I downloaded the update for any-audio-converter from the official site.
I installed it but later I found out it had installeda youtubedownloader extension for chrome and my start page became btsearch.name.
I have kaspersky antivirus but It found anything.
After LOTS of antivirus trial (with no threats detected ecept superantsomething) I was able to delete youtubedownloader chrome extension but I'm still not able to get rid of btsearch.name start page and btsearch.name as default search engine.
I tried a manual removal but I was not able to find items in registry
I ran OTL from safe mode:
OTL.Txt
OTL logfile created on: 12/28/2012 7:50:39 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\utente\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
2.97 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 61.78% Memory free
5.93 Gb Paging File | 5.09 Gb Available in Paging File | 85.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 187.94 Gb Free Space | 41.91% Space Free | Partition Type: NTFS
Drive E: | 1.99 Gb Total Space | 1.76 Gb Free Space | 88.37% Space Free | Partition Type: FAT32
Computer Name: PC | User Name: utente | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\utente\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASD.exe (Anvisoft)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\sqlite3.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMENC.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMAESLib.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\MCharSet.dll ()
========== Services (SafeList) ==========
SRV - (asdsrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe (Anvisoft)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (ADBlockerSrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerSrv.exe ()
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
SRV - (EpsonCustomerResearchParticipation) – C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (VmbService) – C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (CSObjectsSrv) – C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (yksvc) – C:\Windows\System32\yk62x86.dll (Marvell)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (RoxMediaDB10) – c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (AEADIFilters) – C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Driver Services (SafeList) ==========
DRV - (RkHit) – C:\windows\system32\drivers\RKHit.sys File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (asdrs) – C:\Windows\System32\drivers\asdrs.sys (Anvisoft)
DRV - (asdws) – C:\Windows\System32\drivers\asdws.sys ()
DRV - (asdrm) – C:\Windows\System32\drivers\asdrm.sys (Anvisoft)
DRV - (taphss6) – C:\Windows\System32\drivers\taphss6.sys (Anchorfree Inc.)
DRV - (HssDRV6) – C:\Windows\System32\drivers\hssdrv6.sys (AnchorFree Inc.)
DRV - (KLIF) – C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (asdnet) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\sys\x86\asdnet.sys ()
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (KLIM6) – C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV - (vodafone_K3805-z_cdc_ecm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) – C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) – C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (FsUsbExDisk) – C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NETw5s32) – C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (CSCrySec) – C:\Windows\System32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) – C:\Windows\System32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (klmouflt) – C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (netw5v32) – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (hpdskflt) – C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard)
DRV - (Accelerometer) – C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard)
DRV - (5U876UVC) – C:\Windows\System32\drivers\5U876.sys (Ricoh co.,Ltd.)
DRV - (mfetdik) – C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pfc) – C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://btsearch.name
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKCU\..\URLSearchHook: {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
IE - HKCU\..\SearchScopes,DefaultScope = {8d492f70-ea37-453e-a0e4-9d709483a4cd}
IE - HKCU\..\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}: "URL" = http://btsearch.name/results.php?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]
[2012/09/17 15:23:28 | 000,000,000 | —D | M] (No name found) – C:\Users\utente\AppData\Roaming\mozilla\Extensions
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Custom search (Enabled)
CHR - default_search_provider: search_url = http://btsearch.name/results.php?q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\utente\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Orbit Downloader (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Flickr\u2122 Downloader = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebkkoejhhdbbohdhikahjanhbiegfhmi\3.0.0.0_0\
CHR - Extension: Qtube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhakcmpgccbfnmamojhjhaflhnfdooaa\1.11_0\
CHR - Extension: Gmail = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (YouTube Downloader) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
O3 - HKLM\..\Toolbar: (YouTube Downloader) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
O4 - HKLM..\Run: [ADBlocker] C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
O4 - HKLM..\Run: [Anvi Smart Defender] C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" –atRestart File not found
O4 - HKLM..\Run: [FUFAXRCV] C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [PMSpeed] C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE (NewSoft Technology Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
O4 - HKLM..\Run: [YouTube Downloader_Helper] C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [EPSON WF-7515 Series] C:\windows\System32\spool\DRIVERS\W32X86\3\E_TATIHCE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 100
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{65C17FEC-4D94-4AF8-917D-6111DA444667}: NameServer = 83.224.70.93 83.224.66.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{98ECAE4D-7803-485D-B168-2FF52E90694F}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC3BBE37-C7E4-4597-9FD9-51FEBDCB221B}: NameServer = 8.8.8.8,8.8.8.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.24
7.20,156.154.70.1,156.154.71.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF42F48F-3663-45FD-8BB4-4F3844DC57A5}: DhcpNameServer = 8.8.8.8
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/12/28 19:00:12 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{1c434c24-1fdc-11e1-916b-8948ce200d89}\Shell - "" = AutoRun
O33 - MountPoints2\{1c434c24-1fdc-11e1-916b-8948ce200d89}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{2401276b-4718-11e1-8c0d-869dba3b719a}\Shell - "" = AutoRun
O33 - MountPoints2\{2401276b-4718-11e1-8c0d-869dba3b719a}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{3dc5bb52-7099-11df-80d2-d8d385117a41}\Shell - "" = AutoRun
O33 - MountPoints2\{3dc5bb52-7099-11df-80d2-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{4760c7e9-7a41-11df-b999-0027138b4d63}\Shell - "" = AutoRun
O33 - MountPoints2\{4760c7e9-7a41-11df-b999-0027138b4d63}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{9690b8c2-708b-11df-8e80-d8d385117a41}\Shell - "" = AutoRun
O33 - MountPoints2\{9690b8c2-708b-11df-8e80-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{9690b8cb-708b-11df-8e80-d8d385117a41}\Shell - "" = AutoRun
O33 - MountPoints2\{9690b8cb-708b-11df-8e80-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{a3c521a8-7a4d-11df-8036-0027138b4d63}\Shell - "" = AutoRun
O33 - MountPoints2\{a3c521a8-7a4d-11df-8036-0027138b4d63}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\Shell - "" = AutoRun
O33 - MountPoints2\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{fb160359-d177-11e0-95ae-a0e442636015}\Shell - "" = AutoRun
O33 - MountPoints2\{fb160359-d177-11e0-95ae-a0e442636015}\Shell\AutoRun\command - "" = D:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv50 - C:\windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
========== Files/Folders - Created Within 30 Days ==========
[2012/12/28 19:47:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:46:20 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\whatthetech
[2012/12/28 19:26:23 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Anvisoft
[2012/12/28 19:25:19 | 000,022,864 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrs.sys
[2012/12/28 19:25:19 | 000,016,208 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrm.sys
[2012/12/28 19:24:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft
[2012/12/28 19:24:52 | 000,000,000 | —D | C] – C:\ProgramData\Anvisoft
[2012/12/28 19:24:48 | 000,000,000 | —D | C] – C:\Program Files\Anvisoft
[2012/12/28 18:59:27 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/12/28 18:58:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/12/28 15:32:02 | 000,000,000 | —D | C] – C:\ProgramData\XoftSpySE
[2012/12/28 11:51:08 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Malwarebytes
[2012/12/28 11:50:44 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/12/28 11:50:30 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Local\Programs
[2012/12/28 10:52:26 | 000,000,000 | —D | C] – C:\Program Files\YouTube Downloader
[2012/12/28 10:51:31 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\november rain
[2012/12/28 10:05:10 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\SENE
[2012/12/19 22:59:34 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\Nuova cartella (2)
[2012/12/19 10:51:52 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\murrina
[2012/12/06 12:40:37 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\paypal
[2012/12/05 23:02:32 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\bedandcinema.com
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\Program Files\ColorDetector200
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Color Detector 2.0
[2012/12/04 11:57:04 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\BedAndCinema
[2012/11/30 10:05:27 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Local\{1192868A-6E88-42D4-87F8-FBDD2CB86138}
[2012/11/29 08:44:03 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\Nuova cartella
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[1 C:\Users\utente\Desktop\*.tmp files -> C:\Users\utente\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:25:19 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | M] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:21:08 | 000,065,536 | —- | M] () – C:\windows\System32\Ikeext.etl
[2012/12/28 19:20:59 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/12/28 19:20:52 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2012/12/28 19:10:01 | 000,000,978 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/12/28 18:54:00 | 000,001,164 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001UA.job
[2012/12/28 18:34:02 | 000,001,138 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/28 16:03:41 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 16:03:41 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 16:02:32 | 000,698,570 | —- | M] () – C:\windows\System32\perfh010.dat
[2012/12/28 16:02:32 | 000,616,008 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/12/28 16:02:32 | 000,127,764 | —- | M] () – C:\windows\System32\perfc010.dat
[2012/12/28 16:02:32 | 000,106,388 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/12/28 15:55:53 | 000,001,134 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/28 15:54:56 | 000,000,436 | —- | M] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 15:05:52 | 000,001,112 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001Core.job
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2012/12/18 16:53:03 | 003,115,570 | —- | M] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/17 12:34:42 | 000,000,326 | —- | M] () – C:\windows\tasks\HPCeeScheduleForutente.job
[2012/12/16 22:15:14 | 000,000,218 | —- | M] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:47 | 000,271,046 | —- | M] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/12 20:11:29 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2012/12/12 20:11:29 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2012/12/10 09:48:08 | 000,470,393 | —- | M] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:28 | 001,040,996 | —- | M] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:29 | 000,612,798 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:11 | 000,219,495 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | M] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/03 11:38:02 | 000,001,363 | —- | M] () – C:\Users\utente\Desktop\Internet Explorer (No Add-ons).lnk
[2012/12/01 23:29:29 | 001,088,880 | —- | M] () – C:\Users\utente\Desktop\telecomando258.jpg
[2012/11/29 16:42:25 | 000,870,035 | —- | M] () – C:\Users\utente\Desktop\raccomandata NIC257.pdf
[2012/11/29 15:50:56 | 000,689,825 | —- | M] () – C:\Users\utente\Desktop\denuncia carabinieri 29-11.pdf
[2012/11/29 15:50:04 | 000,339,597 | —- | M] () – C:\Users\utente\Desktop\consegna chiavi255.pdf
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[1 C:\Users\utente\Desktop\*.tmp files -> C:\Users\utente\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/12/28 19:25:19 | 000,014,160 | —- | C] () – C:\windows\System32\drivers\asdws.sys
[2012/12/28 19:25:19 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | C] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:00:12 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2012/12/28 15:53:02 | 000,000,436 | —- | C] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\mozilla.cfg
[2012/12/18 16:52:55 | 003,115,570 | —- | C] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/16 22:15:14 | 000,000,218 | —- | C] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:43 | 000,271,046 | —- | C] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/10 09:48:08 | 000,470,393 | —- | C] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:26 | 001,040,996 | —- | C] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:28 | 000,612,798 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:10 | 000,219,495 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | C] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/06 12:04:15 | 000,634,564 | —- | C] () – C:\Users\utente\Desktop\5 carta identità codice fiscale.pdf
[2012/12/01 23:29:29 | 001,088,880 | —- | C] () – C:\Users\utente\Desktop\telecomando258.jpg
[2012/11/29 16:42:23 | 000,870,035 | —- | C] () – C:\Users\utente\Desktop\raccomandata NIC257.pdf
[2012/11/29 15:50:56 | 000,689,825 | —- | C] () – C:\Users\utente\Desktop\denuncia carabinieri 29-11.pdf
[2012/11/29 15:50:04 | 000,339,597 | —- | C] () – C:\Users\utente\Desktop\consegna chiavi255.pdf
[2012/09/01 10:32:47 | 000,000,030 | —- | C] () – C:\windows\iedit_.INI
[2012/05/17 11:00:28 | 000,116,189 | —- | C] () – C:\windows\System32\drivers\klin.dat
[2012/05/17 11:00:28 | 000,098,168 | —- | C] () – C:\windows\System32\drivers\klick.dat
[2012/04/18 10:33:44 | 000,017,408 | —- | C] () – C:\Users\utente\AppData\Local\WebpageIcons.db
[2012/02/08 16:26:32 | 000,258,348 | —- | C] () – C:\Users\utente\AppData\Local\rx_image32.Cache
[2011/12/03 17:00:13 | 000,000,827 | —- | C] () – C:\windows\Brpfx04a.ini
[2011/12/03 17:00:13 | 000,000,161 | —- | C] () – C:\windows\brpcfx.ini
[2011/12/03 16:58:32 | 000,106,496 | —- | C] () – C:\windows\System32\BrMuSNMP.dll
[2011/12/03 16:52:17 | 000,000,420 | —- | C] () – C:\windows\BRWMARK.INI
[2011/12/03 16:52:17 | 000,000,065 | —- | C] () – C:\windows\System32\BD7820N.DAT
[2011/08/31 21:11:40 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2011/03/11 11:43:54 | 000,029,763 | —- | C] () – C:\windows\System32\drivers\klopp.dat
[2010/11/23 08:37:23 | 000,000,600 | —- | C] () – C:\Users\utente\AppData\Local\PUTTY.RND
[2010/11/23 00:27:55 | 000,000,600 | —- | C] () – C:\Users\utente\AppData\Roaming\winscp.rnd
[2010/09/08 10:07:40 | 000,159,464 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
========== ZeroAccess Check ==========
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2010/07/27 15:03:24 | 012,867,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/14 02:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/12/28 19:19:31 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\.oit
[2012/12/28 19:26:23 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Anvisoft
[2010/08/20 13:31:58 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\AnvSoft
[2010/05/16 16:31:45 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\CoffeeCup Software
[2012/08/19 00:27:28 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Dario Corsetti
[2012/09/17 15:23:27 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Disruptive Innovations SARL
[2012/08/16 15:02:33 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\DVDVideoSoft
[2012/06/16 08:53:51 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Epson
[2012/12/28 11:08:44 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\FileZilla
[2010/12/03 19:19:08 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\GARMIN
[2010/11/23 00:16:57 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\GetRightToGo
[2010/09/05 16:07:46 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\GrabPro
[2012/10/14 18:19:57 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\IrfanView
[2010/06/13 14:28:57 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1
[2012/09/28 14:47:51 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Leawo
[2011/06/15 10:12:16 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Mael
[2012/02/10 19:14:26 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\NewSoft
[2010/10/10 20:24:52 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Nokia
[2010/10/10 20:24:54 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Nokia Ovi Suite
[2012/08/16 15:02:34 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\OpenCandy
[2012/08/13 09:10:08 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\OpenOffice.org
[2012/09/28 14:46:43 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Orbit
[2010/10/10 20:27:46 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\PC Suite
[2012/02/01 18:22:22 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\PC-FAX TX
[2010/09/05 16:08:16 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\ProgSense
[2010/08/19 18:18:24 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Samsung
[2010/08/22 22:30:12 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Serif
[2010/04/20 07:32:36 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Softland
[2011/08/28 14:38:13 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Vodafone
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2012/12/21 09:00:05 | 000,000,000 | —- | M] () – C:\ctapi_out_gr.txt
[2011/08/31 19:58:34 | 000,000,043 | —- | M] () – C:\END
[2008/04/11 09:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 09:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 09:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 09:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 09:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 09:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 09:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 09:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 09:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 09:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2009/03/02 22:47:38 | 000,049,233 | —- | M] () – C:\fat32format.exe
[2008/04/11 09:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/12/28 19:20:52 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 07:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 09:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 07:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 07:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 07:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 07:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 07:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 07:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 07:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 09:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 07:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 07:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/12/28 19:20:56 | 3183,755,264 | -HS- | M] () – C:\pagefile.sys
[2010/04/15 10:20:33 | 000,982,458 | —- | M] () – C:\Setup Log 2010-04-15 #001.txt
[2012/12/28 11:50:07 | 000,147,038 | —- | M] () – C:\TDSSKiller.2.8.15.0_28.12.2012_11.49.07_log.txt
[2012/02/08 16:06:27 | 000,065,745 | —- | M] () – C:\testFindSector.log
[2009/10/19 23:43:50 | 000,047,104 | —- | M] () – C:\Thumbs.db
[2008/04/11 09:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 09:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 09:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | -H– | M] () – C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/17 04:23:20 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\windows\system32\spool\prtprocs\w32x86\DELR1pc.dll
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/14 18:36:17 | 000,000,221 | -HS- | M] () – C:\Users\utente\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[1 C:\Users\utente\Desktop\*.tmp files -> C:\Users\utente\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:FB1B13D8
< End of report >
and Extras.Txt
OTL Extras logfile created on: 12/28/2012 7:50:39 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\utente\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
2.97 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 61.78% Memory free
5.93 Gb Paging File | 5.09 Gb Available in Paging File | 85.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 187.94 Gb Free Space | 41.91% Space Free | Partition Type: NTFS
Drive E: | 1.99 Gb Total Space | 1.76 Gb Free Space | 88.37% Space Free | Partition Type: FAT32
Computer Name: PC | User Name: utente | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\Users\utente\AppData\Local\Aptana Studio 3\AptanaStudio3.exe ()
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – "%1" %*
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
jsfile [open] – "C:\Users\utente\AppData\Local\Aptana Studio 3\AptanaStudio3.exe" "%1" ()
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with &IrfanView;] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001CDCB6-DDC1-4102-AD27-F46AC4AEE63B}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{1793292E-41BE-490C-8878-BF295378FF52}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1E800862-749D-4963-B7BE-D32AFF3C9EBD}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{2085ECE5-B7D5-4E7C-9D3A-6226FE0DE84C}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{20BFE309-9BC1-44B2-8795-B7BBAEDDC63E}" = rport=138 | protocol=17 | dir=out | app=system |
"{255D911E-1A89-4875-B3A3-4992D7B27B7C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{25A33B47-97DA-407A-ADF1-F253333F21A2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{286C616D-725C-4509-90CF-E275D66FBC38}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{37ED7D3B-888B-43F0-B526-47295EF22889}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3AED7CDC-B1F3-4AB8-9BA7-6A8D97338CDE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{40BC2FAF-4DDF-495E-9470-FE22D0D263EB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4504616B-00A4-4689-8794-B95ACC5534AC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{453EEAB5-FA7D-4149-B7C6-5F534246DCFA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{463D7C47-06AE-4177-8AE4-950B6FD75E77}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{51DE8A95-D944-4778-9BCB-CA0F9B456FCE}" = lport=137 | protocol=17 | dir=in | app=system |
"{6735DCF5-7D3C-4ED2-82FF-B0CF66C2287C}" = lport=138 | protocol=17 | dir=in | app=system |
"{691F66BE-CEF5-4DD8-A690-7A3B62F942C3}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{70C30FFE-00D6-4A7B-B23A-07527FC634B2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7CF81E9F-0218-4E48-BE36-B87778BDD848}" = rport=10243 | protocol=6 | dir=out | app=system |
"{80A7D7F9-668D-4A74-9B7D-01CAE7471B38}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{87899A3F-E17B-479F-A8C8-91EBFD5281E9}" = lport=10243 | protocol=6 | dir=in | app=system |
"{9509A457-3873-41D3-9420-A1164DEB7BD4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9CC63F24-96CB-48BA-85DB-7B920C89EE08}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9FA3E89D-01AD-4469-B656-D00D8E30BECD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A25321EA-8273-4036-BD35-209CC2928568}" = rport=137 | protocol=17 | dir=out | app=system |
"{A7AD4913-AF4B-4178-81C7-D6DC252FC146}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AA3AB239-46C0-4734-9999-50AD44AB422A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ACECB579-04B1-4518-88A9-ACD49233CEBE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D1F09B88-CFCE-45F8-90B8-8EBBBFA4355B}" = rport=445 | protocol=6 | dir=out | app=system |
"{D5F8CE6F-D0AD-4605-87DB-BCCD4700234D}" = lport=445 | protocol=6 | dir=in | app=system |
"{DDFEEDF4-161D-4958-8C54-CEF50FC25E7D}" = lport=139 | protocol=6 | dir=in | app=system |
"{F6716352-C29F-4703-8D78-B106CFBB0CEF}" = rport=139 | protocol=6 | dir=out | app=system |
"{FB066C49-6DEA-4456-A6D7-FFB60FC9E5F2}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{FD06693C-D3CF-4041-B20F-84C7B11654B9}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F4328B2-DF36-41B1-A231-DB98C1FDDB77}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{15F9902A-4413-4640-A87B-E7B81F11C35A}" = dir=in | app=c:\program files\nokia\nokia ovi suite\nokiaovisuite.exe |
"{21C0A6AB-3505-49FD-AC2B-DCA8F240BD17}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{2430111F-17BC-4BEB-B106-D0713D7039E7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{244BBEB0-74F7-458B-A382-28FA0C7253AA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2567C9A2-BB32-4874-848E-3C5CBDAF5F83}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{28DF3827-A3A1-4A00-927B-064167E7246D}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{34A05218-D444-43BB-8D8E-AE955CAD312A}" = protocol=6 | dir=in | app=c:\program files\newsoft\presto! pagemanager 9.03\licensecheck.exe |
"{44EF6177-29EA-40B3-9F7C-CB24D0A848CF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4B738DED-BA62-4835-B54B-9B31ABE52DCC}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{4E62A130-9D5A-42D5-8976-01A39BE2E9B9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5BE3D965-9CFB-4C90-81E0-D4378B8D4D62}" = dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"{5BF56DC6-D487-4D55-B537-119DC8F45C66}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{60B0C98E-EF76-4B9E-BAB0-ECB99DFCF0E5}" = dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"{666593F2-B3BF-4AEB-88B2-13A22EF77E08}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6B5DBCA8-EF30-488A-8F7D-3D35614250F5}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{6CAA6BD2-14D9-4916-9B0F-3B1309E7DBC9}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{88B668ED-3B6C-4215-AD80-805C31E634E5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{984376BD-FC44-4762-B3E5-177E9F11C37A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9DCD7B21-0AB0-46A4-A1F9-0B7EA4D57CA8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A4190284-D559-4CBC-9FC4-C0C30E4F6AF7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A4F54E8D-F309-4462-BA83-72FE6E3A574E}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{A6AD0F1D-E2BF-4BB0-848B-1E15DC181D9F}" = dir=in | app=c:\program files\nokia\nokia ovi suite\nokiaovisuite.exe |
"{B1D0C64C-C537-4722-A735-5D951CA47954}" = protocol=17 | dir=in | app=c:\program files\newsoft\presto! pagemanager 9.03\licensecheck.exe |
"{B351ABA7-07E1-4E17-9246-BBB32A241F6E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BC63507A-5FE3-4E65-8F2B-0F58B007DB30}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{BD031721-5848-4FF0-A676-81937FCDBDFF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C4546C43-DCB5-4DDC-8C4F-9C60EB4BDC77}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C77D130A-8377-409C-99CE-9BC796A4F2E1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C8046D5A-5C7E-4A74-9827-890BBD864AA2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CC70B4C3-4D09-407D-8768-DF19B4514087}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DEC4E61C-1AED-414D-A53D-93C1BAF6441F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E3210E50-7361-43BE-8C8E-8E6021693ED6}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{E816B9E1-E34C-4901-90C8-EC737FC3E6BD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EC59B00F-BF6A-4C0A-9231-F515BCC786B4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FC7705A7-6F66-467F-A95F-76B46FD8FF7E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FEA451B3-7787-44BA-8F9B-5465CE420F1E}" = protocol=6 | dir=out | app=system |
"TCP Query User{9360CD7D-E98D-4CB6-89E9-87D927A6BBA0}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{1F3C54AC-5A41-40AA-9159-73D567DC96D0}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{04AF7536-446D-4F5A-8920-B4E885E4581B}" = Presto! PageManager 9.03 SE
"{065D5505-3821-4C2E-BB6C-FE66A7E7CB4F}" = USB Flash Port Driver
"{07D77970-B205-460C-84E4-263F30455597}" = Nokia Ovi Suite
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Toolbar
"{085A087C-8559-AC21-F988-9B885923B58B}" = CCC Help Japanese
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{0A1CAF84-CDC8-477F-997F-800AB090EA46}" = Serif Premium Template Pack 1 for WebPlus
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
"{12451AF7-EFF8-4B5B-8255-282D7CC7CAEE}" = OviMPlatform
"{17BDCAD2-39E2-A44B-CDCA-6854FA71421E}" = Catalyst Control Center Localization All
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{1D61E881-43CD-447B-9E6B-D2C6138B2862}" = HP Webcam
"{1D7DBD8E-4E22-B307-81F4-D55080B16FC7}" = ccc-utility
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2CC53A53-44F4-4667-8584-2FFC9ACB2242}" = Ovi Desktop Sync Engine
"{2D270A67-B7CD-4281-B2FE-60DF18D19B8E}" = Kaspersky PURE 2.0
"{2D99A593-C841-43A7-B7C9-D6F3AE70B756}" = Nokia Connectivity Cable Driver
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2F892D3E-3F96-4518-B715-F8D5A6E256DF}" = KONICA MINOLTA PageScope Box Operator 3.2.02000
"{30A2A953-DEB1-466A-B660-F4399C7C6B9D}" = Roxio MyDVD
"{31D9C74D-CD7A-4215-B1E4-DF8099AEA997}" = Catalyst Control Center - Branding
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{37D6F9FA-A5F2-3040-AF7B-78BE92957D89}" = CCC Help Thai
"{38BA2875-D7AD-4611-ABA3-C385051ADF42}" = Eraser 6.0.7.1893
"{38CA1644-39F5-44EB-F200-DFC6C5E9C5A8}" = CCC Help Chinese Standard
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D0C22FA-96D7-4789-BC5B-991A5A99BFFA}" = Windows Live Messenger
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{41D6CED7-65E8-4EBB-BB1A-B45E2D8CF6D7}" = Windows Live Family Safety
"{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B1EDAFC-B0EB-465F-886C-24FAC1BED2AC}" = Windows Live Remote Client Resources
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4D833CF3-A3AE-2863-584B-3AD3A0D70981}" = CCC Help Russian
"{4F46FDB9-B906-47BF-B3D5-C62E01B3C5EE}" = HP Support Assistant
"{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1" = Data Lifeguard Diagnostic for Windows 1.24
"{52AD35F5-FDA6-6E74-27E4-5EC2BD8A8B29}" = CCC Help Korean
"{52B24A16-729C-BDB9-D921-01556B19283D}" = CCC Help Greek
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Creator Business
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{55485AA6-B3C8-4FEF-9A1E-09B7DE3DB589}" = Serif WebPlus X4 Bonus Content Pack
"{565AEE5D-35E5-0A21-02E2-3DC8CEA652FB}" = Catalyst Control Center Graphics Light
"{57115A63-203E-8864-8951-4D5864D23956}" = CCC Help Norwegian
"{572964E9-BE64-1F57-B672-4D2B7595FAA1}" = Catalyst Control Center Graphics Full Existing
"{5AE47629-FA38-4747-4CEA-1DD2983FA8BF}" = CCC Help German
"{5B295588-59C1-4386-9F85-BB4BEDCB0D22}" = HP Customer Experience Enhancements
"{5BF8E079-D6E2-4323-B794-75152371122A}" = Windows 7 Default Setting
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5E984B44-B441-5361-B00B-91441EE7B5B4}" = CCC Help English
"{602C75D1-0C09-D216-D83D-F3126AC24A27}" = CCC Help French
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65C0025A-2CDE-43C5-82D0-C7A56EF0DB39}" = Bing Bar Platform
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68EB2C37-083A-4303-B5D8-41FA67E50B8F}_is1" = Poedit
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}" = Vodafone Mobile Broadband Lite
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common
"{76AF1F61-BB44-4694-A0EA-C6830C8BEF41}" = HP Software Setup
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B20C1C7-2766-DDB8-A02E-D6F9C7341864}" = CCC Help Finnish
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7EFEE754-EA7D-A79B-8DDA-65CADCAF1AB4}" = Catalyst Control Center InstallProxy
"{7FFAA34E-0AA6-BF03-D37C-7AC5C380CF2F}" = CCC Help Chinese Traditional
"{805F8590-510E-74AD-FC88-ADE4224B8854}" = CCC Help Polish
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{853403A9-70A9-2C60-9E74-67BDC650E820}" = Catalyst Control Center Core Implementation
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{86CE1746-9EFF-3C9C-8755-81EA8903AC34}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87CA636B-85B8-4611-A81D-F97E71024AFD}" = HP Common Access Service Library
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A75B387-6A34-7FBE-3512-89809AF89524}" = CCC Help Hungarian
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8ED43F7E-A8F6-4898-AF11-B6158F2EDF94}" = Epson Event Manager
"{8F0EDF80-31C2-FA10-DEE8-BD435A5F7D61}" = ATI Catalyst Install Manager
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-040C-0000-0000000FF1CE}" = Microsoft Office Access MUI (French) 2007
"{90120000-0015-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0410-0000-0000000FF1CE}" = Microsoft Office Access MUI (Italian) 2007
"{90120000-0015-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0413-0000-0000000FF1CE}" = Microsoft Office Access MUI (Dutch) 2007
"{90120000-0015-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-040C-0000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2007
"{90120000-0016-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0410-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Italian) 2007
"{90120000-0016-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0413-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Dutch) 2007
"{90120000-0016-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2007
"{90120000-0018-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0410-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Italian) 2007
"{90120000-0018-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0413-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Dutch) 2007
"{90120000-0018-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-040C-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (French) 2007
"{90120000-0019-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0410-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Italian) 2007
"{90120000-0019-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0413-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Dutch) 2007
"{90120000-0019-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-040C-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (French) 2007
"{90120000-001A-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0410-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Italian) 2007
"{90120000-001A-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0413-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Dutch) 2007
"{90120000-001A-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-040C-0000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2007
"{90120000-001B-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0410-0000-0000000FF1CE}" = Microsoft Office Word MUI (Italian) 2007
"{90120000-001B-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0413-0000-0000000FF1CE}" = Microsoft Office Word MUI (Dutch) 2007
"{90120000-001B-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007
"{90120000-001F-0401-0000-0000000FF1CE}_PROHYBRIDR_{14809F99-C601-4D4A-9391-F1E8FAA964C5}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROHYBRIDR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0413-0000-0000000FF1CE}_PROHYBRIDR_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-002C-040C-0000-0000000FF1CE}" = Microsoft Office Proofing (French) 2007
"{90120000-002C-0410-0000-0000000FF1CE}" = Microsoft Office Proofing (Italian) 2007
"{90120000-002C-0413-0000-0000000FF1CE}" = Microsoft Office Proofing (Dutch) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PROHYBRIDR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-040C-0000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2007
"{90120000-006E-040C-0000-0000000FF1CE}_PROHYBRIDR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0410-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Italian) 2007
"{90120000-006E-0410-0000-0000000FF1CE}_PROHYBRIDR_{0A75DA12-55CB-4DE5-8B6A-74D97847204E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0413-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Dutch) 2007
"{90120000-006E-0413-0000-0000000FF1CE}_PROHYBRIDR_{89C8E56A-90D8-4598-B0E6-EB28F6270E07}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0410-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96CFF0DB-C3C3-44B8-930C-1121EC68A3BF}" = Serif WebPlus X4 Resources
"{9ADA45A0-8043-470A-8E8B-02EA7D95F896}" = Serif WebPlus X4
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E4FC4A7-E9E1-1EF1-104B-ECFB738A1824}" = CCC Help Italian
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = HP Integrated Module with Bluetooth wireless technology
"{9EE30AB4-1D07-7C32-106D-7AE7CEEFD1EC}" = CCC Help Spanish
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{A45AF5E2-3648-EA45-2A62-C3EA975D57D9}" = Catalyst Control Center Graphics Full New
"{A657B744-4F40-6973-D177-5FD028712702}" = ccc-core-static
"{A6C3D5F0-3C6C-46BF-A8D0-06EE92E02E9E}_is1" = AD Blocker
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7554849-3B09-4A89-86E5-FC62498B470F}" = Epp Client
"{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}" = IMinent Toolbar
"{A8F7FCEF-3CA6-4CE9-8FEA-8BB18F8686F0}" = Nokia Ovi Suite Software Updater
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC0628FF-532F-4800-91EC-40903B04682F}" = Windows Live Remote Service Resources
"{AC76BA86-7AD7-1040-7B44-A94000000001}" = Adobe Reader 9.4.7 - Italiano
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B0344B38-378B-47E0-BDCC-977785D24768}" = Integrated Camera Driver Installer Package Ver.[removed]
"{B1EE1CC5-6CED-4801-BFFF-8454F21A245A}" = Garmin Communicator Plugin
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B26449A6-6007-4460-B4FE-C4776115BCEA}" = Epson Customer Research Participation
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B8ECD0D3-AE08-4891-B6C7-32F96B75EB6C}" = EPSON Printer Finder
"{BA728FCC-0B8C-6F7F-B29C-583829D1E8BB}" = CCC Help Dutch
"{C373F7C4-05D2-4047-96D1-6AF30661C6AA}" = PC Connectivity Solution
"{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections
"{C7AE4EC3-9C13-4213-8457-74D16B353F91}" = HP Web Camera
"{C7DAD22D-29D4-438F-B986-03B9ED582EA4}" = Messenger Companion
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D0BFE65D-C320-4FC9-88D2-B9C32FB95DA0}" = HP Setup
"{D2131BFA-A0D6-4FDE-8614-75B07A9B15EE}" = Windows Live UX Platform Language Pack
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D52E5A05-8A76-46A5-BD34-06CB0493F1AD}" = HP QuickLook
"{D796ABCD-73D4-F18D-CF80-9BA1BE403933}" = CCC Help Swedish
"{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}" = Epson Connect Printer Setup
"{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials
"{E045FAC9-0B70-4796-AD3A-7035E89CE536}" = SCR3xxx Smart Card Reader
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E48D0275-B2E0-C879-4B86-506757A16DC7}" = CCC Help Turkish
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E728441A-7820-4B1C-87C9-DE7BE37B2953}" = Download Navigator
"{E9B0164A-27EA-4C31-5526-867C6882B60D}" = CCC Help Czech
"{EA891D60-C20D-03C4-88CB-E4597A1753AA}" = CCC Help Portuguese
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EBDEA960-D5D6-4047-91C7-C2064072A409}" = HP User Guides 0136
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Business v10
"{EE70E5CC-B1D7-4FC0-7DC5-5460EF22FFC9}" = Widget vodafone.it
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F173C2B3-296F-458C-98FF-1676A42EBA02}" = HP Wallpaper
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F3818CCA-B7E4-2B53-F86E-2D4F195F66F3}" = CCC Help Danish
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F91CF0E6-7B98-45DB-AE57-B6E09C40B364}" = OpenOffice.org 3.4
"{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFBDA363-A033-4F32-8DE0-AEF0F105410E}" = HP ESU for Microsoft Windows 7
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"504244733D18C8F63FF584AEB290E3904E791693" = Pacchetto driver Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"7D6D030B3D73FCCA3D4E45319380F315DFBE7A54" = Pacchetto driver Windows - Infineon Technologies (FlashUSB) USB (04/16/2009 1.0.0.6)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AndreaMosaic" = AndreaMosaic 3.33.0
"Anvi Smart Defender" = Anvi Smart Defender 1.8
"Any Audio Converter_is1" = Any Audio Converter 3.0.7
"Any DVD Converter Professional_is1" = Any DVD Converter Professional 4.3.4
"Aptana Studio 3" = Aptana Studio 3
"asterisk key" = Asterisk Key 10.0
"CCleaner" = CCleaner
"CoffeeCup Free HTML Editor" = CoffeeCup Free HTML Editor
"ColorDetector200_is1" = Color Detector 2.0
"DivX Setup" = DivX Setup
"doPDF 7 printer_is1" = doPDF 7.2 printer
"EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
"EPSON Scanner" = EPSON Scan
"EPSON WF-7515 Series" = EPSON WF-7515 Series Printer Uninstall
"EPSON WF-7515 Series Netg" = Guida di rete EPSON WF-7515 Series
"EPSON WF-7515 Series Useg" = Guida utente EPSON WF-7515 Series
"FileZilla Client" = FileZilla Client 3.6.0.2
"Fotosizer" = Fotosizer 1.35
"Free Audio Dub_is1" = Free Audio Dub version 1.7.9.908
"Freemake Video Converter_is1" = Freemake Video Converter versione 2.3.4
"GSiteCrawler" = GSiteCrawler
"HxD Hex Editor_is1" = HxD Hex Editor versione 1.7.7.0
"Infineon USB driver_is1" = Infineon USB driver 1.0.0.6
"InstallWIX_{2D270A67-B7CD-4281-B2FE-60DF18D19B8E}" = Kaspersky PURE 2.0
"IrfanView" = IrfanView (remove only)
"it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1" = Widget vodafone.it
"jZip" = jZip
"Marvell Miniport Driver" = Marvell Miniport Driver
"MemoriesOnTV3-CS1_is1" = MemoriesOnTV ClipShow Volume 1.1
"MemoriesOnTV4_is1" = MemoriesOnTV 4.1.2
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Nokia Ovi Suite" = Nokia Ovi Suite
"NTSInformaticaBusiness_is1" = Business NET 2009
"PageBreeze Free HTML Editor" = PageBreeze Free HTML Editor
"PROHYBRIDR" = 2007 Microsoft Office system
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Total Video Converter 3.61_is1" = Total Video Converter 3.61 100319
"Total Video Converter 3.71_is1" = Total Video Converter 3.71 100812
"VLC media player" = VLC media player 1.1.2
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.45-4
"WinLiveSuite" = Windows Live Essentials
"winscp3_is1" = WinSCP 4.2.9
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 12/27/2012 5:55:24 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 12/27/2012 5:55:24 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3354
Error - 12/27/2012 5:55:24 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3354
Error - 12/28/2012 5:53:04 AM | Computer Name = PC | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 12/28/2012 6:42:37 AM | Computer Name = PC | Source = VmbService | ID = 0
Description = conflictManagerTypeValue
Error - 12/28/2012 10:00:38 AM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: svchost.exe_SysMain,
versione: 6.1.7600.16385, timestamp: 0x4a5bc100 Nome del modulo che ha generato
l'errore: sysmain.dll, versione: 6.1.7600.16385, timestamp: 0x4a5bdb23 Codice eccezione:
0xc0000006 Offset errore 0x0009af43 ID processo che ha generato l'errore: 0x430 Ora
di avvio dell'applicazione che ha generato l'errore: 0x01cde4e804b8d654 Percorso
dell'applicazione che ha generato l'errore: C:\windows\System32\svchost.exe Percorso
del modulo che ha generato l'errore: c:\windows\system32\sysmain.dll ID segnalazione:
f49c75c5-50f6-11e2-8e9d-cbe1ac0062c0
Error - 12/28/2012 10:00:38 AM | Computer Name = PC | Source = Application Error | ID = 1005
Description = Impossibile accedere al file C:\Windows\Prefetch\AgCx_SC1.db.trx per
uno dei motivi seguenti: Si è verificato un problema relativo alla connessione
di rete, al disco in cui è archiviato il file o ai driver di archiviazione installati
nel computer oppure il disco è assente. Il programma Processo host per servizi di
Windows è stato chiuso a causa dell'errore. Programma: Processo host per servizi
di Windows File: C:\Windows\Prefetch\AgCx_SC1.db.trx Il valore dell'errore è indicato
nella sezione Dati aggiuntivi. Azione utente 1. Aprire nuovamente il file. Potrebbe
trattarsi di un problema temporaneo che si risolverà automaticamente rieseguendo
il programma. 2. Se il file risulta comunque non accessibile e: - Si trova in rete,
è
necessario che l'amministratore della rete verifichi la presenza di eventuali problemi
di rete e che sia possibile contattare il server. - Si trova in un disco rimovibile,
ad esempio un disco floppy o un CD, verificare che il disco sia inserito correttamente
nel computer. 3. Controllare e ripristinare il file system eseguendo CHKDSK. Per
eseguire CHKDSK, fare clic sul pulsante Start, scegliere Esegui, digitare CMD,
quindi scegliere OK. Al prompt dei comandi, digitare CHKDSK /F, quindi premere INVIO.
4.
Se il problema persiste, ripristinare il file da una copia di backup. 5. Determinare
se è possibile aprire altri file nello stesso disco. Se non è possibile, il disco
potrebbe essere danneggiato. Se si tratta di un disco rigido, contattare l'amministratore
o il fornitore dell'hardware del computer per ottenere assistenza. Dati aggiuntivi
Valore
errore: C0000185 Tipo disco: 3
Error - 12/28/2012 10:32:48 AM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: XoftSpySE_Setup_RW.exe,
versione: 7.0.1.0, timestamp: 0x4f47e2df Nome del modulo che ha generato l'errore:
System.dll, versione: 0.0.0.0, timestamp: 0x4bccb8d8 Codice eccezione: 0xc0000005
Offset
errore 0x000018ed ID processo che ha generato l'errore: 0x1f2c Ora di avvio dell'applicazione
che ha generato l'errore: 0x01cde50807adfd3e Percorso dell'applicazione che ha generato
l'errore: C:\Users\utente\Downloads\XoftSpySE_Setup_RW.exe Percorso del modulo che
ha generato l'errore: C:\Users\utente\AppData\Local\Temp\nsu282E.tmp\System.dll
ID
segnalazione: 731c850c-50fb-11e2-8e9d-cbe1ac0062c0
Error - 12/28/2012 10:55:04 AM | Computer Name = PC | Source = VmbService | ID = 0
Description = conflictManagerTypeValue
Error - 12/28/2012 1:25:24 PM | Computer Name = PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Servizi di crittografia: impossibile elaborare la chiamata OnIdentity()
nell'oggetto writer del sistema. Details: AddLegacyDriverFiles: Unable to back up
image of binary SASKUTIL. System Error: Impossibile trovare il file specificato. .
Error - 12/28/2012 1:58:58 PM | Computer Name = PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Servizi di crittografia: impossibile elaborare la chiamata OnIdentity()
nell'oggetto writer del sistema. Details: AddLegacyDriverFiles: Unable to back up
image of binary SASKUTIL. System Error: Impossibile trovare il file specificato. .
Error - 12/28/2012 2:01:10 PM | Computer Name = PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Servizi di crittografia: impossibile elaborare la chiamata OnIdentity()
nell'oggetto writer del sistema. Details: AddLegacyDriverFiles: Unable to back up
image of binary SASKUTIL. System Error: Impossibile trovare il file specificato. .
[ Hewlett-Packard Events ]
Error - 7/2/2010 9:03:15 AM | Computer Name = pc-paride | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF
in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 4/29/2011 10:29:59 AM | Computer Name = pc-paride | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF
in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 8/17/2012 8:43:35 AM | Computer Name = PC | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF
in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 9/28/2012 9:15:53 AM | Computer Name = PC | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF
in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 10/12/2012 2:38:49 PM | Computer Name = PC | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF
in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 11/9/2012 10:38:50 AM | Computer Name = PC | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF
in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
[ OSession Events ]
Error - 7/24/2010 8:50:08 AM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 17
seconds with 0 seconds of active time. This session ended with a crash.
Error - 8/6/2010 2:50:40 PM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/13/2010 10:08:57 AM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4092
seconds with 960 seconds of active time. This session ended with a crash.
Error - 11/24/2010 5:00:58 AM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3794
seconds with 1740 seconds of active time. This session ended with a crash.
Error - 7/3/2011 1:13:07 PM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11607
seconds with 5400 seconds of active time. This session ended with a crash.
Error - 9/29/2011 4:01:21 AM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 151
seconds with 120 seconds of active time. This session ended with a crash.
Error - 2/19/2012 5:39:09 PM | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 24023
seconds with 360 seconds of active time. This session ended with a crash.
Error - 7/1/2012 10:41:49 AM | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 112
seconds with 0 seconds of active time. This session ended with a crash.
Error - 9/9/2012 2:43:59 PM | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 32306
seconds with 6780 seconds of active time. This session ended with a crash.
Error - 9/9/2012 2:51:39 PM | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 169
seconds with 60 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068
Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068
Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068
Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068
Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068
Error - 12/28/2012 2:21:29 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068
Error - 12/28/2012 2:21:29 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068
Error - 12/28/2012 2:21:29 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068
Error - 12/28/2012 2:21:32 PM | Computer Name = PC | Source = DCOM | ID = 10005
Description =
Error - 12/28/2012 2:21:32 PM | Computer Name = PC | Source = DCOM | ID = 10005
Description =
Error - 12/28/2012 2:21:33 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Provider Gruppo Home dipende dal servizio Host provider
di individuazione funzioni che non è stato avviato per il seguente errore: %%1068
< End of report >