06 06.54.35 | 000,000,002 | -H– | M] () – C:\Documento recuperato 16.txt
[2012/09/03 12.06.25 | 000,000,025 | -H– | M] () – C:\Documento recuperato 17.txt
[2012/09/21 08.54.37 | 000,017,053 | -H– | M] () – C:\Documento recuperato 18.txt
[2012/09/21 08.54.37 | 000,000,008 | -H– | M] () – C:\Documento recuperato 19.txt
[2012/01/20 07.56.53 | 000,113,888 | -H– | M] () – C:\Documento recuperato 2.txt
[2012/09/21 08.54.39 | 000,016,200 | -H– | M] () – C:\Documento recuperato 20.txt
[2012/09/21 08.54.39 | 000,000,002 | -H– | M] () – C:\Documento recuperato 21.txt
[2012/10/04 12.11.22 | 000,002,274 | -H– | M] () – C:\Documento recuperato 22.txt
[2012/10/05 06.49.43 | 000,003,525 | -H– | M] () – C:\Documento recuperato 23.txt
[2012/10/10 20.35.33 | 000,008,185 | -H– | M] () – C:\Documento recuperato 24.txt
[2012/10/10 20.35.37 | 000,008,039 | -H– | M] () – C:\Documento recuperato 25.txt
[2012/10/10 20.35.37 | 000,000,002 | -H– | M] () – C:\Documento recuperato 26.txt
[2012/10/12 16.12.54 | 000,033,199 | -H– | M] () – C:\Documento recuperato 27.txt
[2012/01/20 07.56.56 | 000,090,956 | -H– | M] () – C:\Documento recuperato 3.txt
[2012/04/06 20.06.01 | 000,006,820 | -H– | M] () – C:\Documento recuperato 4.txt
[2012/01/20 15.51.33 | 000,091,914 | -H– | M] () – C:\Documento recuperato 5.txt
[2012/04/06 20.06.01 | 000,015,179 | -H– | M] () – C:\Documento recuperato 6.txt
[2012/04/12 06.41.22 | 000,023,706 | -H– | M] () – C:\Documento recuperato 7.txt
[2012/04/12 06.41.23 | 000,023,488 | -H– | M] () – C:\Documento recuperato 8.txt
[2012/07/05 07.01.29 | 000,015,670 | -H– | M] () – C:\Documento recuperato 9.txt
[2011/11/27 16.22.48 | 000,012,310 | -H– | M] () – C:\Documento recuperato.txt
[2012/05/14 16.34.21 | 000,007,530 | -H– | M] () – C:\dps.pad
[2012/10/30 07.46.59 | 3623,276,544 | -HS- | M] () – C:\hiberfil.sys
[2011/04/22 15.57.10 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/04/22 15.57.10 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/19 09.00.00 | 000,047,564 | -HS- | M] () – C:\NTDETECT.COM
[2011/04/22 13.06.21 | 000,251,600 | -HS- | M] () – C:\NTLDR
[2012/10/30 07.46.58 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2012/01/29 22.52.30 | 000,004,135 | -H– | M] () – C:\SIAsecure.tok
[2012/10/26 22.37.25 | 000,004,448 | —- | M] () – C:\TDSSKiller.2.8.13.0_26.10.2012_21.06.51_log.txt
[2012/10/27 07.07.22 | 000,205,910 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.05.46_log.txt
[2012/10/27 07.09.00 | 000,103,546 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.07.26_log.txt
[2012/10/27 07.13.39 | 000,004,448 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.13.14_log.txt
[2012/10/27 07.46.15 | 000,119,466 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_08.25.51_log.txt
[2012/10/27 09.59.07 | 000,333,992 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_09.10.16_log.txt
[2012/10/27 14.33.27 | 000,003,756 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_15.33.16_log.txt
[2012/10/27 15.00.56 | 000,117,594 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_15.33.54_log.txt
[2012/10/27 19.17.33 | 000,214,298 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_16.36.03_log.txt
[2012/10/27 20.23.13 | 000,101,692 | —- | M] () – C:\TDSSKiller.2.8.13.0_27.10.2012_21.22.24_log.txt
[2012/10/28 09.49.31 | 000,199,028 | —- | M] () – C:\TDSSKiller.2.8.13.0_28.10.2012_09.47.52_log.txt
[2012/07/31 15.25.05 | 000,000,056 | -H– | M] () – C:\{006D62A9-6D48-4907-B430-A4444814C43B}
[2012/10/23 06.52.10 | 000,000,056 | -H– | M] () – C:\{045BDA75-A73A-4735-B5A2-C951E3A0691D}
[2012/06/29 09.13.00 | 000,000,056 | -H– | M] () – C:\{081B71FB-F92A-4957-9E68-F27A9D5E74E1}
[2012/10/16 06.58.44 | 000,000,056 | -H– | M] () – C:\{118E65A5-F43D-41F5-8E2F-C014BCDE65AD}
[2012/08/01 15.35.32 | 000,000,056 | -H– | M] () – C:\{3018C3D5-465E-46AC-9C65-0F81523A07E0}
[2012/09/16 06.34.58 | 000,000,056 | -H– | M] () – C:\{39546EFA-056C-4EAE-8F50-3901877259E9}
[2011/10/13 07.25.27 | 000,000,056 | -H– | M] () – C:\{3C0B3BE5-289E-4FBF-B9CC-0D4A558E55F2}
[2012/09/23 09.05.53 | 000,000,056 | -H– | M] () – C:\{43E7740E-4CA8-42A6-86AC-83A8FD6B4EE3}
[2012/05/17 13.21.22 | 000,000,056 | -H– | M] () – C:\{4610592A-EACB-4EB9-BAFF-E784857A831C}
[2012/06/21 10.16.58 | 000,000,056 | -H– | M] () – C:\{57A154CD-5FAA-40F5-BFB7-429C78669257}
[2012/07/03 07.16.59 | 000,000,056 | -H– | M] () – C:\{6DE2C036-3841-4D67-9DE9-BA8A3EA0C6DA}
[2012/07/01 14.40.33 | 000,000,056 | -H– | M] () – C:\{793858B2-B508-4A28-BB5D-C51A58BE807C}
[2012/09/29 13.38.59 | 000,000,056 | -H– | M] () – C:\{83F285CB-260B-4833-BFD9-92B53722461F}
[2012/10/24 06.57.25 | 000,000,056 | -H– | M] () – C:\{85812078-F51C-434F-A845-FDB50CE3CA74}
[2012/07/10 13.23.10 | 000,000,056 | -H– | M] () – C:\{963DE796-D4F2-4CCA-9DDD-0AB4C1914C8F}
[2012/01/20 08.29.21 | 000,000,792 | -H– | M] () – C:\{B0D18835-8531-4EDB-8F9D-38EFFCC3EE0B}
[2011/05/12 10.44.37 | 000,009,744 | -H– | M] () – C:\{B1C62062-28E6-4362-B45B-6521E079B3BB}
[2012/09/05 07.04.50 | 000,000,056 | -H– | M] () – C:\{B2B91FFD-9E59-4990-A725-90BD0079A7D3}
[2012/07/07 14.30.03 | 000,000,056 | -H– | M] () – C:\{B5F69271-2FB9-40BF-B4C9-D7BA4774C1F2}
[2012/08/14 08.08.21 | 000,000,056 | -H– | M] () – C:\{B8BB83CD-F8B3-48CE-BFA9-341D8A4AC483}
[2012/08/06 06.36.08 | 000,000,056 | -H– | M] () – C:\{BC8CAC7B-6E48-4BAD-866D-1ECEEA29FEC1}
[2012/10/15 06.47.02 | 000,000,056 | -H– | M] () – C:\{C2DEBB06-EA83-41C3-8462-BDB11EBF293A}
[2012/07/13 08.07.08 | 000,000,056 | -H– | M] () – C:\{C61D3825-40EE-44C9-9D08-1EBFE16D6084}
[2012/05/08 09.51.11 | 000,000,056 | -H– | M] () – C:\{D93B4F7D-7E8C-4094-8298-B34D94A96438}
[2012/07/15 16.59.41 | 000,000,056 | -H– | M] () – C:\{F4AD72CA-903F-410B-A856-7DB0AB3CB554}
[2012/05/09 12.38.30 | 000,000,056 | -H– | M] () – C:\{F8D856C8-3CA1-47E0-BF2A-36150EBA317E}
[2012/02/06 08.27.40 | 000,000,288 | -H– | M] () – C:\{FCCB1DBD-1D2D-4897-BB34-CBF584FCF98E}
[2012/09/04 06.39.47 | 000,000,056 | -H– | M] () – C:\{FDA14E6F-1144-49AE-9ED0-B5F3E8AA994B}
[2012/10/03 12.25.20 | 000,000,056 | -H– | M] () – C:\{FFA92799-A496-4A4E-9B3A-96525B6D9F03}
[2011/09/27 10.08.35 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 1.doc
[2011/11/27 16.22.50 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 1.txt
[2012/07/06 06.54.35 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 16.txt
[2012/09/03 12.06.25 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 17.txt
[2012/09/21 08.54.39 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 21.txt
[2012/10/05 06.49.43 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 23.txt
[2012/10/10 20.35.37 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 25.txt
[2012/10/10 20.35.37 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 26.txt
[2012/10/12 16.12.54 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 27.txt
[2012/01/20 15.51.33 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 5.txt
[2012/04/12 06.41.22 | 000,000,162 | -H– | M] () – C:\~$cumento recuperato 7.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14.39.28 | 000,026,040 | -H– | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13.53.56 | 000,026,489 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14.39.28 | 000,029,779 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13.58.52 | 000,030,808 | -H– | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/30 12.07.18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13.06.10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2002/01/10 09.08.34 | 000,046,592 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpprn02.dll
[2004/06/01 13.55.56 | 000,061,952 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp35z.dll
[2008/07/06 11.50.03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2003/05/25 17.46.42 | 000,065,536 | —- | M] (Happy Dude) – C:\WINDOWS\ZMatrixSS.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/30 13.54.42 | 000,094,208 | -H– | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/30 13.54.42 | 000,638,976 | -H– | M] () – C:\WINDOWS\System32\config\software.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/21 21.16.13 | 000,000,123 | -HS- | M] () – C:\Documents and Settings\Marco\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/30 12.13.52 | 000,000,079 | —- | M] () – C:\Documents and Settings\Marco\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\Mostra Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/10/27 16.02.33 | 001,932,256 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\FixTDSS.exe
[2012/10/26 07.09.05 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/27 15.38.32 | 010,669,896 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Marco\Desktop\mbam-setup.exe
[2012/10/27 15.29.35 | 000,751,391 | —- | M] (Farbar) – C:\Documents and Settings\Marco\Desktop\MiniToolBox.exe
[2012/10/29 17.16.53 | 000,912,040 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NBRT-Retail-Downloader.exe
[2012/01/16 23.20.22 | 092,199,288 | —- | M] () – C:\Documents and Settings\Marco\Desktop\Nokia_Suite_webinstaller_ALL.exe
[2012/10/28 13.09.22 | 002,957,840 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Marco\Desktop\NPE.exe
[2012/10/30 10.58.19 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Marco\Desktop\OTL.exe
[2012/10/26 07.09.52 | 021,170,696 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Marco\Desktop\SUPERAntiSpyware.exe
[2012/10/26 20.06.48 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Marco\Desktop\tdsskiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-10-10 20:30:32

< >
[2004/08/19 09.00.00 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\desktop.ini
[2004/08/30 12.26.48 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2012/10/26 07.19.53 | 000,000,494 | —- | C] () – C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
[2012/10/26 07.19.53 | 000,001,124 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2012/10/26 07.19.53 | 000,001,128 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2012/10/26 07.19.54 | 000,000,494 | —- | C] () – C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
[2012/10/29 08.54.37 | 000,000,434 | -H– | C] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job

< End of report >




OTL Extras logfile created on: 30/10/2012 11.10.05 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Marco\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

3,37 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 70,53% Memory free
5,21 Gb Paging File | 4,11 Gb Available in Paging File | 78,83% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 120,17 Gb Total Space | 13,53 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
Drive D: | 7,81 Gb Total Space | 0,71 Gb Free Space | 9,05% Space Free | Partition Type: FAT32
Drive G: | 468,17 Gb Total Space | 468,07 Gb Free Space | 99,98% Space Free | Partition Type: NTFS

Computer Name: NX9420 | User Name: Marco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Servizio di condivisione in rete Windows Media Player

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\WINDOWS\SMINST\Scheduler.exe" = C:\WINDOWS\SMINST\Scheduler.exe:*:Enabled:Scheduler – ()
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Documents and Settings\Marco\Dati applicazioni\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Marco\Dati applicazioni\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"E:\D-Link.exe" = E:\D-Link.exe:*:Enabled:D-Link Click'n Connect
"C:\Programmi\Skype\Phone\Skype.exe" = C:\Programmi\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0315DA0A-C9CD-4FCA-A762-CE25FB8954AB}" = PCXTools OMC 810 22.1a
"{0515803B-5068-4599-8666-963E143C7381}" = HP Smart Card Security for ProtectTools 5.00 D4
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{0906982B-A432-4C06-8F01-C01BE1143779}" = Nokia Connectivity Cable Driver
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1F89F212-2052-414A-8B7E-D8604C431BDF}" = HP User Guides 0013
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{2298055A-F5E6-4332-9A15-C5D99870E72F}" = HP Embedded Security for ProtectTools
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 25
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33EBF075-8593-4698-BDAF-CF8DED80BB5B}" = Nokia Suite
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.00 B2
"{350C9410-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DF12C94-8D3D-43D4-AF3C-754F51CB89CD}" = HP Install Network Printer Wizard
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = HP Integrated Module with Bluetooth wireless technology
"{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = Installer HP Backup and Recovery Manager
"{404C18ED-873A-4191-BA03-30F627445418}" = Sentinel Protection Installer 7.3.0
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 C1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50D25574-2C48-4AEC-8FFC-32AEAD2EAEFF}" = Nokia Ovi Player
"{5783F2D7-0201-0410-0002-0060B0CE6BBA}" = AutoCAD 2004
"{5783F2D7-0211-0409-0000-0060B0CE6BBA}" = AutoCAD Express Tools Volumes 1-9
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6C943D33-4B89-49A7-9126-2C59EBE64B81}" = StruM.I.S.NET
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{70B31335-50EE-4834-8431-27412CDE62BD}" = Nokia_Multimedia_Common_Components_2_5
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75ECB75A-522C-4312-8DE7-597CDA9D96A3}" = HP Mobile Data Protection System
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110410-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{90120000-0020-0410-0000-0000000FF1CE}" = Pacchetto di compatibilità per Office System 2007
"{914E1AB1-DCA0-4A7D-935F-B58C4B887A2B}" = HP ProtectTools Security Manager 2.00 B3
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A7AD8CEF-72D7-4FE4-8A14-DDD09DC86074}" = HP Notebook Accessories Product Tour
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AC76BA86-7AD7-1040-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Italiano
"{AE052EF7-2640-48D7-8915-69B810D975CB}" = HP BIOS Configuration for ProtectTools 2.00 C2
"{AE1B3F7B-CF35-4195-9D30-ED08A4BA892E}" = ATI Catalyst Control Center
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B9F4C05D-E42F-4E9A-A73F-FDD9355319FB}" = HP Credential Manager for ProtectTools
"{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}" = PC Connectivity Solution
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F2D2B58B-B2FD-46D1-8319-DCE564079934}" = Microsoft .NET Framework 1.1 Italian Language Pack
"{FF94AAB0-EC20-484C-A470-FFC06561F227}" = Strucad V14
"17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382" = Pacchetto driver Windows - Nokia pccsmcfd “LegacyDriver” (05/31/2012 7.1.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"ATI Display Driver" = ATI Display Driver
"Autodesk Express Viewer" = Autodesk Express Viewer
"Baldur's Gate" = Baldur's Gate
"CdaC13Ba" = SafeCast Shared Components
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA_hpq0033m" = HDAUDIO Soft Data Fax Modem with SmartCP
"ESET Online Scanner" = ESET Online Scanner v3
"ie8" = Windows Internet Explorer 8
"InstallShield_{6C943D33-4B89-49A7-9126-2C59EBE64B81}" = StruCad Estimating
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FF94AAB0-EC20-484C-A470-FFC06561F227}" = Strucad V14
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versione 1.65.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Thunderbird 15.0.1 (x86 it)" = Mozilla Thunderbird 15.0.1 (x86 it)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"N360" = Norton 360
"NBRTWizard" = Norton Bootable Recovery Tool Wizard
"Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM
"NeroVision!UninstallKey" = Ahead NeroVision Express
"NMIX!UninstallKey" = Ahead NeroMIX
"NMPUninstallKey" = Ahead NeroMediaPlayer
"Nokia Suite" = Nokia Suite
"ST6UNST #1" = PacchettoComune
"ST6UNST #2" = Profili_v6
"ST6UNST #3" = Telaio2D
"ST6UNST #4" = TraveConDwg Ver. 7.4
"ST6UNST #5" = Muro
"ST6UNST #6" = 1CAMP
"ST6UNST #7" = ConfiguraDvbTco
"ST6UNST #8" = VcaSlu
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Zip Repair Tool_is1" = Zip Repair Tool v.3.2
"ZMatrix_is1" = ZMatrix 1.5.2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Cened+" = Cened+
"Dropbox" = Dropbox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 29/10/2012 9.36.25 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.

Error - 29/10/2012 9.36.25 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 29/10/2012 10.10.27 | Computer Name = NX9420 | Source = LoadPerf | ID =
3013

Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 29/10/2012 10.10.27 | Computer Name = NX9420 | Source = LoadPerf | ID =
3009

Error - 29/10/2012 11.23.36 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.

Error - 29/10/2012 11.23.36 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 29/10/2012 11.24.23 | Computer Name = NX9420 | Source = LoadPerf | ID =
3013

Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 29/10/2012 11.24.23 | Computer Name = NX9420 | Source = LoadPerf | ID =
3009

Error - 30/10/2012 2.47.26 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.

Error - 30/10/2012 2.47.26 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009
Error - 30/10/2012 2.49.37 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013

Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID lingua 009.
Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione dati.
Error - 30/10/2012 2.49.37 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009

Error - 30/10/2012 2.49.56 | Computer Name = NX9420 | Source = LoadPerf | ID = 3013
Description = Impossibile aggiornare le stringhe del contatore prestazioni dell'ID
lingua 009. Lo stato Win32 restituito dalla chiamata è il primo DWORD della sezione
dati.

Error - 30/10/2012 2.49.56 | Computer Name = NX9420 | Source = LoadPerf | ID = 3009

Error encountered while reading event logs.

< End of report >


Can someone help me? MANY THANKS in advance
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Sorry for any delay! :)

Please download TDSSKiller
  • Double click TDSSKiller.exe
  • When the window opens, click on Change Parameters
  • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
  • Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct
    items.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Hi Jeff and thankyou, sorry for the delai: yesterday i worked at home (preparing for winter) and didn't open pc, so here my scan result. 10:58:56.0578 4232 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 10:58:56.0625 4232 ============================================================ 10:58:56.0625 4232 Current date / time: 2012/11/02 10:58:56.0625 10:58:56.0625 4232 SystemInfo: 10:58:56.0625 4232 10:58:56.0625 4232 OS Version: 5.1.2600 ServicePack: 3.0 10:58:56.0625 4232 Product type: Workstation 10:58:56.0625 4232 ComputerName: NX9420 10:58:56.0625 4232 UserName: Marco 10:58:56.0625 4232 Windows directory: C:\WINDOWS 10:58:56.0625 4232 System windows directory: C:\WINDOWS 10:58:56.0625 4232 Processor architecture: Intel x86 10:58:56.0625 4232 Number of processors: 2 10:58:56.0625 4232 Page size: 0x1000 10:58:56.0625 4232 Boot type: Normal boot 10:58:56.0625 4232 ============================================================ 10:58:58.0812 4232 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x14301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050 10:58:58.0828 4232 ============================================================ 10:58:58.0828 4232 \Device\Harddisk0\DR0: 10:58:58.0828 4232 MBR partitions: 10:58:58.0828 4232 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xF058581 10:58:58.0828 4232 \Device\Harddisk0\DR0\Partition2: MBR, Type 0xC, StartLBA 0xF0585FF, BlocksNum 0xFA5291 10:58:58.0843 4232 ============================================================ 10:58:58.0906 4232 C: <-> \Device\Harddisk0\DR0\Partition1 10:58:58.0921 4232 D: <-> \Device\Harddisk0\DR0\Partition2 10:58:58.0921 4232 ============================================================ 10:58:58.0921 4232 Initialize success 10:58:58.0921 4232 ============================================================ 11:01:27.0375 4488 ============================================================ 11:01:27.0375 4488 Scan started 11:01:27.0375 4488 Mode: Manual; TDLFS; 11:01:27.0375 4488 ============================================================ 11:01:27.0546 4488 ================ Scan system memory ======================== 11:01:27.0562 4488 System memory - ok 11:01:27.0562 4488 ================ Scan services ============================= 11:01:27.0656 4488 71145046 - ok 11:01:27.0656 4488 Abiosdsk - ok 11:01:27.0656 4488 abp480n5 - ok 11:01:27.0687 4488 [ 2AD11B75224BC6C54735FB6853105B8B ] Accelerometer C:\WINDOWS\system32\DRIVERS\Accelerometer.sys 11:01:27.0703 4488 Accelerometer - ok 11:01:27.0734 4488 [ D766E636187B8F240BBFBABCD51EB2C6 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 11:01:27.0734 4488 ACPI - ok 11:01:27.0750 4488 [ 49AC5CD87FBDDA62F3E25190019E7627 ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 11:01:27.0750 4488 ACPIEC - ok 11:01:27.0750 4488 [ 584544EDD609CEAC24156F4C3B4CF5AA ] ADIHdAudAddService C:\WINDOWS\system32\drivers\ADIHdAud.sys 11:01:27.0765 4488 ADIHdAudAddService - ok 11:01:27.0765 4488 adpu160m - ok 11:01:27.0765 4488 [ C984DE22ED71414ABC42C1E03D412E33 ] AEAudioService C:\WINDOWS\system32\drivers\AEAudio.sys 11:01:27.0781 4488 AEAudioService - ok 11:01:27.0781 4488 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 11:01:27.0781 4488 aec - ok 11:01:27.0812 4488 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 11:01:27.0828 4488 AFD - ok 11:01:27.0843 4488 Aha154x - ok 11:01:27.0843 4488 aic78u2 - ok 11:01:27.0843 4488 aic78xx - ok 11:01:27.0875 4488 [ 14A077AD0CF6116D1102631D8E1EDEE8 ] Alerter C:\WINDOWS\system32\alrsvc.dll 11:01:27.0875 4488 Alerter - ok 11:01:27.0890 4488 [ 79FE2E0D7859738225816658F0BB2A0D ] ALG C:\WINDOWS\System32\alg.exe 11:01:27.0890 4488 ALG - ok 11:01:27.0890 4488 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys 11:01:27.0890 4488 AliIde - ok 11:01:27.0906 4488 amsint - ok 11:01:27.0906 4488 AppMgmt - ok 11:01:27.0906 4488 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys 11:01:27.0921 4488 Arp1394 - ok 11:01:27.0921 4488 asc - ok 11:01:27.0937 4488 asc3350p - ok 11:01:27.0937 4488 asc3550 - ok 11:01:28.0015 4488 [ 47589CC135E28532AFC39394BBF87F0D ] ASChannel C:\Programmi\HPQ\IAM\Bin\ASChnl.dll 11:01:28.0015 4488 ASChannel - ok 11:01:28.0109 4488 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 11:01:28.0140 4488 aspnet_state - ok 11:01:28.0156 4488 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 11:01:28.0156 4488 AsyncMac - ok 11:01:28.0187 4488 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 11:01:28.0187 4488 atapi - ok 11:01:28.0187 4488 Atdisk - ok 11:01:28.0234 4488 [ 1345218AE88C039FED6BE0E99C70A5A8 ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe 11:01:28.0234 4488 Ati HotKey Poller - ok 11:01:28.0312 4488 [ B428DCE21561DD9EDD42878DC9B7603A ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 11:01:28.0328 4488 ati2mtag - ok 11:01:28.0343 4488 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 11:01:28.0359 4488 Atmarpc - ok 11:01:28.0359 4488 [ 4AE213E390888B090D38DE37921ED53F ] ATSWPDRV C:\WINDOWS\system32\Drivers\ATSwpDrv.sys 11:01:28.0375 4488 ATSWPDRV - ok 11:01:28.0406 4488 [ 1B58D118049304E88464BE614C6D0014 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 11:01:28.0406 4488 AudioSrv - ok 11:01:28.0406 4488 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 11:01:28.0406 4488 audstub - ok 11:01:28.0421 4488 [ C0ACD392ECE55784884CC208AAFA06CE ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys 11:01:28.0421 4488 b57w2k - ok 11:01:28.0437 4488 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 11:01:28.0437 4488 Beep - ok 11:01:28.0578 4488 [ 684B12018A54ADC1F856372EC5762B48 ] BHDrvx86 C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121005.002\BHDrvx86.sys 11:01:28.0578 4488 BHDrvx86 - ok 11:01:28.0625 4488 [ 48C4763A9C8990FB48B73445BEB15D6A ] BITS C:\WINDOWS\system32\qmgr.dll 11:01:28.0656 4488 BITS - ok 11:01:28.0687 4488 [ F934D1B230F84E1D19DD00AC5A7A83ED ] Bridge C:\WINDOWS\system32\DRIVERS\bridge.sys 11:01:28.0687 4488 Bridge - ok 11:01:28.0687 4488 [ F934D1B230F84E1D19DD00AC5A7A83ED ] BridgeMP C:\WINDOWS\system32\DRIVERS\bridge.sys 11:01:28.0687 4488 BridgeMP - ok 11:01:28.0718 4488 [ 076D11B52F066ED33E3A80F8070A3E2E ] Browser C:\WINDOWS\System32\browser.dll 11:01:28.0718 4488 Browser - ok 11:01:28.0765 4488 [ 853712261A42074E144CA66E4FD17C09 ] btaudio C:\WINDOWS\system32\drivers\btaudio.sys 11:01:28.0765 4488 btaudio - ok 11:01:28.0781 4488 [ 552D5C78B072B4DE9BB563B43A715ACA ] BTDriver C:\WINDOWS\system32\DRIVERS\btport.sys 11:01:28.0796 4488 BTDriver - ok 11:01:28.0828 4488 [ 42884A5E3555CFEC2E97CB08C7CD8957 ] BTKRNL C:\WINDOWS\system32\DRIVERS\btkrnl.sys 11:01:28.0843 4488 BTKRNL - ok 11:01:28.0890 4488 [ D2467DBABD2D6064085C3F38036C4683 ] btwdins C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe 11:01:28.0890 4488 btwdins - ok 11:01:28.0921 4488 [ 288140799F62F8841F7C8944BF1C9195 ] BTWDNDIS C:\WINDOWS\system32\DRIVERS\btwdndis.sys 11:01:28.0921 4488 BTWDNDIS - ok 11:01:28.0953 4488 [ 14684EB96FB2CFA9DB145E82682A1182 ] btwmodem C:\WINDOWS\system32\DRIVERS\btwmodem.sys 11:01:28.0953 4488 btwmodem - ok 11:01:28.0984 4488 [ 1F5796135B955348BA0622D2EACE3E47 ] BTWUSB C:\WINDOWS\system32\Drivers\btwusb.sys 11:01:28.0984 4488 BTWUSB - ok 11:01:29.0015 4488 [ 9BDBDA21D3BA8E374FD06A405BE10215 ] C-DillaCdaC11BA C:\WINDOWS\system32\drivers\CDAC11BA.EXE 11:01:29.0015 4488 C-DillaCdaC11BA - ok 11:01:29.0046 4488 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 11:01:29.0046 4488 cbidf2k - ok 11:01:29.0093 4488 [ 1277AD8F053CC60C17CAFAB411F3CF40 ] ccSet_N360 C:\WINDOWS\system32\drivers\N360\1402000.013\ccSetx86.sys 11:01:29.0109 4488 ccSet_N360 - ok 11:01:29.0109 4488 cd20xrnt - ok 11:01:29.0125 4488 [ F76CB7259AA575CC53F3996BC6B68C18 ] CdaC15BA C:\WINDOWS\system32\drivers\CDAC15BA.SYS 11:01:29.0125 4488 CdaC15BA - ok 11:01:29.0140 4488 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 11:01:29.0140 4488 Cdaudio - ok 11:01:29.0156 4488 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 11:01:29.0156 4488 Cdfs - ok 11:01:29.0171 4488 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 11:01:29.0171 4488 Cdrom - ok 11:01:29.0187 4488 Changer - ok 11:01:29.0203 4488 [ D04F2BEB5EA63D0766E12E44AEF7C38D ] CiSvc C:\WINDOWS\system32\cisvc.exe 11:01:29.0203 4488 CiSvc - ok 11:01:29.0218 4488 [ 48CB1DEFA1A6506C3CF09E4950F82EF6 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 11:01:29.0218 4488 ClipSrv - ok 11:01:29.0265 4488 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 11:01:29.0296 4488 clr_optimization_v2.0.50727_32 - ok 11:01:29.0328 4488 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 11:01:29.0406 4488 clr_optimization_v4.0.30319_32 - ok 11:01:29.0437 4488 [ 0F6C187D38D98F8DF904589A5F94D411 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 11:01:29.0437 4488 CmBatt - ok 11:01:29.0437 4488 CmdIde - ok 11:01:29.0453 4488 [ 6E4C9F21F0FAE8940661144F41B13203 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 11:01:29.0453 4488 Compbatt - ok 11:01:29.0468 4488 COMSysApp - ok 11:01:29.0484 4488 Cpqarray - ok 11:01:29.0515 4488 [ B6FCBB157E9C8ABDCA4134C535535A8B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 11:01:29.0515 4488 CryptSvc - ok 11:01:29.0531 4488 dac2w2k - ok 11:01:29.0531 4488 dac960nt - ok 11:01:29.0578 4488 [ BC4E0226341AAEC1222336B3AED86BAB ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 11:01:29.0578 4488 DcomLaunch - ok 11:01:29.0609 4488 [ 699EE7F752A25180AEB92C3A0EAEE440 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 11:01:29.0609 4488 Dhcp - ok 11:01:29.0625 4488 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 11:01:29.0625 4488 Disk - ok 11:01:29.0687 4488 [ 244B6285B14E06A9BA81B3ED9B9A3B38 ] DLABOIOM C:\WINDOWS\system32\DLA\DLABOIOM.SYS 11:01:29.0687 4488 DLABOIOM - ok 11:01:29.0703 4488 [ D979BEBCF7EDCC9C9EE1857D1A68C67B ] DLACDBHM C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 11:01:29.0703 4488 DLACDBHM - ok 11:01:29.0718 4488 [ 04DEE88CF4B91367559B6AFBB4472228 ] DLADResN C:\WINDOWS\system32\DLA\DLADResN.SYS 11:01:29.0718 4488 DLADResN - ok 11:01:29.0734 4488 [ 46CDF41AB0F616168F2C03EDB590643A ] DLAIFS_M C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 11:01:29.0734 4488 DLAIFS_M - ok 11:01:29.0750 4488 [ 94F39387819A9AE05C788CFD7EA4E16B ] DLAOPIOM C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 11:01:29.0750 4488 DLAOPIOM - ok 11:01:29.0750 4488 [ F4DCC4DF6B27EE4E3D08258ECDDECB1F ] DLAPoolM C:\WINDOWS\system32\DLA\DLAPoolM.SYS 11:01:29.0765 4488 DLAPoolM - ok 11:01:29.0765 4488 [ 7EE0852AE8907689DF25049DCD2342E8 ] DLARTL_N C:\WINDOWS\system32\Drivers\DLARTL_N.SYS 11:01:29.0765 4488 DLARTL_N - ok 11:01:29.0781 4488 [ BDE11A8C697C5E22AEDF34CA3FDB5940 ] DLAUDFAM C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 11:01:29.0781 4488 DLAUDFAM - ok 11:01:29.0796 4488 [ 069D67EED1CEC572DC28CB5582B5AA96 ] DLAUDF_M C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 11:01:29.0796 4488 DLAUDF_M - ok 11:01:29.0796 4488 dmadmin - ok 11:01:29.0843 4488 [ 82BC125A8ED33F5F0E75F2AAC1065323 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 11:01:29.0859 4488 dmboot - ok 11:01:29.0875 4488 [ E959DDC0EA7AC11EE5E5602E2A364310 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 11:01:29.0875 4488 dmio - ok 11:01:29.0906 4488 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 11:01:29.0906 4488 dmload - ok 11:01:29.0937 4488 [ A01858C50704B2D2EDEEBBF6BBBCED2A ] dmserver C:\WINDOWS\System32\dmserver.dll 11:01:29.0937 4488 dmserver - ok 11:01:29.0968 4488 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 11:01:29.0968 4488 DMusic - ok 11:01:29.0984 4488 [ B7A1162B1A26DF7B60D5D9500006096C ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 11:01:29.0984 4488 Dnscache - ok 11:01:30.0015 4488 [ D580D77DFF316BD8C9D73B38695DE8DC ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 11:01:30.0031 4488 Dot3svc - ok 11:01:30.0078 4488 [ 3E4B043F8BC6BE1D4820CC6C9C500306 ] dot4 C:\WINDOWS\system32\DRIVERS\Dot4.sys 11:01:30.0078 4488 dot4 - ok 11:01:30.0093 4488 [ 77CE63A8A34AE23D9FE4C7896D1DEBE7 ] Dot4Print C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys 11:01:30.0109 4488 Dot4Print - ok 11:01:30.0140 4488 [ 707E8402ECAF9C87A7DD15615F0CFEA2 ] dot4usb C:\WINDOWS\system32\DRIVERS\dot4usb.sys 11:01:30.0140 4488 dot4usb - ok 11:01:30.0140 4488 dpti2o - ok 11:01:30.0187 4488 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 11:01:30.0187 4488 drmkaud - ok 11:01:30.0218 4488 [ FE923D5529144D47B907663D2838C032 ] DRVMCDB C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 11:01:30.0218 4488 DRVMCDB - ok 11:01:30.0218 4488 [ B4869D320428CDC5EC4D7F5E808E99B5 ] DRVNDDM C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 11:01:30.0234 4488 DRVNDDM - ok 11:01:30.0250 4488 [ B5CB3084046146FD2587D8C9B219FEB4 ] eabfiltr C:\WINDOWS\system32\DRIVERS\eabfiltr.sys 11:01:30.0250 4488 eabfiltr - ok 11:01:30.0265 4488 [ 231F4547AE1E4B3E60ECA66C3A96D218 ] eabusb C:\WINDOWS\system32\DRIVERS\eabusb.sys 11:01:30.0265 4488 eabusb - ok 11:01:30.0281 4488 [ 86B1F123BACD444E81960B339BAE3FF2 ] EapHost C:\WINDOWS\System32\eapsvc.dll 11:01:30.0281 4488 EapHost - ok 11:01:30.0359 4488 [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl C:\Programmi\File comuni\Symantec Shared\EENGINE\eeCtrl.sys 11:01:30.0359 4488 eeCtrl - ok 11:01:30.0390 4488 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 11:01:30.0390 4488 EraserUtilRebootDrv - ok 11:01:30.0421 4488 [ B6599EDA9F3EBEF064504EE35BBECA1C ] ERSvc C:\WINDOWS\System32\ersvc.dll 11:01:30.0421 4488 ERSvc - ok 11:01:30.0453 4488 [ 26845F272435302E0F3322E660A24F7D ] Eventlog C:\WINDOWS\system32\services.exe 11:01:30.0453 4488 Eventlog - ok 11:01:30.0484 4488 [ 8360CB9756E598A5C6214EACFB3677C3 ] EventSystem C:\WINDOWS\system32\es.dll 11:01:30.0484 4488 EventSystem - ok 11:01:30.0500 4488 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 11:01:30.0515 4488 Fastfat - ok 11:01:30.0546 4488 [ DCCC606FC144F6E44E497F9A906F1C30 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 11:01:30.0546 4488 FastUserSwitchingCompatibility - ok 11:01:30.0578 4488 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 11:01:30.0578 4488 Fdc - ok 11:01:30.0609 4488 [ 2CFEA3326981A18C6BAF2BD9BE76225B ] Fips C:\WINDOWS\system32\drivers\Fips.sys 11:01:30.0609 4488 Fips - ok 11:01:30.0625 4488 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 11:01:30.0625 4488 Flpydisk - ok 11:01:30.0640 4488 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 11:01:30.0640 4488 FltMgr - ok 11:01:30.0703 4488 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 11:01:30.0718 4488 FontCache3.0.0.0 - ok 11:01:30.0734 4488 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 11:01:30.0734 4488 Fs_Rec - ok 11:01:30.0750 4488 [ F3269A6EE547EA87B949A1CEA4816B38 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 11:01:30.0750 4488 Ftdisk - ok 11:01:30.0781 4488 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 11:01:30.0781 4488 GEARAspiWDM - ok 11:01:30.0796 4488 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 11:01:30.0812 4488 Gpc - ok 11:01:30.0828 4488 [ B6B1F53F585B41091EB3586F8297A379 ] GTIPCI21 C:\WINDOWS\system32\DRIVERS\gtipci21.sys 11:01:30.0843 4488 GTIPCI21 - ok 11:01:30.0875 4488 [ ED32D389F8B0E74E400932E020BCFBDF ] Hardlock C:\WINDOWS\system32\drivers\hardlock.sys 11:01:30.0890 4488 Hardlock - ok 11:01:30.0906 4488 [ 4D4D97671C63C3AF869B3518E6054204 ] HBtnKey C:\WINDOWS\system32\DRIVERS\cpqbttn.sys 11:01:30.0906 4488 HBtnKey - ok 11:01:30.0937 4488 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 11:01:30.0953 4488 HDAudBus - ok 11:01:31.0031 4488 [ 6CE66B51B4EB23D9D073F92698C55C8D ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 11:01:31.0031 4488 helpsvc - ok 11:01:31.0062 4488 [ 43D985A9A51E0295091B6EBE84C96B78 ] HidServ C:\WINDOWS\System32\hidserv.dll 11:01:31.0062 4488 HidServ - ok 11:01:31.0109 4488 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 11:01:31.0109 4488 HidUsb - ok 11:01:31.0140 4488 [ 00CAD842F48947887A972828ACA665F7 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 11:01:31.0140 4488 hkmsvc - ok 11:01:31.0156 4488 [ B5E68A5D9E0AAC82E4DDD340E1F0274A ] hpdskflt C:\WINDOWS\system32\DRIVERS\hpdskflt.sys 11:01:31.0171 4488 hpdskflt - ok 11:01:31.0171 4488 hpn - ok 11:01:31.0218 4488 [ 85DD9EDBB1A035BA9B0E9FCC70624990 ] hpqwmi C:\Programmi\HPQ\Shared\hpqwmi.exe 11:01:31.0218 4488 hpqwmi - ok 11:01:31.0281 4488 [ 4A8E6BCFD119BC4BD2EB251ECD49FFCB ] hpqwmiex C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe 11:01:31.0281 4488 hpqwmiex - ok 11:01:31.0312 4488 [ 89E256C5F5346BE265D9F86AC8625D4F ] HSFHWAZL C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 11:01:31.0312 4488 HSFHWAZL - ok 11:01:31.0343 4488 [ 0E44AF3828111D4C3E73C33AC95226D8 ] HSF_DPV C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 11:01:31.0359 4488 HSF_DPV - ok 11:01:31.0406 4488 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 11:01:31.0406 4488 HTTP - ok 11:01:31.0437 4488 [ 450091AEBFCD08E5858533EAB5B9A436 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 11:01:31.0437 4488 HTTPFilter - ok 11:01:31.0437 4488 i2omgmt - ok 11:01:31.0453 4488 i2omp - ok 11:01:31.0468 4488 [ 610726E28AF55B95043C5C35A727E320 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 11:01:31.0468 4488 i8042prt - ok 11:01:31.0515 4488 [ 309C4D86D989FB1FCF64BD30DC81C51B ] iaStor C:\WINDOWS\system32\DRIVERS\iaStor.sys 11:01:31.0531 4488 iaStor - ok 11:01:31.0593 4488 [ 6F95324909B502E2651442C1548AB12F ] IDriverT c:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe 11:01:31.0593 4488 IDriverT - ok 11:01:31.0671 4488 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 11:01:31.0687 4488 idsvc - ok 11:01:31.0765 4488 [ C19BF2A07BE972A110220DF6B1E89D14 ] IDSxpx86 C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121101.001\IDSxpx86.sys 11:01:31.0765 4488 IDSxpx86 - ok 11:01:31.0812 4488 [ FF9F7B9FD77A6F26BDE91A33A348404C ] IFXSpMgtSrv C:\WINDOWS\system32\IFXSPMGT.exe 11:01:31.0828 4488 IFXSpMgtSrv - ok 11:01:31.0859 4488 [ E80B373A6B42C2274AE85379173F0204 ] IFXTCS C:\WINDOWS\system32\IFXTCS.exe 11:01:31.0859 4488 IFXTCS - ok 11:01:31.0890 4488 [ 0B556E950404D90D097C687E65238730 ] IFXTPM C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS 11:01:31.0906 4488 IFXTPM - ok 11:01:31.0906 4488 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 11:01:31.0906 4488 Imapi - ok 11:01:31.0937 4488 [ DB491237445F172FDDDF00541DE1A51D ] ImapiService C:\WINDOWS\system32\imapi.exe 11:01:31.0937 4488 ImapiService - ok 11:01:31.0953 4488 ini910u - ok 11:01:31.0984 4488 [ 027FE9B28FB0F861C181D25923B31E78 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys 11:01:31.0984 4488 IntelIde - ok 11:01:32.0015 4488 [ EBD830A0970C438047006A49C23E287F ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 11:01:32.0015 4488 intelppm - ok 11:01:32.0031 4488 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 11:01:32.0046 4488 Ip6Fw - ok 11:01:32.0062 4488 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 11:01:32.0062 4488 IpFilterDriver - ok 11:01:32.0078 4488 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 11:01:32.0078 4488 IpInIp - ok 11:01:32.0093 4488 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 11:01:32.0093 4488 IpNat - ok 11:01:32.0109 4488 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 11:01:32.0109 4488 IPSec - ok 11:01:32.0125 4488 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 11:01:32.0125 4488 IRENUM - ok 11:01:32.0140 4488 [ 0953594BEB81CC72FCC62D37921B25A6 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 11:01:32.0140 4488 isapnp - ok 11:01:32.0203 4488 [ 11C3EFB4BAC41175D03B1595DB1A4A4F ] JavaQuickStarterService C:\Programmi\Java\jre6\bin\jqs.exe 11:01:32.0203 4488 JavaQuickStarterService - ok 11:01:32.0218 4488 [ 28B6EACE513CA7EABA3B809AD4BC274D ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 11:01:32.0218 4488 Kbdclass - ok 11:01:32.0234 4488 [ 4C61C226BDDA2EF1672B2C5F4E56625E ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 11:01:32.0234 4488 kbdhid - ok 11:01:32.0250 4488 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 11:01:32.0250 4488 kmixer - ok 11:01:32.0265 4488 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 11:01:32.0281 4488 KSecDD - ok 11:01:32.0312 4488 [ 0F726D49C0B19E5A506A1CDFCE0EE42F ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 11:01:32.0312 4488 lanmanserver - ok 11:01:32.0328 4488 [ E13B0181DDA60B93E3253EFF52A79CBE ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 11:01:32.0343 4488 lanmanworkstation - ok 11:01:32.0343 4488 lbrtfdc - ok 11:01:32.0406 4488 [ 9696786759C4B43FA5C894747E893EA2 ] LightScribeService C:\Programmi\File comuni\LightScribe\LSSrvc.exe 11:01:32.0406 4488 LightScribeService - ok 11:01:32.0437 4488 [ E01255727D0B158538D7C2B469B533A8 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 11:01:32.0437 4488 LmHosts - ok 11:01:32.0468 4488 [ 500D089CE760D83DA2B6CBA681AA9949 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys 11:01:32.0468 4488 MBAMProtector - ok 11:01:32.0500 4488 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe 11:01:32.0515 4488 MBAMScheduler - ok 11:01:32.0546 4488 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe 11:01:32.0546 4488 MBAMService - ok 11:01:32.0593 4488 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe 11:01:32.0593 4488 MDM - ok 11:01:32.0640 4488 [ 3C318B9CD391371BED62126581EE9961 ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 11:01:32.0640 4488 mdmxsdk - ok 11:01:32.0656 4488 [ 3B32F662C8607E891F325E41F7EE225C ] Messenger C:\WINDOWS\System32\msgsvc.dll 11:01:32.0671 4488 Messenger - ok 11:01:32.0687 4488 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 11:01:32.0687 4488 mnmdd - ok 11:01:32.0718 4488 [ 514A299EC926BAADA3C718B171476AA4 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 11:01:32.0718 4488 mnmsrvc - ok 11:01:32.0734 4488 [ 8CB6636806D76B85FAFAEE94D75F5129 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 11:01:32.0734 4488 Modem - ok 11:01:32.0765 4488 [ E904EBED608055A2BFB824C07F59766C ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 11:01:32.0765 4488 Mouclass - ok 11:01:32.0781 4488 [ D7662F0CF5B77BBBE3202716F5BD5318 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 11:01:32.0781 4488 mouhid - ok 11:01:32.0812 4488 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 11:01:32.0812 4488 MountMgr - ok 11:01:32.0812 4488 mraid35x - ok 11:01:32.0828 4488 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 11:01:32.0828 4488 MRxDAV - ok 11:01:32.0859 4488 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 11:01:32.0875 4488 MRxSmb - ok 11:01:32.0890 4488 [ 01F77E9E473235C31796ADE46107B0AD ] MSDTC C:\WINDOWS\system32\msdtc.exe 11:01:32.0890 4488 MSDTC - ok 11:01:32.0906 4488 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 11:01:32.0906 4488 Msfs - ok 11:01:32.0906 4488 MSIServer - ok 11:01:32.0937 4488 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 11:01:32.0937 4488 MSKSSRV - ok 11:01:32.0953 4488 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 11:01:32.0953 4488 MSPCLOCK - ok 11:01:32.0968 4488 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 11:01:32.0968 4488 MSPQM - ok 11:01:32.0984 4488 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 11:01:32.0984 4488 mssmbios - ok 11:01:33.0015 4488 MSSQLSERVER - ok 11:01:33.0062 4488 [ CB7524C21727404BD3140DCA32DEB7DE ] MSSQLServerADHelper C:\Programmi\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe 11:01:33.0062 4488 MSSQLServerADHelper - ok 11:01:33.0109 4488 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 11:01:33.0109 4488 Mup - ok 11:01:33.0171 4488 [ 4A9258B9597A31DB68EC9740F3A8A70B ] N360 C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe 11:01:33.0171 4488 N360 - ok 11:01:33.0203 4488 [ 911587FD303C9690A428BB4B04732B61 ] napagent C:\WINDOWS\System32\qagentrt.dll 11:01:33.0218 4488 napagent - ok 11:01:33.0312 4488 [ 8E4C77AD9BB279900C00F870CC0C674B ] NAVENG C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121101.032\NAVENG.SYS 11:01:33.0312 4488 NAVENG - ok 11:01:33.0375 4488 [ 826F699B69E88A3920C70F344DD42D88 ] NAVEX15 C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121101.032\NAVEX15.SYS 11:01:33.0390 4488 NAVEX15 - ok 11:01:33.0421 4488 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 11:01:33.0421 4488 NDIS - ok 11:01:33.0468 4488 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 11:01:33.0468 4488 NdisTapi - ok 11:01:33.0468 4488 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 11:01:33.0484 4488 Ndisuio - ok 11:01:33.0500 4488 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 11:01:33.0500 4488 NdisWan - ok 11:01:33.0515 4488 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 11:01:33.0515 4488 NDProxy - ok 11:01:33.0546 4488 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 11:01:33.0546 4488 NetBIOS - ok 11:01:33.0562 4488 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 11:01:33.0562 4488 NetBT - ok 11:01:33.0593 4488 [ 1B09227E41F414A93DBC0BAF80C4D527 ] NetDDE C:\WINDOWS\system32\netdde.exe 11:01:33.0609 4488 NetDDE - ok 11:01:33.0609 4488 [ 1B09227E41F414A93DBC0BAF80C4D527 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 11:01:33.0609 4488 NetDDEdsdm - ok 11:01:33.0640 4488 [ 0FBA335727905DE8E4CB5A2CF438ABF5 ] Netlogon C:\WINDOWS\system32\lsass.exe 11:01:33.0640 4488 Netlogon - ok 11:01:33.0656 4488 [ 02815B70FC4CA8611A926176F1C39FC2 ] Netman C:\WINDOWS\System32\netman.dll 11:01:33.0656 4488 Netman - ok 11:01:33.0718 4488 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 11:01:33.0750 4488 NetTcpPortSharing - ok 11:01:33.0765 4488 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys 11:01:33.0765 4488 NIC1394 - ok 11:01:33.0796 4488 [ C6B69A18D39744725FB73AC85E46032B ] Nla C:\WINDOWS\System32\mswsock.dll 11:01:33.0796 4488 Nla - ok 11:01:33.0828 4488 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 11:01:33.0828 4488 Npfs - ok 11:01:33.0843 4488 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 11:01:33.0859 4488 Ntfs - ok 11:01:33.0875 4488 [ 0FBA335727905DE8E4CB5A2CF438ABF5 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 11:01:33.0875 4488 NtLmSsp - ok 11:01:33.0921 4488 [ 89DB90B5F35D2795D9FC56D933CC72B8 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 11:01:33.0937 4488 NtmsSvc - ok 11:01:33.0968 4488 [ CF7E041663119E09D2E118521ADA9300 ] NuidFltr C:\WINDOWS\system32\DRIVERS\NuidFltr.sys 11:01:33.0968 4488 NuidFltr - ok 11:01:34.0000 4488 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 11:01:34.0000 4488 Null - ok 11:01:34.0031 4488 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 11:01:34.0031 4488 NwlnkFlt - ok 11:01:34.0046 4488 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 11:01:34.0046 4488 NwlnkFwd - ok 11:01:34.0062 4488 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys 11:01:34.0062 4488 ohci1394 - ok 11:01:34.0093 4488 [ 4E9408A178B2D955871C2CDD278DE3C3 ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 11:01:34.0093 4488 Parport - ok 11:01:34.0109 4488 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 11:01:34.0109 4488 PartMgr - ok 11:01:34.0125 4488 [ 0DABEF655A444CB1E193626FB1D24B9F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 11:01:34.0125 4488 ParVdm - ok 11:01:34.0171 4488 [ 5EEB45F500E3E97153CB75723F8CA185 ] PCA C:\WINDOWS\SMINST\PCAngel.exe 11:01:34.0187 4488 PCA - ok 11:01:34.0203 4488 [ F451DCACBAA67F3307305EBD4A39EA07 ] pccsmcfd C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys 11:01:34.0203 4488 pccsmcfd - ok 11:01:34.0203 4488 [ F40A46892AFEBB0314536B849D57C11E ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 11:01:34.0218 4488 PCI - ok 11:01:34.0218 4488 PCIDump - ok 11:01:34.0218 4488 [ B2DF00D650FD6C4EE781740ED3C8E67F ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 11:01:34.0234 4488 PCIIde - ok 11:01:34.0234 4488 [ 815C50F2B1D1562800BDCE8BE895000E ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys 11:01:34.0234 4488 Pcmcia - ok 11:01:34.0250 4488 PDCOMP - ok 11:01:34.0250 4488 PDFRAME - ok 11:01:34.0265 4488 PDRELI - ok 11:01:34.0265 4488 PDRFRAME - ok 11:01:34.0265 4488 perc2 - ok 11:01:34.0281 4488 perc2hib - ok 11:01:34.0312 4488 [ 9F09361EEAE6180CCDC8E99BAC641943 ] PersonalSecureDrive C:\WINDOWS\System32\drivers\psd.sys 11:01:34.0312 4488 PersonalSecureDrive - ok 11:01:34.0375 4488 [ 2A8335EE3997E72690394D86258814A2 ] PersonalSecureDriveService C:\Programmi\ProtectTools\Embedded Security Software\PSDsrvc.EXE 11:01:34.0375 4488 PersonalSecureDriveService - ok 11:01:34.0390 4488 [ 26845F272435302E0F3322E660A24F7D ] PlugPlay C:\WINDOWS\system32\services.exe 11:01:34.0406 4488 PlugPlay - ok 11:01:34.0406 4488 [ 0FBA335727905DE8E4CB5A2CF438ABF5 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 11:01:34.0406 4488 PolicyAgent - ok 11:01:34.0437 4488 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 11:01:34.0437 4488 PptpMiniport - ok 11:01:34.0453 4488 [ 0FBA335727905DE8E4CB5A2CF438ABF5 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 11:01:34.0453 4488 ProtectedStorage - ok 11:01:34.0453 4488 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 11:01:34.0453 4488 PSched - ok 11:01:34.0484 4488 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 11:01:34.0484 4488 Ptilink - ok 11:01:34.0500 4488 [ 86724469CD077901706854974CD13C3E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 11:01:34.0500 4488 PxHelp20 - ok 11:01:34.0500 4488 ql1080 - ok 11:01:34.0515 4488 Ql10wnt - ok 11:01:34.0515 4488 ql12160 - ok 11:01:34.0515 4488 ql1240 - ok 11:01:34.0531 4488 ql1280 - ok 11:01:34.0546 4488 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 11:01:34.0546 4488 RasAcd - ok 11:01:34.0593 4488 [ 9839B418343D6E6E52659BDF3FF1FE67 ] RasAuto C:\WINDOWS\System32\rasauto.dll 11:01:34.0593 4488 RasAuto - ok 11:01:34.0625 4488 [ 0207D26DDF796A193CCD9F83047BB5FC ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys 11:01:34.0625 4488 Rasirda - ok 11:01:34.0640 4488 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 11:01:34.0656 4488 Rasl2tp - ok 11:01:34.0687 4488 [ 62AD41548E720DB4763B86F95E44F3FA ] RasMan C:\WINDOWS\System32\rasmans.dll 11:01:34.0687 4488 RasMan - ok 11:01:34.0703 4488 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 11:01:34.0703 4488 RasPppoe - ok 11:01:34.0718 4488 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 11:01:34.0718 4488 Raspti - ok 11:01:34.0734 4488 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 11:01:34.0750 4488 Rdbss - ok 11:01:34.0750 4488 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 11:01:34.0750 4488 RDPCDD - ok 11:01:34.0781 4488 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 11:01:34.0781 4488 RDPWD - ok 11:01:34.0812 4488 [ CC72E6AE90245F0AE48BF1236A7E1F9C ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 11:01:34.0812 4488 RDSessMgr - ok 11:01:34.0828 4488 [ 393FC252593323B624B230ECA6B85E63 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 11:01:34.0828 4488 redbook - ok 11:01:34.0843 4488 [ 7EBBF16FBD3E0E34F084FA635C1844E3 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 11:01:34.0859 4488 RemoteAccess - ok 11:01:34.0875 4488 [ F17713D108ACA124A139FDE877EEF68A ] RimUsb C:\WINDOWS\system32\Drivers\RimUsb.sys 11:01:34.0875 4488 RimUsb - ok 11:01:34.0906 4488 [ DC97F6C8A94691834439872B9E8FF2B3 ] RpcLocator C:\WINDOWS\system32\locator.exe 11:01:34.0906 4488 RpcLocator - ok 11:01:34.0937 4488 [ BC4E0226341AAEC1222336B3AED86BAB ] RpcSs C:\WINDOWS\system32\rpcss.dll 11:01:34.0937 4488 RpcSs - ok 11:01:34.0968 4488 [ DCE0D20F8FB66DF41D53734BFF9D66F0 ] RSVP C:\WINDOWS\system32\rsvp.exe 11:01:34.0984 4488 RSVP - ok 11:01:35.0000 4488 [ 0FBA335727905DE8E4CB5A2CF438ABF5 ] SamSs C:\WINDOWS\system32\lsass.exe 11:01:35.0000 4488 SamSs - ok 11:01:35.0046 4488 [ 39763504067962108505BFF25F024345 ] SASDIFSV C:\Programmi\SUPERAntiSpyware\SASDIFSV.SYS 11:01:35.0046 4488 SASDIFSV - ok 11:01:35.0078 4488 [ 77B9FC20084B48408AD3E87570EB4A85 ] SASKUTIL C:\Programmi\SUPERAntiSpyware\SASKUTIL.SYS 11:01:35.0078 4488 SASKUTIL - ok 11:01:35.0093 4488 [ 1D456F1CD76A80793C07BA52CF3A7455 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 11:01:35.0093 4488 SCardSvr - ok 11:01:35.0140 4488 [ 511886E5BD060046CCE8373E92E62EDF ] Schedule C:\WINDOWS\system32\schedsvc.dll 11:01:35.0140 4488 Schedule - ok 11:01:35.0171 4488 [ 8D04819A3CE51B9EB47E5689B44D43C4 ] sdbus C:\WINDOWS\system32\DRIVERS\sdbus.sys 11:01:35.0171 4488 sdbus - ok 11:01:35.0203 4488 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 11:01:35.0203 4488 Secdrv - ok 11:01:35.0218 4488 [ 17C6354CA08E7C7972E12C67478AE134 ] seclogon C:\WINDOWS\System32\seclogon.dll 11:01:35.0234 4488 seclogon - ok 11:01:35.0250 4488 [ A0ECA1CE0FCCB29C5E4E1F416E95E73E ] SENS C:\WINDOWS\system32\sens.dll 11:01:35.0265 4488 SENS - ok 11:01:35.0312 4488 [ 7E5C2C58FC4E3862E7BF88BFB809A9B0 ] Sentinel C:\WINDOWS\System32\Drivers\SENTINEL.SYS 11:01:35.0312 4488 Sentinel - ok 11:01:35.0328 4488 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 11:01:35.0328 4488 serenum - ok 11:01:35.0359 4488 [ FDBD9D64E2E03270021D424F0DCCF79D ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 11:01:35.0359 4488 Serial - ok 11:01:35.0421 4488 [ 9BDE8F1F5D060E912FCF9FB58B71CBC1 ] ServiceLayer C:\Programmi\PC Connectivity Solution\ServiceLayer.exe 11:01:35.0437 4488 ServiceLayer - ok 11:01:35.0484 4488 [ C73D743CB826E683BC120285F742A513 ] ServiceOMC C:\WINDOWS\system32\ServiceOMC.exe 11:01:35.0484 4488 ServiceOMC - ok 11:01:35.0500 4488 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\DRIVERS\sfloppy.sys 11:01:35.0500 4488 Sfloppy - ok 11:01:35.0546 4488 [ 152C0555925DFE028E3148FD215146BB ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 11:01:35.0546 4488 SharedAccess - ok 11:01:35.0562 4488 [ DCCC606FC144F6E44E497F9A906F1C30 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 11:01:35.0578 4488 ShellHWDetection - ok 11:01:35.0578 4488 Simbad - ok 11:01:35.0640 4488 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Programmi\Skype\Updater\Updater.exe 11:01:35.0656 4488 SkypeUpdate - ok 11:01:35.0671 4488 [ F67092C18B1E1EE4D73447F293970A79 ] SMCIRDA C:\WINDOWS\system32\DRIVERS\smcirda.sys 11:01:35.0671 4488 SMCIRDA - ok 11:01:35.0718 4488 [ 1475A9533649935A048EA5E27F8C3B37 ] SNTNLUSB C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS 11:01:35.0718 4488 SNTNLUSB - ok 11:01:35.0718 4488 Sparrow - ok 11:01:35.0750 4488 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 11:01:35.0828 4488 splitter - ok 11:01:35.0875 4488 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 11:01:35.0875 4488 Spooler - ok 11:01:35.0875 4488 SQLSERVERAGENT - ok 11:01:35.0906 4488 [ 618718CAE288BF7CBD8FCBAB2577D932 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 11:01:35.0906 4488 sr - ok 11:01:35.0937 4488 [ B3E3DA70A7A76E69B872DE3D06D32C19 ] srservice C:\WINDOWS\system32\srsvc.dll 11:01:35.0953 4488 srservice - ok 11:01:36.0015 4488 [ 26C1B59C80FEF94B025DF5C3C1B791A7 ] SRTSP C:\WINDOWS\system32\drivers\N360\1402000.013\SRTSP.SYS 11:01:36.0031 4488 SRTSP - ok 11:01:36.0062 4488 [ 21AC3AE81E8263061624C4ED3B11509A ] SRTSPX C:\WINDOWS\system32\drivers\N360\1402000.013\SRTSPX.SYS 11:01:36.0062 4488 SRTSPX - ok 11:01:36.0093 4488 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 11:01:36.0109 4488 Srv - ok 11:01:36.0140 4488 [ 5215569DD3A8FBC65A85E85F3C12258B ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 11:01:36.0140 4488 SSDPSRV - ok 11:01:36.0171 4488 [ 3B9263E137896E4D303494F116E00608 ] stisvc C:\WINDOWS\system32\wiaservc.dll 11:01:36.0187 4488 stisvc - ok 11:01:36.0203 4488 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 11:01:36.0203 4488 swenum - ok 11:01:36.0234 4488 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 11:01:36.0234 4488 swmidi - ok 11:01:36.0234 4488 SwPrv - ok 11:01:36.0250 4488 symc810 - ok 11:01:36.0250 4488 symc8xx - ok 11:01:36.0312 4488 [ FB69A67FEEE3026C7F99774A1C405326 ] SymDS C:\WINDOWS\system32\drivers\N360\1402000.013\SYMDS.SYS 11:01:36.0312 4488 SymDS - ok 11:01:36.0421 4488 [ 28C5FAFA7FD1C522B8DCD59694D39412 ] SymEFA C:\WINDOWS\system32\drivers\N360\1402000.013\SYMEFA.SYS 11:01:36.0437 4488 SymEFA - ok 11:01:36.0468 4488 [ C940F10C31E2C60CC967FFD6A370720C ] SymEvent C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 11:01:36.0468 4488 SymEvent - ok 11:01:36.0484 4488 [ 8C9B9036E301A9965CF15BEC91C58A12 ] SymIRON C:\WINDOWS\system32\drivers\N360\1402000.013\Ironx86.SYS 11:01:36.0500 4488 SymIRON - ok 11:01:36.0531 4488 [ EC979002EBA25C9D109B2FE0E03457DA ] SYMTDI C:\WINDOWS\system32\drivers\N360\1402000.013\SYMTDI.SYS 11:01:36.0546 4488 SYMTDI - ok 11:01:36.0546 4488 sym_hi - ok 11:01:36.0546 4488 sym_u3 - ok 11:01:36.0593 4488 [ FD5010A627D2A7BBD1C44A488E3A8FE5 ] SynTP C:\WINDOWS\system32\DRIVERS\SynTP.sys 11:01:36.0593 4488 SynTP - ok 11:01:36.0625 4488 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 11:01:36.0625 4488 sysaudio - ok 11:01:36.0671 4488 [ A34A9A872EEC4C026FD542AC7156FE0B ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 11:01:36.0671 4488 SysmonLog - ok 11:01:36.0718 4488 [ 6B85F1A9DCE45D45BFFAD3222C21F297 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 11:01:36.0734 4488 TapiSrv - ok 11:01:36.0765 4488 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 11:01:36.0781 4488 Tcpip - ok 11:01:36.0796 4488 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 11:01:36.0796 4488 TDPIPE - ok 11:01:36.0828 4488 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 11:01:36.0828 4488 TDTCP - ok 11:01:36.0828 4488 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 11:01:36.0843 4488 TermDD - ok 11:01:36.0875 4488 [ FE5A5329CCFC33D645C33077FF04F052 ] TermService C:\WINDOWS\System32\termsrv.dll 11:01:36.0875 4488 TermService - ok 11:01:36.0890 4488 [ DCCC606FC144F6E44E497F9A906F1C30 ] Themes C:\WINDOWS\System32\shsvcs.dll 11:01:36.0906 4488 Themes - ok 11:01:36.0921 4488 [ 9179E07503630D6FB2E4162FF0196191 ] tifm21 C:\WINDOWS\system32\drivers\tifm21.sys 11:01:36.0937 4488 tifm21 - ok 11:01:36.0937 4488 TosIde - ok 11:01:36.0953 4488 [ 690294999DF1248FAF85D95B31955D0C ] TrkWks C:\WINDOWS\system32\trkwks.dll 11:01:36.0968 4488 TrkWks - ok 11:01:36.0984 4488 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 11:01:37.0000 4488 Udfs - ok 11:01:37.0000 4488 ultra - ok 11:01:37.0046 4488 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 11:01:37.0046 4488 Update - ok 11:01:37.0078 4488 [ 8057B0744D9842A090E51D2845861D5F ] upnphost C:\WINDOWS\System32\upnphost.dll 11:01:37.0078 4488 upnphost - ok 11:01:37.0109 4488 [ F5E8B846EC10E1DF8DCA64119E2EB709 ] UPS C:\WINDOWS\System32\ups.exe 11:01:37.0109 4488 UPS - ok 11:01:37.0140 4488 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 11:01:37.0140 4488 usbccgp - ok 11:01:37.0156 4488 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 11:01:37.0156 4488 usbehci - ok 11:01:37.0171 4488 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 11:01:37.0187 4488 usbhub - ok 11:01:37.0203 4488 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 11:01:37.0203 4488 usbscan - ok 11:01:37.0234 4488 [ 1C888B000C2F9492F4B15B5B6B84873E ] usbser C:\WINDOWS\system32\drivers\usbser.sys 11:01:37.0234 4488 usbser - ok 11:01:37.0250 4488 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 11:01:37.0250 4488 USBSTOR - ok 11:01:37.0281 4488 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 11:01:37.0281 4488 usbuhci - ok 11:01:37.0296 4488 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 11:01:37.0296 4488 VgaSave - ok 11:01:37.0312 4488 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys 11:01:37.0312 4488 ViaIde - ok 11:01:37.0328 4488 [ E46C1B5A56DA7DA603D09DFCC79EC59E ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 11:01:37.0328 4488 VolSnap - ok 11:01:37.0343 4488 [ C2FE17125256102F5B44194D5DB0A799 ] VSS C:\WINDOWS\System32\vssvc.exe 11:01:37.0359 4488 VSS - ok 11:01:37.0375 4488 [ 2969DD84B584A6BB541A5273103957A3 ] W32Time C:\WINDOWS\system32\w32time.dll 11:01:37.0390 4488 W32Time - ok 11:01:37.0453 4488 [ B1F126E7E28877106D60E6FF3998D033 ] w39n51 C:\WINDOWS\system32\DRIVERS\w39n51.sys 11:01:37.0484 4488 w39n51 - ok 11:01:37.0500 4488 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 11:01:37.0500 4488 Wanarp - ok 11:01:37.0546 4488 [ D918617B46457B9AC28027722E30F647 ] Wdf01000 C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 11:01:37.0546 4488 Wdf01000 - ok 11:01:37.0546 4488 WDICA - ok 11:01:37.0578 4488 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 11:01:37.0578 4488 wdmaud - ok 11:01:37.0625 4488 [ 2EC50EE79B65F60C8E8B4A03BBB3A42F ] WebClient C:\WINDOWS\System32\webclnt.dll 11:01:37.0640 4488 WebClient - ok 11:01:37.0656 4488 [ 214BC3AD84907AD6AD655AC5465F449A ] winachsf C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 11:01:37.0671 4488 winachsf - ok 11:01:37.0734 4488 [ 40911E98D0F1CBB1015F2101982F1DDF ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 11:01:37.0734 4488 winmgmt - ok 11:01:37.0796 4488 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 11:01:37.0796 4488 WmdmPmSN - ok 11:01:37.0812 4488 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 11:01:37.0812 4488 WmiAcpi - ok 11:01:37.0828 4488 [ 81FD02839FDB10ACF0EC40B809B9F8CC ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 11:01:37.0828 4488 WmiApSrv - ok 11:01:37.0906 4488 [ F30DC8F80CF65A323E8B6A2DB81561E3 ] WMPNetworkSvc C:\Programmi\Windows Media Player\WMPNetwk.exe 11:01:37.0921 4488 WMPNetworkSvc - ok 11:01:37.0968 4488 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys 11:01:37.0968 4488 WpdUsb - ok 11:01:38.0015 4488 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 11:01:38.0046 4488 WPFFontCache_v0400 - ok 11:01:38.0093 4488 [ 926D921C93CFF1E19EF4DE3E4C8368CA ] wscsvc C:\WINDOWS\system32\wscsvc.dll 11:01:38.0093 4488 wscsvc - ok 11:01:38.0125 4488 [ CC48415E6C7CBAA441A3D6A6DCCBCFA6 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 11:01:38.0140 4488 wuauserv - ok 11:01:38.0171 4488 [ EAA6324F51214D2F6718977EC9CE0DEF ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 11:01:38.0171 4488 WudfPf - ok 11:01:38.0187 4488 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 11:01:38.0203 4488 WudfSvc - ok 11:01:38.0234 4488 [ 053E0307A08CAC60793E27E921B46B3E ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 11:01:38.0234 4488 WZCSVC - ok 11:01:38.0250 4488 [ 5526482DCBA6047641B13BF9C75A74E0 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 11:01:38.0265 4488 xmlprov - ok 11:01:38.0281 4488 ================ Scan global =============================== 11:01:38.0312 4488 [ 17DDFE6A0B5404C5EF4C03AD996D0562 ] C:\WINDOWS\system32\basesrv.dll 11:01:38.0343 4488 [ 7B39F8912DF2C266411F7248EC250AE6 ] C:\WINDOWS\system32\winsrv.dll 11:01:38.0359 4488 [ 7B39F8912DF2C266411F7248EC250AE6 ] C:\WINDOWS\system32\winsrv.dll 11:01:38.0375 4488 [ 26845F272435302E0F3322E660A24F7D ] C:\WINDOWS\system32\services.exe 11:01:38.0375 4488 [Global] - ok 11:01:38.0375 4488 ================ Scan MBR ================================== 11:01:38.0375 4488 [ A0EA0378FDA342F3B16A929327613908 ] \Device\Harddisk0\DR0 11:01:38.0671 4488 \Device\Harddisk0\DR0 - ok 11:01:38.0671 4488 ================ Scan VBR ================================== 11:01:38.0671 4488 [ 66C7762E5CFE622F90E5934A5E364752 ] \Device\Harddisk0\DR0\Partition1 11:01:38.0671 4488 \Device\Harddisk0\DR0\Partition1 - ok 11:01:38.0703 4488 [ 189397632A4FC68BDB5531E58D84931C ] \Device\Harddisk0\DR0\Partition2 11:01:38.0703 4488 \Device\Harddisk0\DR0\Partition2 - ok 11:01:38.0703 4488 ============================================================ 11:01:38.0703 4488 Scan finished 11:01:38.0703 4488 ============================================================ 11:01:38.0718 4464 Detected object count: 0 11:01:38.0718 4464 Actual detected object count: 0
Hi,

No problem….I have been sick so I wasn't on much yesterday either. :)

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
4. If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.
———-
Hi, hope today you 're right. I've done here my report:

ComboFix 12-11-02.02 - Marco 02/11/2012 13.27.11.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.3455.2468 [GMT 1:00]
Eseguito da: c:\documents and settings\Marco\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\VRKaEc3r1e3CKs
c:\documents and settings\Marco\WINDOWS
c:\windows\dasetup.log
c:\windows\IsUn0410.exe
c:\windows\system32\regobj.dll
c:\windows\system32\SET37D.tmp
c:\windows\system32\SET37F.tmp
c:\windows\system32\SET382.tmp
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Creati Da 2012-10-02 al 2012-11-02 )))))))))))))))))))))))))))))))))))
.
.
2012-10-30 19:43 . 2012-10-30 19:43 ——– d—–w- c:\programmi\Microsoft Download Manager
2012-10-30 02:20 . 2012-10-30 02:21 ——– d—–w- C:\NBRT
2012-10-29 16:24 . 2012-07-26 05:32 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-29 16:24 . 2012-07-26 05:32 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2012-10-29 16:23 . 2012-10-29 16:23 ——– d—–w- c:\windows\system32\drivers\NBRTWizard
2012-10-29 16:23 . 2012-10-29 16:23 ——– d—–w- c:\programmi\Norton Bootable Recovery Tool Wizard
2012-10-29 07:07 . 2012-10-29 07:07 ——– d—–w- c:\programmi\ESET
2012-10-28 19:29 . 2012-10-30 02:22 ——– d—–w- c:\documents and settings\Administrator
2012-10-27 20:09 . 2012-10-27 20:09 142496 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-10-27 20:09 . 2012-10-27 20:09 ——– d—–w- c:\programmi\Symantec
2012-10-27 20:09 . 2012-10-27 20:13 ——– d—–w- c:\windows\system32\drivers\N360\1402000.013
2012-10-27 20:09 . 2012-10-27 20:09 ——– d—–w- c:\programmi\Norton 360
2012-10-27 20:08 . 2012-10-29 16:21 ——– d—–w- c:\programmi\NortonInstaller
2012-10-27 10:29 . 2012-10-27 10:29 ——– d—–w- c:\windows\system32\wbem\Repository
2012-10-27 06:06 . 2012-10-27 06:06 ——– d—–w- C:\TDSSKiller_Quarantine
2012-10-26 21:37 . 2012-10-26 21:37 177496 —-a-w- c:\windows\system32\drivers\59697464.sys
2012-10-26 06:24 . 2012-10-26 06:24 ——– d—–w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
2012-10-26 06:20 . 2012-10-26 06:20 ——– d—–w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Google
2012-10-26 06:19 . 2012-10-26 06:19 ——– d—–w- c:\documents and settings\Marco\Dati applicazioni\SUPERAntiSpyware.com
2012-10-26 06:19 . 2012-10-26 06:22 ——– d—–w- c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\Google
2012-10-26 06:19 . 2012-10-26 06:19 ——– d—–w- c:\programmi\SUPERAntiSpyware
2012-10-26 06:19 . 2012-10-26 06:19 ——– d—–w- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2012-10-26 06:17 . 2012-10-26 06:17 ——– d—–w- c:\documents and settings\Marco\Dati applicazioni\Malwarebytes
2012-10-26 06:16 . 2012-10-26 06:16 ——– d—–w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2012-10-26 06:16 . 2012-10-27 14:40 ——– d—–w- c:\programmi\Malwarebytes' Anti-Malware
2012-10-26 06:16 . 2012-09-29 17:54 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-10-25 15:50 . 2012-10-29 14:03 ——– d—–w- c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\NPE
2012-10-25 14:23 . 2012-10-25 14:23 ——– d—–w- c:\documents and settings\Marco\Dati applicazioni\SPE
2012-10-22 09:50 . 2012-10-22 09:50 ——– d—–w- c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache
2012-10-22 06:48 . 2012-10-22 06:48 ——– d—–w- c:\programmi\PC Connectivity Solution
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-11 18:52 . 2012-04-11 17:23 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 18:52 . 2011-05-16 08:23 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 15:05 . 2004-08-19 08:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:05 . 2004-08-19 08:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:05 . 2004-08-19 08:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-19 08:00 385024 —ha-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2004-08-19 08:00 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-23 06:27 . 2004-08-19 08:00 2152448 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-23 06:27 . 2004-08-19 08:00 2031104 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 204288]
"NokiaSuite.exe"="c:\programmi\Nokia\Nokia Suite\NokiaSuite.exe" [2012-10-12 1088424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"ATICCC"="c:\programmi\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"AccelerometerSysTrayApplet"="c:\windows\system32\AccelerometerSt.exe" [2006-01-16 53248]
"PTHOSTTR"="c:\programmi\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2005-10-04 86016]
"HP Software Update"="c:\programmi\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-08-31 122940]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-11-10 761945]
"hpWirelessAssistant"="c:\programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"CognizanceTS"="c:\progra~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 17920]
"QlbCtrl"="c:\programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-01-15 131072]
"Recguard"="c:\windows\Sminst\Recguard.exe" [2005-12-20 1187840]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-01-23 802816]
"Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-01-19 905216]
"WatchDog"="c:\programmi\InterVideo\DVD Check\DVDCheck.exe" [2005-11-08 184320]
"Cpqset"="c:\programmi\HPQ\Default Settings\cpqset.exe" [2005-10-27 241726]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Acrobat Assistant.lnk - c:\programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
BTTray.lnk - c:\programmi\WIDCOMM\Software Bluetooth\BTTray.exe [2006-1-18 581693]
DVD Check.lnk - c:\programmi\InterVideo\DVD Check\DVDCheck.exe [2011-4-21 184320]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Service Manager.lnk - c:\programmi\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2005-08-19 13:52 389120 —-a-w- c:\windows\system32\IfxWlxEN.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2005-07-25 18:41 40960 —-a-w- c:\programmi\HPQ\IAM\Bin\AsWlnPkg.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SMINST\\Scheduler.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Marco\\Dati applicazioni\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\1402000.013\SymDS.sys [27/10/2012 21.09.26 368288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\1402000.013\SymEFA.sys [27/10/2012 21.09.26 927904]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121005.002\BHDrvx86.sys [05/10/2012 19.23.26 995488]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360\1402000.013\ccSetx86.sys [27/10/2012 21.09.25 134304]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [25/10/2005 19.10.44 35488]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [22/07/2011 17.27.02 12880]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [12/07/2011 22.55.22 67664]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\1402000.013\Ironx86.sys [27/10/2012 21.09.25 175264]
R2 ASChannel;Canale di comunicazione locale;c:\windows\System32\svchost.exe -k Cognizance [19/08/2004 9.00.00 14336]
R2 MBAMScheduler;MBAMScheduler;c:\programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe [26/10/2012 7.16.47 399432]
R2 N360;Norton 360;c:\programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe [27/10/2012 21.09.15 143928]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [28/10/2012 8.57.28 106656]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [28/02/2006 5.23.47 87936]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121101.001\IDSXpx86.sys [02/11/2012 9.29.20 373728]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [10/06/2005 14.26.00 35968]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [26/10/2012 7.16.46 22856]
S2 MBAMService;MBAMService;c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe [26/10/2012 7.16.47 676936]
S2 SkypeUpdate;Skype Updater;c:\programmi\Skype\Updater\Updater.exe [13/07/2012 12.28.36 160944]
S3 71145046;71145046; [x]
S3 ServiceOMC;ServiceOMC;c:\windows\system32\ServiceOMC.exe [17/10/2011 11.54.36 63488]
.
— Altri Servizi/Drivers In Memoria —
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2012-10-26 06:19]
.
2012-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2012-10-26 06:19]
.
2012-10-30 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
- c:\programmi\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
2012-10-28 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
- c:\programmi\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
2012-11-02 c:\windows\Tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
——- Scansione supplementare ——-
.
uStart Page = hxxp://www.hp.com
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
IE: &Cerca con Google - c:\programmi\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Traduci parola in italiano - c:\programmi\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
IE: Link a ritroso - c:\programmi\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Pagine simili - c:\programmi\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Versione cache della pagina - c:\programmi\Google\GoogleToolbar1.dll/cmcache.html
TCP: DhcpNameServer = 192.168.1.1
.
.
——- Associazioni dei file ——-
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\programmi\Java\jre6\bin\jusched.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Baldur's Gate - c:\windows\IsUn0410.exe
AddRemove-Microsoft Interactive Training - c:\windows\IsUn0410.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-02 14:06
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti …
.
scansione entrate autostart nascoste …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\HPQ\Default Settings\cpqset.exe?????????v????s?n??|?????? ?t?C?????????????xmC??????v?
.
Scansione files nascosti …
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe\" /s \"N360\" /m \"c:\programmi\Norton 360\Engine\20.2.0.19\diMaster.dll\" /prefetch:1"
.
——————— CHIAVI DI REGISTRO BLOCCATE ———————
.
[HKEY_USERS\S-1-5-21-3596313449-3792058534-325310585-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{14F7AFEC-91FF-1896-6309-3661D8AC7AC7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— Dlls caricate dai processi in esecuzione ———————
.
- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\Ati2evxx.dll
c:\programmi\HPQ\IAM\Bin\AsWlnPkg.dll
c:\programmi\HPQ\IAM\Bin\ASChnl.dll
c:\windows\system32\WININET.dll
c:\programmi\HPQ\IAM\Bin\ItMsg.dll
c:\windows\system32\IfxWlxEN.dll
.
- - - - - - - > 'explorer.exe'(4492)
c:\windows\system32\WININET.dll
c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
c:\programmi\HPQ\IAM\Bin\SFSShell.dll
c:\programmi\HPQ\IAM\bin\ItMsg.dll
c:\programmi\HPQ\IAM\bin\1040\SFSShell.dll
c:\programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Altri processi in esecuzione ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\IFXTCS.exe
c:\windows\system32\DllHost.exe
c:\windows\System32\SCardSvr.exe
c:\programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\windows\system32\IFXSPMGT.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
c:\programmi\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
c:\programmi\ProtectTools\Embedded Security Software\PSDsrvc.EXE
c:\programmi\Hewlett-Packard\Shared\hpqwmiex.exe
c:\programmi\Windows Media Player\WMPNetwk.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\HPQ\IAM\bin\asghost.exe
c:\windows\system32\wscntfy.exe
c:\programmi\ProtectTools\Embedded Security Software\PSDrt.exe
c:\programmi\ProtectTools\Embedded Security Software\SpTna.exe
c:\programmi\HPQ\HP ProtectTools Security Manager\PTServs.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\progra~1\FILECO~1\Nokia\MPLATF~1\NOKIAM~1.EXE
c:\programmi\PC Connectivity Solution\Transports\NclMSBTSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclBCBTSrv.exe
.
**************************************************************************
.
Ora fine scansione: 2012-11-02 14:12:03 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-11-02 13:12
.
Pre-Run: 14.276.300.800 byte disponibili
Post-Run: 14.790.062.080 byte disponibili
.
WindowsXP-KB310994-SP2-Home-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - A83559A923EC7CE610893F241AFECF0B


when finish it show log.txt on full screen, when I minimized, I found under, the norton window showing detected threats .. boot.tidserv
Hi,

Please go to: VirusTotal
On the page you'll find a "Choose File" button.
Click on the Choose File button.
In the Choose File to Upload window which opens, copy and paste this into the File Name box.

c:\windows\system32\drivers\59697464.sys

Next, click the Open button.
Then click the "Scan It!" button just below.
This will scan the file. Please be patient.
If you get a message saying File has already been analyzed: click Reanalyze file now
Once scanned, copy and paste the link to the results page in your next reply.
———-
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


    ClearJavaCache::

    File::
    c:\windows\system32\drivers\59697464.sys

    Folder::
    c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache

    Driver::
    71145046

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Post the new ComboFix log and let me know how your system is running. :)
i've to do 2 times… an error accour during the first after reboot. here result:

ComboFix 12-11-02.02 - Marco 02/11/2012 21.17.38.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.3455.2752 [GMT 1:00]
Eseguito da: c:\documents and settings\Marco\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Marco\Desktop\CFScript.txt
AV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
FILE ::
"c:\windows\system32\drivers\59697464.sys"
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\59697464.sys
.
—- Esecuzione precedente ——-
.
c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache
c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache\GameManager\log\gamestub_install_log.txt
c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache\Upgrade\stub\governor-of-poker-game_s18_l7_gF2574T1L7_d1896312167[1].exe
c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache\Upgrade\stub\governor-of-poker-game_s18_l7_gF2574T1L7_d1896312641[1].exe
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_71145046
——-\Service_71145046
.
.
((((((((((((((((((((((((( Files Creati Da 2012-10-02 al 2012-11-02 )))))))))))))))))))))))))))))))))))
.
.
2012-10-30 19:43 . 2012-10-30 19:43 ——– d—–w- c:\programmi\Microsoft Download Manager
2012-10-30 02:20 . 2012-10-30 02:21 ——– d—–w- C:\NBRT
2012-10-29 16:24 . 2012-07-26 05:32 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-29 16:24 . 2012-07-26 05:32 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2012-10-29 16:23 . 2012-10-29 16:23 ——– d—–w- c:\windows\system32\drivers\NBRTWizard
2012-10-29 16:23 . 2012-10-29 16:23 ——– d—–w- c:\programmi\Norton Bootable Recovery Tool Wizard
2012-10-29 07:07 . 2012-10-29 07:07 ——– d—–w- c:\programmi\ESET
2012-10-28 19:29 . 2012-10-30 02:22 ——– d—–w- c:\documents and settings\Administrator
2012-10-27 20:09 . 2012-10-27 20:09 142496 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-10-27 20:09 . 2012-10-27 20:09 ——– d—–w- c:\programmi\Symantec
2012-10-27 20:09 . 2012-10-27 20:13 ——– d—–w- c:\windows\system32\drivers\N360\1402000.013
2012-10-27 20:09 . 2012-10-27 20:09 ——– d—–w- c:\programmi\Norton 360
2012-10-27 20:08 . 2012-10-29 16:21 ——– d—–w- c:\programmi\NortonInstaller
2012-10-27 10:29 . 2012-10-27 10:29 ——– d—–w- c:\windows\system32\wbem\Repository
2012-10-27 06:06 . 2012-10-27 06:06 ——– d—–w- C:\TDSSKiller_Quarantine
2012-10-26 06:24 . 2012-10-26 06:24 ——– d—–w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
2012-10-26 06:20 . 2012-10-26 06:20 ——– d—–w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Google
2012-10-26 06:19 . 2012-10-26 06:19 ——– d—–w- c:\documents and settings\Marco\Dati applicazioni\SUPERAntiSpyware.com
2012-10-26 06:19 . 2012-10-26 06:22 ——– d—–w- c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\Google
2012-10-26 06:19 . 2012-10-26 06:19 ——– d—–w- c:\programmi\SUPERAntiSpyware
2012-10-26 06:19 . 2012-10-26 06:19 ——– d—–w- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2012-10-26 06:17 . 2012-10-26 06:17 ——– d—–w- c:\documents and settings\Marco\Dati applicazioni\Malwarebytes
2012-10-26 06:16 . 2012-10-26 06:16 ——– d—–w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2012-10-26 06:16 . 2012-10-27 14:40 ——– d—–w- c:\programmi\Malwarebytes' Anti-Malware
2012-10-26 06:16 . 2012-09-29 17:54 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-10-25 15:50 . 2012-10-29 14:03 ——– d—–w- c:\documents and settings\Marco\Impostazioni locali\Dati applicazioni\NPE
2012-10-25 14:23 . 2012-10-25 14:23 ——– d—–w- c:\documents and settings\Marco\Dati applicazioni\SPE
2012-10-22 06:48 . 2012-10-22 06:48 ——– d—–w- c:\programmi\PC Connectivity Solution
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-11 18:52 . 2012-04-11 17:23 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 18:52 . 2011-05-16 08:23 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 15:05 . 2004-08-19 08:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:05 . 2004-08-19 08:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:05 . 2004-08-19 08:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-19 08:00 385024 —ha-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2004-08-19 08:00 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-23 06:27 . 2004-08-19 08:00 2152448 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-23 06:27 . 2004-08-19 08:00 2031104 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 204288]
"NokiaSuite.exe"="c:\programmi\Nokia\Nokia Suite\NokiaSuite.exe" [2012-10-12 1088424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"ATICCC"="c:\programmi\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"AccelerometerSysTrayApplet"="c:\windows\system32\AccelerometerSt.exe" [2006-01-16 53248]
"PTHOSTTR"="c:\programmi\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2005-10-04 86016]
"HP Software Update"="c:\programmi\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-08-31 122940]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-11-10 761945]
"hpWirelessAssistant"="c:\programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"CognizanceTS"="c:\progra~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 17920]
"QlbCtrl"="c:\programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-01-15 131072]
"Recguard"="c:\windows\Sminst\Recguard.exe" [2005-12-20 1187840]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-01-23 802816]
"Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-01-19 905216]
"WatchDog"="c:\programmi\InterVideo\DVD Check\DVDCheck.exe" [2005-11-08 184320]
"Cpqset"="c:\programmi\HPQ\Default Settings\cpqset.exe" [2005-10-27 241726]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Acrobat Assistant.lnk - c:\programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
BTTray.lnk - c:\programmi\WIDCOMM\Software Bluetooth\BTTray.exe [2006-1-18 581693]
DVD Check.lnk - c:\programmi\InterVideo\DVD Check\DVDCheck.exe [2011-4-21 184320]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Service Manager.lnk - c:\programmi\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2005-08-19 13:52 389120 —-a-w- c:\windows\system32\IfxWlxEN.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2005-07-25 18:41 40960 —-a-w- c:\programmi\HPQ\IAM\Bin\AsWlnPkg.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SMINST\\Scheduler.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Marco\\Dati applicazioni\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\1402000.013\SymDS.sys [27/10/2012 21.09.26 368288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\1402000.013\SymEFA.sys [27/10/2012 21.09.26 927904]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121005.002\BHDrvx86.sys [05/10/2012 19.23.26 995488]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360\1402000.013\ccSetx86.sys [27/10/2012 21.09.25 134304]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [25/10/2005 19.10.44 35488]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [22/07/2011 17.27.02 12880]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [12/07/2011 22.55.22 67664]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\1402000.013\Ironx86.sys [27/10/2012 21.09.25 175264]
R2 ASChannel;Canale di comunicazione locale;c:\windows\System32\svchost.exe -k Cognizance [19/08/2004 9.00.00 14336]
R2 MBAMScheduler;MBAMScheduler;c:\programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe [26/10/2012 7.16.47 399432]
R2 N360;Norton 360;c:\programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe [27/10/2012 21.09.15 143928]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [28/10/2012 8.57.28 106656]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [28/02/2006 5.23.47 87936]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121101.001\IDSXpx86.sys [02/11/2012 9.29.20 373728]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [10/06/2005 14.26.00 35968]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [26/10/2012 7.16.46 22856]
S2 MBAMService;MBAMService;c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe [26/10/2012 7.16.47 676936]
S2 SkypeUpdate;Skype Updater;c:\programmi\Skype\Updater\Updater.exe [13/07/2012 12.28.36 160944]
S3 ServiceOMC;ServiceOMC;c:\windows\system32\ServiceOMC.exe [17/10/2011 11.54.36 63488]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2012-10-26 06:19]
.
2012-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2012-10-26 06:19]
.
2012-11-02 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 58504311-ff35-4af5-9dec-e10adb14e442.job
- c:\programmi\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
2012-10-28 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task ec3a15f7-94f1-4f89-afc4-89ca03dc7c42.job
- c:\programmi\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
2012-11-02 c:\windows\Tasks\User_Feed_Synchronization-{C73F6C0B-8913-4B7D-803B-13B9A5E2AD2F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
——- Scansione supplementare ——-
.
uStart Page = hxxp://www.hp.com
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
IE: &Cerca con Google - c:\programmi\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Traduci parola in italiano - c:\programmi\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
IE: Link a ritroso - c:\programmi\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Pagine simili - c:\programmi\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Versione cache della pagina - c:\programmi\Google\GoogleToolbar1.dll/cmcache.html
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-02 22:15
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti …
.
scansione entrate autostart nascoste …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\HPQ\Default Settings\cpqset.exe?????????v??????n??|?????? ?t?C?????????????xmC??????v?
.
Scansione files nascosti …
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe\" /s \"N360\" /m \"c:\programmi\Norton 360\Engine\20.2.0.19\diMaster.dll\" /prefetch:1"
.
——————— CHIAVI DI REGISTRO BLOCCATE ———————
.
[HKEY_USERS\S-1-5-21-3596313449-3792058534-325310585-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{14F7AFEC-91FF-1896-6309-3661D8AC7AC7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— Dlls caricate dai processi in esecuzione ———————
.
- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\Ati2evxx.dll
c:\programmi\HPQ\IAM\Bin\AsWlnPkg.dll
c:\programmi\HPQ\IAM\Bin\ASChnl.dll
c:\windows\system32\WININET.dll
c:\programmi\HPQ\IAM\Bin\ItMsg.dll
c:\windows\system32\IfxWlxEN.dll
.
- - - - - - - > 'explorer.exe'(5184)
c:\windows\system32\WININET.dll
c:\documents and settings\Marco\Dati applicazioni\Dropbox\bin\DropboxExt.14.dll
c:\programmi\HPQ\IAM\Bin\SFSShell.dll
c:\programmi\HPQ\IAM\bin\ItMsg.dll
c:\programmi\HPQ\IAM\bin\1040\SFSShell.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Altri processi in esecuzione ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\IFXTCS.exe
c:\windows\system32\DllHost.exe
c:\windows\System32\SCardSvr.exe
c:\programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\windows\system32\IFXSPMGT.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
c:\programmi\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
c:\programmi\ProtectTools\Embedded Security Software\PSDsrvc.EXE
c:\programmi\Hewlett-Packard\Shared\hpqwmiex.exe
c:\programmi\Windows Media Player\WMPNetwk.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\programmi\HPQ\IAM\bin\asghost.exe
c:\programmi\ProtectTools\Embedded Security Software\PSDrt.exe
c:\programmi\ProtectTools\Embedded Security Software\SpTna.exe
c:\programmi\HPQ\HP ProtectTools Security Manager\PTServs.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\progra~1\FILECO~1\Nokia\MPLATF~1\NOKIAM~1.EXE
c:\programmi\PC Connectivity Solution\Transports\NclMSBTSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclBCBTSrv.exe
.
**************************************************************************
.
Ora fine scansione: 2012-11-02 22:18:54 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-11-02 21:18
ComboFix2.txt 2012-11-02 13:12
.
Pre-Run: 14.819.569.664 byte disponibili
Post-Run: 14.858.395.648 byte disponibili
.
- - End Of File - - DABFAA70E6D9F070DE9C4AC61AFD7D32


Norton always detect it after repair protection
Thanks.

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-11-03 17:30:28 —————————– 17:30:28.890 OS Version: Windows 5.1.2600 Service Pack 3 17:30:28.890 Number of processors: 2 586 0xF06 17:30:28.890 ComputerName: NX9420 UserName: Marco 17:30:29.687 Initialize success 17:34:07.343 AVAST engine defs: 12110300 17:35:29.625 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 17:35:29.640 Disk 0 Vendor: SAMSUNG_ 2AJ1 Size: 610480MB BusType: 3 17:35:29.656 Disk 0 MBR read successfully 17:35:29.656 Disk 0 MBR scan 17:35:29.671 Disk 0 unknown MBR code 17:35:29.671 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 123056 MB offset 63 17:35:29.687 Disk 0 Partition 2 00 0C FAT32 LBA RECOVERY 8010 MB offset 252020223 17:35:29.687 Disk 0 Partition - 00 0F Extended LBA 479410 MB offset 268425360 17:35:29.718 Disk 0 scanning sectors +1250257680 17:35:29.781 Disk 0 scanning C:\WINDOWS\system32\drivers 17:35:41.750 Service scanning 17:35:57.984 Modules scanning 17:36:04.281 Module: C:\WINDOWS\System32\DLA\DLADResN.SYS **SUSPICIOUS** 17:36:06.109 Disk 0 trace - called modules: 17:36:06.140 ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys hal.dll ACPI.sys iaStor.sys 17:36:06.140 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ad52ab8] 17:36:06.140 3 CLASSPNP.SYS[f74e7fd7] -> nt!IofCallDriver -> [0x8ad53c08] 17:36:06.156 5 hpdskflt.sys[f7508ffd] -> nt!IofCallDriver -> \Device\000000a5[0x8ad00b50] 17:36:06.156 7 ACPI.sys[f735e620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8acff030] 17:36:06.875 AVAST engine scan C:\WINDOWS 17:36:19.609 AVAST engine scan C:\WINDOWS\system32 17:39:08.312 AVAST engine scan C:\WINDOWS\system32\drivers 17:39:29.890 AVAST engine scan C:\Documents and Settings\Marco 17:49:07.562 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Marco\Desktop\MBR.dat" 17:49:07.765 The log file has been saved successfully to "C:\Documents and Settings\Marco\Desktop\aswMBR.txt"
Hi,

Thanks.

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Goodmorning…there's something… MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000001c Kernel Drivers (total 182): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E6000 \WINDOWS\system32\hal.dll 0xF7987000 \WINDOWS\system32\KDCOM.DLL 0xF7897000 \WINDOWS\system32\BOOTVID.dll 0xF7358000 ACPI.sys 0xF7989000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7347000 pci.sys 0xF7487000 isapnp.sys 0xF7497000 ohci1394.sys 0xF74A7000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF789B000 compbatt.sys 0xF789F000 \WINDOWS\system32\DRIVERS\BATTC.SYS 0xF7A4F000 pciide.sys 0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF798B000 intelide.sys 0xF798D000 viaide.sys 0xF798F000 aliide.sys 0xF7329000 pcmcia.sys 0xF74B7000 MountMgr.sys 0xF730A000 ftdisk.sys 0xF78A3000 ACPIEC.sys 0xF7A50000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 0xF770F000 PartMgr.sys 0xF74C7000 VolSnap.sys 0xF72F2000 atapi.sys 0xF721C000 iaStor.sys 0xF74D7000 disk.sys 0xF74E7000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF71FC000 fltmgr.sys 0xF719D000 SYMDS.SYS 0xF718B000 sr.sys 0xF70A3000 SYMEFA.SYS 0xF708D000 DRVMCDB.SYS 0xF7717000 PxHelp20.sys 0xF7076000 KSecDD.sys 0xF705F000 WudfPf.sys 0xF6FD2000 Ntfs.sys 0xF6FA5000 NDIS.sys 0xF74F7000 Combo-Fix.sys 0xF6F8B000 Mup.sys 0xF7507000 hpdskflt.sys 0xF76C7000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF558C000 \SystemRoot\system32\DRIVERS\ati2mtag.sys 0xF5578000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF5550000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF552D000 \SystemRoot\system32\DRIVERS\b57xp32.sys 0xF53D0000 \SystemRoot\system32\DRIVERS\w39n51.sys 0xF7827000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF53AC000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF782F000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF76D7000 \SystemRoot\system32\DRIVERS\nic1394.sys 0xF5384000 \SystemRoot\system32\drivers\tifm21.sys 0xF5370000 \SystemRoot\system32\DRIVERS\sdbus.sys 0xF535A000 \SystemRoot\system32\DRIVERS\gtipci21.sys 0xF7953000 \SystemRoot\system32\DRIVERS\SMCLIB.SYS 0xF5346000 \SystemRoot\system32\DRIVERS\parport.sys 0xF76E7000 \SystemRoot\system32\DRIVERS\IFXTPM.SYS 0xF76F7000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF7837000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF5317000 \SystemRoot\system32\DRIVERS\SynTP.sys 0xF7A07000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF783F000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7537000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF7A09000 \SystemRoot\System32\Drivers\DLACDBHM.SYS 0xF6749000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF5784000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF52F4000 \SystemRoot\system32\DRIVERS\ks.sys 0xF7847000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0xF5774000 \SystemRoot\system32\DRIVERS\Accelerometer.sys 0xF7963000 \SystemRoot\system32\DRIVERS\cpqbttn.sys 0xF5764000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF784F000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF7967000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0xF796B000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0xF51AF000 \SystemRoot\system32\DRIVERS\btkrnl.sys 0xF7ACA000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF5754000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF796F000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF5198000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF5744000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF5734000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF7857000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF5187000 \SystemRoot\system32\DRIVERS\psched.sys 0xF5724000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF785F000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7867000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF5714000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7A0B000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF5129000 \SystemRoot\system32\DRIVERS\update.sys 0xF797B000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF6EF2000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xF2C6D000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xAA7BF000 \SystemRoot\system32\drivers\ADIHdAud.sys 0xAA79B000 \SystemRoot\system32\drivers\portcls.sys 0xF2C3D000 \SystemRoot\system32\drivers\drmk.sys 0xAA775000 \SystemRoot\system32\drivers\AEAudio.sys 0xAA743000 \SystemRoot\system32\DRIVERS\HSFHWAZL.sys 0xAA646000 \SystemRoot\system32\DRIVERS\HSF_DPV.sys 0xAA596000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys 0xF36F5000 \SystemRoot\System32\Drivers\Modem.SYS 0xF2147000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF2586000 \SystemRoot\System32\drivers\psd.sys 0xA7F86000 \SystemRoot\system32\drivers\N360\1402000.013\ccSetx86.sys 0xA7F59000 \SystemRoot\system32\drivers\N360\1402000.013\Ironx86.SYS 0xF79BF000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xA906A000 \SystemRoot\System32\Drivers\Null.SYS 0xF79C1000 \SystemRoot\System32\Drivers\Beep.SYS 0xF2576000 \SystemRoot\System32\Drivers\DLARTL_N.SYS 0xF256E000 \SystemRoot\System32\drivers\vga.sys 0xF79AB000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xA55C9000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xA3757000 \SystemRoot\System32\Drivers\Msfs.SYS 0xA374F000 \SystemRoot\System32\Drivers\Npfs.SYS 0xA3F13000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xA28C2000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xA2869000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xA2839000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xA27DA000 \SystemRoot\system32\drivers\N360\1402000.013\SYMTDI.SYS 0xA3B0A000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xA27B0000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xA3358000 \SystemRoot\system32\DRIVERS\arp1394.sys 0xA2729000 \SystemRoot\system32\DRIVERS\netbt.sys 0xA378F000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xA2707000 \SystemRoot\System32\drivers\afd.sys 0xA3348000 \SystemRoot\system32\DRIVERS\netbios.sys 0xA55C5000 \SystemRoot\system32\DRIVERS\eabfiltr.sys 0xA3338000 \SystemRoot\system32\drivers\N360\1402000.013\SRTSPX.SYS 0xA26E5000 \??\C:\Programmi\SUPERAntiSpyware\SASKUTIL.SYS 0xA372F000 \??\C:\Programmi\SUPERAntiSpyware\SASDIFSV.SYS 0xA26BA000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xA264A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xA3328000 \SystemRoot\System32\Drivers\Fips.SYS 0xA25EB000 \??\C:\Programmi\File comuni\Symantec Shared\EENGINE\eeCtrl.sys 0xA25CD000 \??\C:\Programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xA24D7000 \??\C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121005.002\BHDrvx86.sys 0xA24B3000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xA23DD000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0xBF800000 \SystemRoot\System32\win32k.sys 0xA2AE0000 \SystemRoot\System32\drivers\Dxapi.sys 0xA2966000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xA7FCC000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\ati2dvag.dll 0xBF054000 \SystemRoot\System32\ati2cqag.dll 0xBF08E000 \SystemRoot\System32\atikvmag.dll 0xBF0C4000 \SystemRoot\System32\ati3duag.dll 0xBF32B000 \SystemRoot\System32\ativvaxx.dll 0xBF3FE000 \SystemRoot\System32\ATMFD.DLL 0xF6F4F000 \??\C:\WINDOWS\system32\drivers\mbam.sys 0xA81EC000 \SystemRoot\System32\Drivers\DRVNDDM.SYS 0xF7B90000 \SystemRoot\System32\DLA\DLADResN.SYS 0xA03C7000 \SystemRoot\System32\DLA\DLAIFS_M.SYS 0xF4210000 \SystemRoot\System32\DLA\DLAOPIOM.SYS 0xA32C2000 \SystemRoot\System32\DLA\DLAPoolM.SYS 0xA8A8A000 \SystemRoot\System32\DLA\DLABOIOM.SYS 0xA03AF000 \SystemRoot\System32\DLA\DLAUDFAM.SYS 0xA0399000 \SystemRoot\System32\DLA\DLAUDF_M.SYS 0xF57EA000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA02CC000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA02B7000 \SystemRoot\System32\Drivers\SENTINEL.SYS 0xA0341000 \??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS 0xA01C1000 \??\C:\WINDOWS\system32\drivers\hardlock.sys 0xA0180000 \SystemRoot\System32\Drivers\HTTP.sys 0xA00D8000 \SystemRoot\system32\DRIVERS\srv.sys 0xA0140000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0x9FA28000 \SystemRoot\System32\Drivers\Cdfs.SYS 0x9F943000 \SystemRoot\system32\drivers\wdmaud.sys 0x9FD80000 \SystemRoot\system32\drivers\sysaudio.sys 0xA3075000 \??\C:\ComboFix\catchme.sys 0xF7A15000 \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS 0x9DAC7000 \SystemRoot\system32\drivers\N360\1402000.013\SRTSP.SYS 0x9D520000 \??\C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121102.021\NAVEX15.SYS 0x9D50B000 \??\C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121102.021\NAVENG.SYS 0x9D4AC000 \??\C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121102.001\IDSxpx86.sys 0x9C770000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF7807000 \SystemRoot\system32\DRIVERS\NuidFltr.sys 0x9C7E0000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS 0x9C50B000 \SystemRoot\system32\DRIVERS\Wdf01000.sys 0x9CAA4000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x9CCDE000 \??\C:\DOCUME~1\Marco\IMPOST~1\Temp\aswMBR.sys 0x9C415000 \SystemRoot\system32\drivers\kmixer.sys 0x7C910000 \WINDOWS\system32\ntdll.dll Processes (total 72): 0 System Idle Process 4 System 796 C:\WINDOWS\system32\smss.exe 860 csrss.exe 888 C:\WINDOWS\system32\winlogon.exe 932 C:\WINDOWS\system32\services.exe 944 C:\WINDOWS\system32\lsass.exe 1128 C:\WINDOWS\system32\ati2evxx.exe 1144 C:\WINDOWS\system32\svchost.exe 1232 svchost.exe 1376 C:\WINDOWS\system32\svchost.exe 1400 C:\WINDOWS\system32\IFXTCS.exe 1432 C:\WINDOWS\system32\svchost.exe 1580 dllhost.exe 1732 svchost.exe 1804 svchost.exe 152 C:\WINDOWS\system32\spoolsv.exe 212 scardsvr.exe 500 svchost.exe 532 C:\WINDOWS\system32\svchost.exe 544 C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe 572 C:\WINDOWS\system32\drivers\CDAC11BA.EXE 680 C:\WINDOWS\system32\svchost.exe 700 C:\WINDOWS\system32\IFXSPMGT.exe 740 C:\Programmi\Java\jre6\bin\jqs.exe 824 C:\Programmi\File comuni\LightScribe\LSSrvc.exe 908 C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe 1624 C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe 1764 C:\Programmi\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe 428 C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe 1016 C:\Programmi\ProtectTools\Embedded Security Software\PSDsrvc.EXE 1716 C:\WINDOWS\system32\svchost.exe 1956 C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe 2160 wmpnetwk.exe 2700 alg.exe 3504 C:\WINDOWS\system32\ati2evxx.exe 2376 C:\Programmi\Norton 360\Engine\20.2.0.19\ccSvcHst.exe 1392 wmiprvse.exe 3364 C:\Programmi\HPQ\IAM\Bin\asghost.exe 3956 C:\Programmi\ProtectTools\Embedded Security Software\PSDrt.exe 3980 C:\Programmi\ProtectTools\Embedded Security Software\SpTNA.exe 4092 C:\Programmi\HPQ\HP ProtectTools Security Manager\PTServs.exe 1904 C:\Programmi\Analog Devices\Core\smax4pnp.exe 3500 C:\Programmi\ATI Technologies\ATI.ACE\CLI.exe 3612 C:\WINDOWS\system32\accelerometerST.exe 4000 C:\Programmi\HPQ\HP ProtectTools Security Manager\pthosttr.exe 3004 C:\Programmi\Hp\HP Software Update\hpwuSchd2.exe 4048 C:\WINDOWS\system32\DLA\DLACTRLW.EXE 3640 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe 1504 C:\Programmi\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe 1852 C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe 3784 C:\WINDOWS\SMINST\Scheduler.exe 2868 C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE 3100 C:\Programmi\InterVideo\DVD Check\DVDCheck.exe 2912 C:\Programmi\Windows Media Player\wmpnscfg.exe 1256 C:\Programmi\Nokia\Nokia Suite\NokiaSuite.exe 4060 C:\WINDOWS\system32\svchost.exe 1760 C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe 5052 C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe 5312 C:\Programmi\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe 4456 C:\Programmi\ATI Technologies\ATI.ACE\CLI.exe 1528 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe 4808 C:\PROGRA~1\FILECO~1\Nokia\MPLATF~1\NOKIAM~1.EXE 5184 C:\WINDOWS\explorer.exe 5992 C:\WINDOWS\system32\ctfmon.exe 6020 C:\Programmi\Messenger\msmsgs.exe 5896 C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe 5932 C:\Programmi\Internet Explorer\iexplore.exe 5972 C:\Programmi\Internet Explorer\iexplore.exe 3172 C:\Programmi\Internet Explorer\iexplore.exe 308 C:\WINDOWS\system32\wscntfy.exe 3740 C:\Documents and Settings\Marco\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x0000001e`0b0bfe00 (FAT32) PhysicalDrive0 Model Number: SAMSUNGHM641JI, Rev: 2AJ10001 Size Device Name MBR Status ——————————————– 596 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: E9E4645696378D21C6E319E447C711E23B3D6DA5 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI