This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

chrome start page and search: btsearch.name [Solved]

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Excuse me for my poor English.

I downloaded the update for any-audio-converter from the official site.
I installed it but later I found out it had installeda youtubedownloader extension for chrome and my start page became btsearch.name.
I have kaspersky antivirus but It found anything.
After LOTS of antivirus trial (with no threats detected ecept superantsomething) I was able to delete youtubedownloader chrome extension but I'm still not able to get rid of btsearch.name start page and btsearch.name as default search engine.
I tried a manual removal but I was not able to find items in registry

I ran OTL from safe mode:
OTL.Txt

OTL logfile created on: 12/28/2012 7:50:39 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\utente\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 61.78% Memory free
5.93 Gb Paging File | 5.09 Gb Available in Paging File | 85.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 187.94 Gb Free Space | 41.91% Space Free | Partition Type: NTFS
Drive E: | 1.99 Gb Total Space | 1.76 Gb Free Space | 88.37% Space Free | Partition Type: FAT32

Computer Name: PC | User Name: utente | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\utente\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASD.exe (Anvisoft)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\sqlite3.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMENC.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMAESLib.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\MCharSet.dll ()


========== Services (SafeList) ==========

SRV - (asdsrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe (Anvisoft)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (ADBlockerSrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerSrv.exe ()
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
SRV - (EpsonCustomerResearchParticipation) – C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (VmbService) – C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (CSObjectsSrv) – C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (yksvc) – C:\Windows\System32\yk62x86.dll (Marvell)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (RoxMediaDB10) – c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (AEADIFilters) – C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV - (RkHit) – C:\windows\system32\drivers\RKHit.sys File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (asdrs) – C:\Windows\System32\drivers\asdrs.sys (Anvisoft)
DRV - (asdws) – C:\Windows\System32\drivers\asdws.sys ()
DRV - (asdrm) – C:\Windows\System32\drivers\asdrm.sys (Anvisoft)
DRV - (taphss6) – C:\Windows\System32\drivers\taphss6.sys (Anchorfree Inc.)
DRV - (HssDRV6) – C:\Windows\System32\drivers\hssdrv6.sys (AnchorFree Inc.)
DRV - (KLIF) – C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (asdnet) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\sys\x86\asdnet.sys ()
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (KLIM6) – C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV - (vodafone_K3805-z_cdc_ecm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) – C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) – C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (FsUsbExDisk) – C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NETw5s32) – C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (CSCrySec) – C:\Windows\System32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) – C:\Windows\System32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (klmouflt) – C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (netw5v32) – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (hpdskflt) – C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard)
DRV - (Accelerometer) – C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard)
DRV - (5U876UVC) – C:\Windows\System32\drivers\5U876.sys (Ricoh co.,Ltd.)
DRV - (mfetdik) – C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pfc) – C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://btsearch.name
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKCU\..\URLSearchHook: {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
IE - HKCU\..\SearchScopes,DefaultScope = {8d492f70-ea37-453e-a0e4-9d709483a4cd}
IE - HKCU\..\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}: "URL" = http://btsearch.name/results.php?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]

[2012/09/17 15:23:28 | 000,000,000 | —D | M] (No name found) – C:\Users\utente\AppData\Roaming\mozilla\Extensions

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Custom search (Enabled)
CHR - default_search_provider: search_url = http://btsearch.name/results.php?q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\utente\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Orbit Downloader (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Flickr\u2122 Downloader = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebkkoejhhdbbohdhikahjanhbiegfhmi\3.0.0.0_0\
CHR - Extension: Qtube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhakcmpgccbfnmamojhjhaflhnfdooaa\1.11_0\
CHR - Extension: Gmail = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (YouTube Downloader) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
O3 - HKLM\..\Toolbar: (YouTube Downloader) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
O4 - HKLM..\Run: [ADBlocker] C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
O4 - HKLM..\Run: [Anvi Smart Defender] C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" –atRestart File not found
O4 - HKLM..\Run: [FUFAXRCV] C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [PMSpeed] C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE (NewSoft Technology Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
O4 - HKLM..\Run: [YouTube Downloader_Helper] C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [EPSON WF-7515 Series] C:\windows\System32\spool\DRIVERS\W32X86\3\E_TATIHCE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 100
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{65C17FEC-4D94-4AF8-917D-6111DA444667}: NameServer = 83.224.70.93 83.224.66.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{98ECAE4D-7803-485D-B168-2FF52E90694F}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC3BBE37-C7E4-4597-9FD9-51FEBDCB221B}: NameServer = 8.8.8.8,8.8.8.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.24
7.20,156.154.70.1,156.154.71.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF42F48F-3663-45FD-8BB4-4F3844DC57A5}: DhcpNameServer = 8.8.8.8
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/12/28 19:00:12 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{1c434c24-1fdc-11e1-916b-8948ce200d89}\Shell - "" = AutoRun
O33 - MountPoints2\{1c434c24-1fdc-11e1-916b-8948ce200d89}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{2401276b-4718-11e1-8c0d-869dba3b719a}\Shell - "" = AutoRun
O33 - MountPoints2\{2401276b-4718-11e1-8c0d-869dba3b719a}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{3dc5bb52-7099-11df-80d2-d8d385117a41}\Shell - "" = AutoRun
O33 - MountPoints2\{3dc5bb52-7099-11df-80d2-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{4760c7e9-7a41-11df-b999-0027138b4d63}\Shell - "" = AutoRun
O33 - MountPoints2\{4760c7e9-7a41-11df-b999-0027138b4d63}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{9690b8c2-708b-11df-8e80-d8d385117a41}\Shell - "" = AutoRun
O33 - MountPoints2\{9690b8c2-708b-11df-8e80-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{9690b8cb-708b-11df-8e80-d8d385117a41}\Shell - "" = AutoRun
O33 - MountPoints2\{9690b8cb-708b-11df-8e80-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{a3c521a8-7a4d-11df-8036-0027138b4d63}\Shell - "" = AutoRun
O33 - MountPoints2\{a3c521a8-7a4d-11df-8036-0027138b4d63}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\Shell - "" = AutoRun
O33 - MountPoints2\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{fb160359-d177-11e0-95ae-a0e442636015}\Shell - "" = AutoRun
O33 - MountPoints2\{fb160359-d177-11e0-95ae-a0e442636015}\Shell\AutoRun\command - "" = D:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv50 - C:\windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084

========== Files/Folders - Created Within 30 Days ==========

[2012/12/28 19:47:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:46:20 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\whatthetech
[2012/12/28 19:26:23 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Anvisoft
[2012/12/28 19:25:19 | 000,022,864 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrs.sys
[2012/12/28 19:25:19 | 000,016,208 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrm.sys
[2012/12/28 19:24:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft
[2012/12/28 19:24:52 | 000,000,000 | —D | C] – C:\ProgramData\Anvisoft
[2012/12/28 19:24:48 | 000,000,000 | —D | C] – C:\Program Files\Anvisoft
[2012/12/28 18:59:27 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/12/28 18:58:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/12/28 15:32:02 | 000,000,000 | —D | C] – C:\ProgramData\XoftSpySE
[2012/12/28 11:51:08 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Malwarebytes
[2012/12/28 11:50:44 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/12/28 11:50:30 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Local\Programs
[2012/12/28 10:52:26 | 000,000,000 | —D | C] – C:\Program Files\YouTube Downloader
[2012/12/28 10:51:31 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\november rain
[2012/12/28 10:05:10 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\SENE
[2012/12/19 22:59:34 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\Nuova cartella (2)
[2012/12/19 10:51:52 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\murrina
[2012/12/06 12:40:37 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\paypal
[2012/12/05 23:02:32 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\bedandcinema.com
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\Program Files\ColorDetector200
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Color Detector 2.0
[2012/12/04 11:57:04 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\BedAndCinema
[2012/11/30 10:05:27 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Local\{1192868A-6E88-42D4-87F8-FBDD2CB86138}
[2012/11/29 08:44:03 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\Nuova cartella
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[1 C:\Users\utente\Desktop\*.tmp files -> C:\Users\utente\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:25:19 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | M] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:21:08 | 000,065,536 | —- | M] () – C:\windows\System32\Ikeext.etl
[2012/12/28 19:20:59 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/12/28 19:20:52 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2012/12/28 19:10:01 | 000,000,978 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/12/28 18:54:00 | 000,001,164 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001UA.job
[2012/12/28 18:34:02 | 000,001,138 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/28 16:03:41 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 16:03:41 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 16:02:32 | 000,698,570 | —- | M] () – C:\windows\System32\perfh010.dat
[2012/12/28 16:02:32 | 000,616,008 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/12/28 16:02:32 | 000,127,764 | —- | M] () – C:\windows\System32\perfc010.dat
[2012/12/28 16:02:32 | 000,106,388 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/12/28 15:55:53 | 000,001,134 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/28 15:54:56 | 000,000,436 | —- | M] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 15:05:52 | 000,001,112 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001Core.job
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2012/12/18 16:53:03 | 003,115,570 | —- | M] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/17 12:34:42 | 000,000,326 | —- | M] () – C:\windows\tasks\HPCeeScheduleForutente.job
[2012/12/16 22:15:14 | 000,000,218 | —- | M] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:47 | 000,271,046 | —- | M] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/12 20:11:29 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2012/12/12 20:11:29 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2012/12/10 09:48:08 | 000,470,393 | —- | M] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:28 | 001,040,996 | —- | M] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:29 | 000,612,798 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:11 | 000,219,495 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | M] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/03 11:38:02 | 000,001,363 | —- | M] () – C:\Users\utente\Desktop\Internet Explorer (No Add-ons).lnk
[2012/12/01 23:29:29 | 001,088,880 | —- | M] () – C:\Users\utente\Desktop\telecomando258.jpg
[2012/11/29 16:42:25 | 000,870,035 | —- | M] () – C:\Users\utente\Desktop\raccomandata NIC257.pdf
[2012/11/29 15:50:56 | 000,689,825 | —- | M] () – C:\Users\utente\Desktop\denuncia carabinieri 29-11.pdf
[2012/11/29 15:50:04 | 000,339,597 | —- | M] () – C:\Users\utente\Desktop\consegna chiavi255.pdf
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[1 C:\Users\utente\Desktop\*.tmp files -> C:\Users\utente\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/12/28 19:25:19 | 000,014,160 | —- | C] () – C:\windows\System32\drivers\asdws.sys
[2012/12/28 19:25:19 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | C] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:00:12 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2012/12/28 15:53:02 | 000,000,436 | —- | C] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\mozilla.cfg
[2012/12/18 16:52:55 | 003,115,570 | —- | C] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/16 22:15:14 | 000,000,218 | —- | C] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:43 | 000,271,046 | —- | C] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/10 09:48:08 | 000,470,393 | —- | C] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:26 | 001,040,996 | —- | C] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:28 | 000,612,798 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:10 | 000,219,495 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | C] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/06 12:04:15 | 000,634,564 | —- | C] () – C:\Users\utente\Desktop\5 carta identità codice fiscale.pdf
[2012/12/01 23:29:29 | 001,088,880 | —- | C] () – C:\Users\utente\Desktop\telecomando258.jpg
[2012/11/29 16:42:23 | 000,870,035 | —- | C] () – C:\Users\utente\Desktop\raccomandata NIC257.pdf
[2012/11/29 15:50:56 | 000,689,825 | —- | C] () – C:\Users\utente\Desktop\denuncia carabinieri 29-11.pdf
[2012/11/29 15:50:04 | 000,339,597 | —- | C] () – C:\Users\utente\Desktop\consegna chiavi255.pdf
[2012/09/01 10:32:47 | 000,000,030 | —- | C] () – C:\windows\iedit_.INI
[2012/05/17 11:00:28 | 000,116,189 | —- | C] () – C:\windows\System32\drivers\klin.dat
[2012/05/17 11:00:28 | 000,098,168 | —- | C] () – C:\windows\System32\drivers\klick.dat
[2012/04/18 10:33:44 | 000,017,408 | —- | C] () – C:\Users\utente\AppData\Local\WebpageIcons.db
[2012/02/08 16:26:32 | 000,258,348 | —- | C] () – C:\Users\utente\AppData\Local\rx_image32.Cache
[2011/12/03 17:00:13 | 000,000,827 | —- | C] () – C:\windows\Brpfx04a.ini
[2011/12/03 17:00:13 | 000,000,161 | —- | C] () – C:\windows\brpcfx.ini
[2011/12/03 16:58:32 | 000,106,496 | —- | C] () – C:\windows\System32\BrMuSNMP.dll
[2011/12/03 16:52:17 | 000,000,420 | —- | C] () – C:\windows\BRWMARK.INI
[2011/12/03 16:52:17 | 000,000,065 | —- | C] () – C:\windows\System32\BD7820N.DAT
[2011/08/31 21:11:40 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2011/03/11 11:43:54 | 000,029,763 | —- | C] () – C:\windows\System32\drivers\klopp.dat
[2010/11/23 08:37:23 | 000,000,600 | —- | C] () – C:\Users\utente\AppData\Local\PUTTY.RND
[2010/11/23 00:27:55 | 000,000,600 | —- | C] () – C:\Users\utente\AppData\Roaming\winscp.rnd
[2010/09/08 10:07:40 | 000,159,464 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4

========== ZeroAccess Check ==========

[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2010/07/27 15:03:24 | 012,867,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/14 02:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/12/28 19:19:31 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\.oit
[2012/12/28 19:26:23 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Anvisoft
[2010/08/20 13:31:58 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\AnvSoft
[2010/05/16 16:31:45 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\CoffeeCup Software
[2012/08/19 00:27:28 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Dario Corsetti
[2012/09/17 15:23:27 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Disruptive Innovations SARL
[2012/08/16 15:02:33 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\DVDVideoSoft
[2012/06/16 08:53:51 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Epson
[2012/12/28 11:08:44 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\FileZilla
[2010/12/03 19:19:08 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\GARMIN
[2010/11/23 00:16:57 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\GetRightToGo
[2010/09/05 16:07:46 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\GrabPro
[2012/10/14 18:19:57 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\IrfanView
[2010/06/13 14:28:57 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1
[2012/09/28 14:47:51 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Leawo
[2011/06/15 10:12:16 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Mael
[2012/02/10 19:14:26 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\NewSoft
[2010/10/10 20:24:52 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Nokia
[2010/10/10 20:24:54 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Nokia Ovi Suite
[2012/08/16 15:02:34 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\OpenCandy
[2012/08/13 09:10:08 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\OpenOffice.org
[2012/09/28 14:46:43 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Orbit
[2010/10/10 20:27:46 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\PC Suite
[2012/02/01 18:22:22 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\PC-FAX TX
[2010/09/05 16:08:16 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\ProgSense
[2010/08/19 18:18:24 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Samsung
[2010/08/22 22:30:12 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Serif
[2010/04/20 07:32:36 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Softland
[2011/08/28 14:38:13 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\Vodafone

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2012/12/21 09:00:05 | 000,000,000 | —- | M] () – C:\ctapi_out_gr.txt
[2011/08/31 19:58:34 | 000,000,043 | —- | M] () – C:\END
[2008/04/11 09:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 09:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 09:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 09:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 09:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 09:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 09:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 09:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 09:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 09:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2009/03/02 22:47:38 | 000,049,233 | —- | M] () – C:\fat32format.exe
[2008/04/11 09:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/12/28 19:20:52 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 07:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 09:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 07:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 07:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 07:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 07:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 07:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 07:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 07:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 09:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 07:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 07:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/12/28 19:20:56 | 3183,755,264 | -HS- | M] () – C:\pagefile.sys
[2010/04/15 10:20:33 | 000,982,458 | —- | M] () – C:\Setup Log 2010-04-15 #001.txt
[2012/12/28 11:50:07 | 000,147,038 | —- | M] () – C:\TDSSKiller.2.8.15.0_28.12.2012_11.49.07_log.txt
[2012/02/08 16:06:27 | 000,065,745 | —- | M] () – C:\testFindSector.log
[2009/10/19 23:43:50 | 000,047,104 | —- | M] () – C:\Thumbs.db
[2008/04/11 09:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 09:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 09:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | -H– | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/17 04:23:20 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\windows\system32\spool\prtprocs\w32x86\DELR1pc.dll
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/14 18:36:17 | 000,000,221 | -HS- | M] () – C:\Users\utente\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[1 C:\Users\utente\Desktop\*.tmp files -> C:\Users\utente\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:FB1B13D8

< End of report >



and Extras.Txt

OTL Extras logfile created on: 12/28/2012 7:50:39 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\utente\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 61.78% Memory free
5.93 Gb Paging File | 5.09 Gb Available in Paging File | 85.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 187.94 Gb Free Space | 41.91% Space Free | Partition Type: NTFS
Drive E: | 1.99 Gb Total Space | 1.76 Gb Free Space | 88.37% Space Free | Partition Type: FAT32

Computer Name: PC | User Name: utente | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\Users\utente\AppData\Local\Aptana Studio 3\AptanaStudio3.exe ()

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – "%1" %*
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
jsfile [open] – "C:\Users\utente\AppData\Local\Aptana Studio 3\AptanaStudio3.exe" "%1" ()
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with &IrfanView;] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001CDCB6-DDC1-4102-AD27-F46AC4AEE63B}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{1793292E-41BE-490C-8878-BF295378FF52}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1E800862-749D-4963-B7BE-D32AFF3C9EBD}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{2085ECE5-B7D5-4E7C-9D3A-6226FE0DE84C}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{20BFE309-9BC1-44B2-8795-B7BBAEDDC63E}" = rport=138 | protocol=17 | dir=out | app=system |
"{255D911E-1A89-4875-B3A3-4992D7B27B7C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{25A33B47-97DA-407A-ADF1-F253333F21A2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{286C616D-725C-4509-90CF-E275D66FBC38}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{37ED7D3B-888B-43F0-B526-47295EF22889}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3AED7CDC-B1F3-4AB8-9BA7-6A8D97338CDE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{40BC2FAF-4DDF-495E-9470-FE22D0D263EB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4504616B-00A4-4689-8794-B95ACC5534AC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{453EEAB5-FA7D-4149-B7C6-5F534246DCFA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{463D7C47-06AE-4177-8AE4-950B6FD75E77}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{51DE8A95-D944-4778-9BCB-CA0F9B456FCE}" = lport=137 | protocol=17 | dir=in | app=system |
"{6735DCF5-7D3C-4ED2-82FF-B0CF66C2287C}" = lport=138 | protocol=17 | dir=in | app=system |
"{691F66BE-CEF5-4DD8-A690-7A3B62F942C3}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{70C30FFE-00D6-4A7B-B23A-07527FC634B2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7CF81E9F-0218-4E48-BE36-B87778BDD848}" = rport=10243 | protocol=6 | dir=out | app=system |
"{80A7D7F9-668D-4A74-9B7D-01CAE7471B38}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{87899A3F-E17B-479F-A8C8-91EBFD5281E9}" = lport=10243 | protocol=6 | dir=in | app=system |
"{9509A457-3873-41D3-9420-A1164DEB7BD4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9CC63F24-96CB-48BA-85DB-7B920C89EE08}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9FA3E89D-01AD-4469-B656-D00D8E30BECD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A25321EA-8273-4036-BD35-209CC2928568}" = rport=137 | protocol=17 | dir=out | app=system |
"{A7AD4913-AF4B-4178-81C7-D6DC252FC146}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AA3AB239-46C0-4734-9999-50AD44AB422A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ACECB579-04B1-4518-88A9-ACD49233CEBE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D1F09B88-CFCE-45F8-90B8-8EBBBFA4355B}" = rport=445 | protocol=6 | dir=out | app=system |
"{D5F8CE6F-D0AD-4605-87DB-BCCD4700234D}" = lport=445 | protocol=6 | dir=in | app=system |
"{DDFEEDF4-161D-4958-8C54-CEF50FC25E7D}" = lport=139 | protocol=6 | dir=in | app=system |
"{F6716352-C29F-4703-8D78-B106CFBB0CEF}" = rport=139 | protocol=6 | dir=out | app=system |
"{FB066C49-6DEA-4456-A6D7-FFB60FC9E5F2}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{FD06693C-D3CF-4041-B20F-84C7B11654B9}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F4328B2-DF36-41B1-A231-DB98C1FDDB77}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{15F9902A-4413-4640-A87B-E7B81F11C35A}" = dir=in | app=c:\program files\nokia\nokia ovi suite\nokiaovisuite.exe |
"{21C0A6AB-3505-49FD-AC2B-DCA8F240BD17}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{2430111F-17BC-4BEB-B106-D0713D7039E7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{244BBEB0-74F7-458B-A382-28FA0C7253AA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2567C9A2-BB32-4874-848E-3C5CBDAF5F83}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{28DF3827-A3A1-4A00-927B-064167E7246D}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{34A05218-D444-43BB-8D8E-AE955CAD312A}" = protocol=6 | dir=in | app=c:\program files\newsoft\presto! pagemanager 9.03\licensecheck.exe |
"{44EF6177-29EA-40B3-9F7C-CB24D0A848CF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4B738DED-BA62-4835-B54B-9B31ABE52DCC}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{4E62A130-9D5A-42D5-8976-01A39BE2E9B9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5BE3D965-9CFB-4C90-81E0-D4378B8D4D62}" = dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"{5BF56DC6-D487-4D55-B537-119DC8F45C66}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{60B0C98E-EF76-4B9E-BAB0-ECB99DFCF0E5}" = dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"{666593F2-B3BF-4AEB-88B2-13A22EF77E08}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6B5DBCA8-EF30-488A-8F7D-3D35614250F5}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{6CAA6BD2-14D9-4916-9B0F-3B1309E7DBC9}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{88B668ED-3B6C-4215-AD80-805C31E634E5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{984376BD-FC44-4762-B3E5-177E9F11C37A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9DCD7B21-0AB0-46A4-A1F9-0B7EA4D57CA8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A4190284-D559-4CBC-9FC4-C0C30E4F6AF7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A4F54E8D-F309-4462-BA83-72FE6E3A574E}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{A6AD0F1D-E2BF-4BB0-848B-1E15DC181D9F}" = dir=in | app=c:\program files\nokia\nokia ovi suite\nokiaovisuite.exe |
"{B1D0C64C-C537-4722-A735-5D951CA47954}" = protocol=17 | dir=in | app=c:\program files\newsoft\presto! pagemanager 9.03\licensecheck.exe |
"{B351ABA7-07E1-4E17-9246-BBB32A241F6E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BC63507A-5FE3-4E65-8F2B-0F58B007DB30}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{BD031721-5848-4FF0-A676-81937FCDBDFF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C4546C43-DCB5-4DDC-8C4F-9C60EB4BDC77}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C77D130A-8377-409C-99CE-9BC796A4F2E1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C8046D5A-5C7E-4A74-9827-890BBD864AA2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CC70B4C3-4D09-407D-8768-DF19B4514087}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DEC4E61C-1AED-414D-A53D-93C1BAF6441F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E3210E50-7361-43BE-8C8E-8E6021693ED6}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{E816B9E1-E34C-4901-90C8-EC737FC3E6BD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EC59B00F-BF6A-4C0A-9231-F515BCC786B4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FC7705A7-6F66-467F-A95F-76B46FD8FF7E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FEA451B3-7787-44BA-8F9B-5465CE420F1E}" = protocol=6 | dir=out | app=system |
"TCP Query User{9360CD7D-E98D-4CB6-89E9-87D927A6BBA0}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{1F3C54AC-5A41-40AA-9159-73D567DC96D0}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{04AF7536-446D-4F5A-8920-B4E885E4581B}" = Presto! PageManager 9.03 SE
"{065D5505-3821-4C2E-BB6C-FE66A7E7CB4F}" = USB Flash Port Driver
"{07D77970-B205-460C-84E4-263F30455597}" = Nokia Ovi Suite
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Toolbar
"{085A087C-8559-AC21-F988-9B885923B58B}" = CCC Help Japanese
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{0A1CAF84-CDC8-477F-997F-800AB090EA46}" = Serif Premium Template Pack 1 for WebPlus
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
"{12451AF7-EFF8-4B5B-8255-282D7CC7CAEE}" = OviMPlatform
"{17BDCAD2-39E2-A44B-CDCA-6854FA71421E}" = Catalyst Control Center Localization All
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{1D61E881-43CD-447B-9E6B-D2C6138B2862}" = HP Webcam
"{1D7DBD8E-4E22-B307-81F4-D55080B16FC7}" = ccc-utility
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2CC53A53-44F4-4667-8584-2FFC9ACB2242}" = Ovi Desktop Sync Engine
"{2D270A67-B7CD-4281-B2FE-60DF18D19B8E}" = Kaspersky PURE 2.0
"{2D99A593-C841-43A7-B7C9-D6F3AE70B756}" = Nokia Connectivity Cable Driver
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2F892D3E-3F96-4518-B715-F8D5A6E256DF}" = KONICA MINOLTA PageScope Box Operator 3.2.02000
"{30A2A953-DEB1-466A-B660-F4399C7C6B9D}" = Roxio MyDVD
"{31D9C74D-CD7A-4215-B1E4-DF8099AEA997}" = Catalyst Control Center - Branding
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{37D6F9FA-A5F2-3040-AF7B-78BE92957D89}" = CCC Help Thai
"{38BA2875-D7AD-4611-ABA3-C385051ADF42}" = Eraser 6.0.7.1893
"{38CA1644-39F5-44EB-F200-DFC6C5E9C5A8}" = CCC Help Chinese Standard
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D0C22FA-96D7-4789-BC5B-991A5A99BFFA}" = Windows Live Messenger
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{41D6CED7-65E8-4EBB-BB1A-B45E2D8CF6D7}" = Windows Live Family Safety
"{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B1EDAFC-B0EB-465F-886C-24FAC1BED2AC}" = Windows Live Remote Client Resources
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4D833CF3-A3AE-2863-584B-3AD3A0D70981}" = CCC Help Russian
"{4F46FDB9-B906-47BF-B3D5-C62E01B3C5EE}" = HP Support Assistant
"{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1" = Data Lifeguard Diagnostic for Windows 1.24
"{52AD35F5-FDA6-6E74-27E4-5EC2BD8A8B29}" = CCC Help Korean
"{52B24A16-729C-BDB9-D921-01556B19283D}" = CCC Help Greek
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Creator Business
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{55485AA6-B3C8-4FEF-9A1E-09B7DE3DB589}" = Serif WebPlus X4 Bonus Content Pack
"{565AEE5D-35E5-0A21-02E2-3DC8CEA652FB}" = Catalyst Control Center Graphics Light
"{57115A63-203E-8864-8951-4D5864D23956}" = CCC Help Norwegian
"{572964E9-BE64-1F57-B672-4D2B7595FAA1}" = Catalyst Control Center Graphics Full Existing
"{5AE47629-FA38-4747-4CEA-1DD2983FA8BF}" = CCC Help German
"{5B295588-59C1-4386-9F85-BB4BEDCB0D22}" = HP Customer Experience Enhancements
"{5BF8E079-D6E2-4323-B794-75152371122A}" = Windows 7 Default Setting
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5E984B44-B441-5361-B00B-91441EE7B5B4}" = CCC Help English
"{602C75D1-0C09-D216-D83D-F3126AC24A27}" = CCC Help French
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65C0025A-2CDE-43C5-82D0-C7A56EF0DB39}" = Bing Bar Platform
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68EB2C37-083A-4303-B5D8-41FA67E50B8F}_is1" = Poedit
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}" = Vodafone Mobile Broadband Lite
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common
"{76AF1F61-BB44-4694-A0EA-C6830C8BEF41}" = HP Software Setup
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B20C1C7-2766-DDB8-A02E-D6F9C7341864}" = CCC Help Finnish
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7EFEE754-EA7D-A79B-8DDA-65CADCAF1AB4}" = Catalyst Control Center InstallProxy
"{7FFAA34E-0AA6-BF03-D37C-7AC5C380CF2F}" = CCC Help Chinese Traditional
"{805F8590-510E-74AD-FC88-ADE4224B8854}" = CCC Help Polish
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{853403A9-70A9-2C60-9E74-67BDC650E820}" = Catalyst Control Center Core Implementation
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{86CE1746-9EFF-3C9C-8755-81EA8903AC34}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87CA636B-85B8-4611-A81D-F97E71024AFD}" = HP Common Access Service Library
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A75B387-6A34-7FBE-3512-89809AF89524}" = CCC Help Hungarian
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8ED43F7E-A8F6-4898-AF11-B6158F2EDF94}" = Epson Event Manager
"{8F0EDF80-31C2-FA10-DEE8-BD435A5F7D61}" = ATI Catalyst Install Manager
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-040C-0000-0000000FF1CE}" = Microsoft Office Access MUI (French) 2007
"{90120000-0015-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0410-0000-0000000FF1CE}" = Microsoft Office Access MUI (Italian) 2007
"{90120000-0015-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0413-0000-0000000FF1CE}" = Microsoft Office Access MUI (Dutch) 2007
"{90120000-0015-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-040C-0000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2007
"{90120000-0016-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0410-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Italian) 2007
"{90120000-0016-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0413-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Dutch) 2007
"{90120000-0016-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2007
"{90120000-0018-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0410-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Italian) 2007
"{90120000-0018-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0413-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Dutch) 2007
"{90120000-0018-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-040C-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (French) 2007
"{90120000-0019-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0410-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Italian) 2007
"{90120000-0019-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0413-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Dutch) 2007
"{90120000-0019-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-040C-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (French) 2007
"{90120000-001A-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0410-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Italian) 2007
"{90120000-001A-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0413-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Dutch) 2007
"{90120000-001A-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-040C-0000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2007
"{90120000-001B-040C-0000-0000000FF1CE}_PROHYBRIDR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0410-0000-0000000FF1CE}" = Microsoft Office Word MUI (Italian) 2007
"{90120000-001B-0410-0000-0000000FF1CE}_PROHYBRIDR_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0413-0000-0000000FF1CE}" = Microsoft Office Word MUI (Dutch) 2007
"{90120000-001B-0413-0000-0000000FF1CE}_PROHYBRIDR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007
"{90120000-001F-0401-0000-0000000FF1CE}_PROHYBRIDR_{14809F99-C601-4D4A-9391-F1E8FAA964C5}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROHYBRIDR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0413-0000-0000000FF1CE}_PROHYBRIDR_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-002C-040C-0000-0000000FF1CE}" = Microsoft Office Proofing (French) 2007
"{90120000-002C-0410-0000-0000000FF1CE}" = Microsoft Office Proofing (Italian) 2007
"{90120000-002C-0413-0000-0000000FF1CE}" = Microsoft Office Proofing (Dutch) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PROHYBRIDR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-040C-0000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2007
"{90120000-006E-040C-0000-0000000FF1CE}_PROHYBRIDR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0410-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Italian) 2007
"{90120000-006E-0410-0000-0000000FF1CE}_PROHYBRIDR_{0A75DA12-55CB-4DE5-8B6A-74D97847204E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0413-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Dutch) 2007
"{90120000-006E-0413-0000-0000000FF1CE}_PROHYBRIDR_{89C8E56A-90D8-4598-B0E6-EB28F6270E07}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0410-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96CFF0DB-C3C3-44B8-930C-1121EC68A3BF}" = Serif WebPlus X4 Resources
"{9ADA45A0-8043-470A-8E8B-02EA7D95F896}" = Serif WebPlus X4
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E4FC4A7-E9E1-1EF1-104B-ECFB738A1824}" = CCC Help Italian
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = HP Integrated Module with Bluetooth wireless technology
"{9EE30AB4-1D07-7C32-106D-7AE7CEEFD1EC}" = CCC Help Spanish
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{A45AF5E2-3648-EA45-2A62-C3EA975D57D9}" = Catalyst Control Center Graphics Full New
"{A657B744-4F40-6973-D177-5FD028712702}" = ccc-core-static
"{A6C3D5F0-3C6C-46BF-A8D0-06EE92E02E9E}_is1" = AD Blocker
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7554849-3B09-4A89-86E5-FC62498B470F}" = Epp Client
"{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}" = IMinent Toolbar
"{A8F7FCEF-3CA6-4CE9-8FEA-8BB18F8686F0}" = Nokia Ovi Suite Software Updater
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC0628FF-532F-4800-91EC-40903B04682F}" = Windows Live Remote Service Resources
"{AC76BA86-7AD7-1040-7B44-A94000000001}" = Adobe Reader 9.4.7 - Italiano
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B0344B38-378B-47E0-BDCC-977785D24768}" = Integrated Camera Driver Installer Package Ver.[removed]
"{B1EE1CC5-6CED-4801-BFFF-8454F21A245A}" = Garmin Communicator Plugin
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B26449A6-6007-4460-B4FE-C4776115BCEA}" = Epson Customer Research Participation
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B8ECD0D3-AE08-4891-B6C7-32F96B75EB6C}" = EPSON Printer Finder
"{BA728FCC-0B8C-6F7F-B29C-583829D1E8BB}" = CCC Help Dutch
"{C373F7C4-05D2-4047-96D1-6AF30661C6AA}" = PC Connectivity Solution
"{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections
"{C7AE4EC3-9C13-4213-8457-74D16B353F91}" = HP Web Camera
"{C7DAD22D-29D4-438F-B986-03B9ED582EA4}" = Messenger Companion
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D0BFE65D-C320-4FC9-88D2-B9C32FB95DA0}" = HP Setup
"{D2131BFA-A0D6-4FDE-8614-75B07A9B15EE}" = Windows Live UX Platform Language Pack
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D52E5A05-8A76-46A5-BD34-06CB0493F1AD}" = HP QuickLook
"{D796ABCD-73D4-F18D-CF80-9BA1BE403933}" = CCC Help Swedish
"{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}" = Epson Connect Printer Setup
"{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials
"{E045FAC9-0B70-4796-AD3A-7035E89CE536}" = SCR3xxx Smart Card Reader
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E48D0275-B2E0-C879-4B86-506757A16DC7}" = CCC Help Turkish
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E728441A-7820-4B1C-87C9-DE7BE37B2953}" = Download Navigator
"{E9B0164A-27EA-4C31-5526-867C6882B60D}" = CCC Help Czech
"{EA891D60-C20D-03C4-88CB-E4597A1753AA}" = CCC Help Portuguese
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EBDEA960-D5D6-4047-91C7-C2064072A409}" = HP User Guides 0136
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Business v10
"{EE70E5CC-B1D7-4FC0-7DC5-5460EF22FFC9}" = Widget vodafone.it
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F173C2B3-296F-458C-98FF-1676A42EBA02}" = HP Wallpaper
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F3818CCA-B7E4-2B53-F86E-2D4F195F66F3}" = CCC Help Danish
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F91CF0E6-7B98-45DB-AE57-B6E09C40B364}" = OpenOffice.org 3.4
"{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFBDA363-A033-4F32-8DE0-AEF0F105410E}" = HP ESU for Microsoft Windows 7
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"504244733D18C8F63FF584AEB290E3904E791693" = Pacchetto driver Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"7D6D030B3D73FCCA3D4E45319380F315DFBE7A54" = Pacchetto driver Windows - Infineon Technologies (FlashUSB) USB (04/16/2009 1.0.0.6)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AndreaMosaic" = AndreaMosaic 3.33.0
"Anvi Smart Defender" = Anvi Smart Defender 1.8
"Any Audio Converter_is1" = Any Audio Converter 3.0.7
"Any DVD Converter Professional_is1" = Any DVD Converter Professional 4.3.4
"Aptana Studio 3" = Aptana Studio 3
"asterisk key" = Asterisk Key 10.0
"CCleaner" = CCleaner
"CoffeeCup Free HTML Editor" = CoffeeCup Free HTML Editor
"ColorDetector200_is1" = Color Detector 2.0
"DivX Setup" = DivX Setup
"doPDF 7 printer_is1" = doPDF 7.2 printer
"EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
"EPSON Scanner" = EPSON Scan
"EPSON WF-7515 Series" = EPSON WF-7515 Series Printer Uninstall
"EPSON WF-7515 Series Netg" = Guida di rete EPSON WF-7515 Series
"EPSON WF-7515 Series Useg" = Guida utente EPSON WF-7515 Series
"FileZilla Client" = FileZilla Client 3.6.0.2
"Fotosizer" = Fotosizer 1.35
"Free Audio Dub_is1" = Free Audio Dub version 1.7.9.908
"Freemake Video Converter_is1" = Freemake Video Converter versione 2.3.4
"GSiteCrawler" = GSiteCrawler
"HxD Hex Editor_is1" = HxD Hex Editor versione 1.7.7.0
"Infineon USB driver_is1" = Infineon USB driver 1.0.0.6
"InstallWIX_{2D270A67-B7CD-4281-B2FE-60DF18D19B8E}" = Kaspersky PURE 2.0
"IrfanView" = IrfanView (remove only)
"it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1" = Widget vodafone.it
"jZip" = jZip
"Marvell Miniport Driver" = Marvell Miniport Driver
"MemoriesOnTV3-CS1_is1" = MemoriesOnTV ClipShow Volume 1.1
"MemoriesOnTV4_is1" = MemoriesOnTV 4.1.2
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Nokia Ovi Suite" = Nokia Ovi Suite
"NTSInformaticaBusiness_is1" = Business NET 2009
"PageBreeze Free HTML Editor" = PageBreeze Free HTML Editor
"PROHYBRIDR" = 2007 Microsoft Office system
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Total Video Converter 3.61_is1" = Total Video Converter 3.61 100319
"Total Video Converter 3.71_is1" = Total Video Converter 3.71 100812
"VLC media player" = VLC media player 1.1.2
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.45-4
"WinLiveSuite" = Windows Live Essentials
"winscp3_is1" = WinSCP 4.2.9

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 12/27/2012 5:55:24 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/27/2012 5:55:24 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3354

Error - 12/27/2012 5:55:24 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3354

Error - 12/28/2012 5:53:04 AM | Computer Name = PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 12/28/2012 6:42:37 AM | Computer Name = PC | Source = VmbService | ID = 0
Description = conflictManagerTypeValue

Error - 12/28/2012 10:00:38 AM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: svchost.exe_SysMain,
versione: 6.1.7600.16385, timestamp: 0x4a5bc100 Nome del modulo che ha generato
l'errore: sysmain.dll, versione: 6.1.7600.16385, timestamp: 0x4a5bdb23 Codice eccezione:
0xc0000006 Offset errore 0x0009af43 ID processo che ha generato l'errore: 0x430 Ora
di avvio dell'applicazione che ha generato l'errore: 0x01cde4e804b8d654 Percorso
dell'applicazione che ha generato l'errore: C:\windows\System32\svchost.exe Percorso
del modulo che ha generato l'errore: c:\windows\system32\sysmain.dll ID segnalazione:
f49c75c5-50f6-11e2-8e9d-cbe1ac0062c0

Error - 12/28/2012 10:00:38 AM | Computer Name = PC | Source = Application Error | ID = 1005
Description = Impossibile accedere al file C:\Windows\Prefetch\AgCx_SC1.db.trx per
uno dei motivi seguenti: Si è verificato un problema relativo alla connessione
di rete, al disco in cui è archiviato il file o ai driver di archiviazione installati
nel computer oppure il disco è assente. Il programma Processo host per servizi di
Windows è stato chiuso a causa dell'errore. Programma: Processo host per servizi
di Windows File: C:\Windows\Prefetch\AgCx_SC1.db.trx Il valore dell'errore è indicato
nella sezione Dati aggiuntivi. Azione utente 1. Aprire nuovamente il file. Potrebbe
trattarsi di un problema temporaneo che si risolverà automaticamente rieseguendo
il programma. 2. Se il file risulta comunque non accessibile e: - Si trova in rete,
è
necessario che l'amministratore della rete verifichi la presenza di eventuali problemi
di rete e che sia possibile contattare il server. - Si trova in un disco rimovibile,
ad esempio un disco floppy o un CD, verificare che il disco sia inserito correttamente
nel computer. 3. Controllare e ripristinare il file system eseguendo CHKDSK. Per
eseguire CHKDSK, fare clic sul pulsante Start, scegliere Esegui, digitare CMD,
quindi scegliere OK. Al prompt dei comandi, digitare CHKDSK /F, quindi premere INVIO.
4.
Se il problema persiste, ripristinare il file da una copia di backup. 5. Determinare
se è possibile aprire altri file nello stesso disco. Se non è possibile, il disco
potrebbe essere danneggiato. Se si tratta di un disco rigido, contattare l'amministratore
o il fornitore dell'hardware del computer per ottenere assistenza. Dati aggiuntivi
Valore
errore: C0000185 Tipo disco: 3

Error - 12/28/2012 10:32:48 AM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: XoftSpySE_Setup_RW.exe,
versione: 7.0.1.0, timestamp: 0x4f47e2df Nome del modulo che ha generato l'errore:
System.dll, versione: 0.0.0.0, timestamp: 0x4bccb8d8 Codice eccezione: 0xc0000005
Offset
errore 0x000018ed ID processo che ha generato l'errore: 0x1f2c Ora di avvio dell'applicazione
che ha generato l'errore: 0x01cde50807adfd3e Percorso dell'applicazione che ha generato
l'errore: C:\Users\utente\Downloads\XoftSpySE_Setup_RW.exe Percorso del modulo che
ha generato l'errore: C:\Users\utente\AppData\Local\Temp\nsu282E.tmp\System.dll
ID
segnalazione: 731c850c-50fb-11e2-8e9d-cbe1ac0062c0

Error - 12/28/2012 10:55:04 AM | Computer Name = PC | Source = VmbService | ID = 0
Description = conflictManagerTypeValue

Error - 12/28/2012 1:25:24 PM | Computer Name = PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Servizi di crittografia: impossibile elaborare la chiamata OnIdentity()
nell'oggetto writer del sistema. Details: AddLegacyDriverFiles: Unable to back up
image of binary SASKUTIL. System Error: Impossibile trovare il file specificato. .

Error - 12/28/2012 1:58:58 PM | Computer Name = PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Servizi di crittografia: impossibile elaborare la chiamata OnIdentity()
nell'oggetto writer del sistema. Details: AddLegacyDriverFiles: Unable to back up
image of binary SASKUTIL. System Error: Impossibile trovare il file specificato. .

Error - 12/28/2012 2:01:10 PM | Computer Name = PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Servizi di crittografia: impossibile elaborare la chiamata OnIdentity()
nell'oggetto writer del sistema. Details: AddLegacyDriverFiles: Unable to back up
image of binary SASKUTIL. System Error: Impossibile trovare il file specificato. .

[ Hewlett-Packard Events ]
Error - 7/2/2010 9:03:15 AM | Computer Name = pc-paride | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF

in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 4/29/2011 10:29:59 AM | Computer Name = pc-paride | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF

in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 8/17/2012 8:43:35 AM | Computer Name = PC | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF

in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 9/28/2012 9:15:53 AM | Computer Name = PC | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF

in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 10/12/2012 2:38:49 PM | Computer Name = PC | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF

in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 11/9/2012 10:38:50 AM | Computer Name = PC | Source = Hewlett-Packard | ID = 0
Description = it-IT Riferimento a un oggetto non impostato su un'istanza di oggetto.
HPSF

in HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender,
RoutedEventArgs e) in System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object
target, RoutedEventArgs routedEventArgs) in System.Windows.EventRoute.InvokeHandlersImpl(Object
source, RoutedEventArgs args, Boolean reRaised) in System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) in System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) in System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) in System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) in MS.Internal.LoadedOrUnloadedOperation.DoWork() in System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

in System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() in System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) in System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) in System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) in System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


[ OSession Events ]
Error - 7/24/2010 8:50:08 AM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 17
seconds with 0 seconds of active time. This session ended with a crash.

Error - 8/6/2010 2:50:40 PM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11/13/2010 10:08:57 AM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4092
seconds with 960 seconds of active time. This session ended with a crash.

Error - 11/24/2010 5:00:58 AM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3794
seconds with 1740 seconds of active time. This session ended with a crash.

Error - 7/3/2011 1:13:07 PM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11607
seconds with 5400 seconds of active time. This session ended with a crash.

Error - 9/29/2011 4:01:21 AM | Computer Name = pc-paride | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 151
seconds with 120 seconds of active time. This session ended with a crash.

Error - 2/19/2012 5:39:09 PM | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 24023
seconds with 360 seconds of active time. This session ended with a crash.

Error - 7/1/2012 10:41:49 AM | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 112
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/9/2012 2:43:59 PM | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 32306
seconds with 6780 seconds of active time. This session ended with a crash.

Error - 9/9/2012 2:51:39 PM | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 169
seconds with 60 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068

Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068

Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068

Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068

Error - 12/28/2012 2:21:27 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068

Error - 12/28/2012 2:21:29 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068

Error - 12/28/2012 2:21:29 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068

Error - 12/28/2012 2:21:29 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Browser di computer dipende dal servizio Server che non
è stato avviato per il seguente errore: %%1068

Error - 12/28/2012 2:21:32 PM | Computer Name = PC | Source = DCOM | ID = 10005
Description =

Error - 12/28/2012 2:21:32 PM | Computer Name = PC | Source = DCOM | ID = 10005
Description =

Error - 12/28/2012 2:21:33 PM | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Provider Gruppo Home dipende dal servizio Host provider
di individuazione funzioni che non è stato avviato per il seguente errore: %%1068


< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

AdwCleaner

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-
Hi Jeff and this is the AdwCleaner result I'm not sure if I upload the aswMBR log file: I upload it again now # AdwCleaner v2.103 - Logfile creato il 28/12/2012 alle 23:47:50 # Aggiornamento 25/12/2012 by Xplode # Sistema Operativo : Windows 7 Professional (32 bits) # Utente : utente - PC # Modalità Avvio : Modalità Normale # Eseguito da : C:\Users\utente\Desktop\AdwCleaner.exe # Opzioni [Elimina] ***** [Servizi] ***** ***** [File / Cartelle] ***** Cartella Eliminato : C:\Program Files\IMinent toolbar Cartella Eliminato : C:\ProgramData\AGI Cartella Eliminato : C:\Users\utente\AppData\LocalLow\Toolbar4 Cartella Eliminato : C:\Users\utente\AppData\Roaming\OpenCandy File Eliminato : C:\END ***** [Registro] ***** Chiave Eliminata : HKCU\Software\AppDataLow\Software\SmartBar Chiave Eliminata : HKCU\Software\Conduit Chiave Eliminata : HKCU\Software\Iminent Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{58124A0B-DC32-4180-9BFF-E0E21AE34026} Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{58124A0B-DC32-4180-9BFF-E0E21AE34026} Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Chiave Eliminata : HKCU\Software\Softonic Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E} Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{58124A0B-DC32-4180-9BFF-E0E21AE34026} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0} Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B} Chiave Eliminata : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler Chiave Eliminata : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\Installer\Features\482AA67AD25E6E74E9F48BD5FBE8533C Chiave Eliminata : HKLM\SOFTWARE\Classes\Installer\Products\482AA67AD25E6E74E9F48BD5FBE8533C Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Chiave Eliminata : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils Chiave Eliminata : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.TbRequest Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.TbTask Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper Chiave Eliminata : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\TBSB01620.IEToolbar Chiave Eliminata : HKLM\SOFTWARE\Classes\TBSB01620.IEToolbar.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\TBSB01620.TBSB01620 Chiave Eliminata : HKLM\SOFTWARE\Classes\TBSB01620.TBSB01620.3 Chiave Eliminata : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier Chiave Eliminata : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl Chiave Eliminata : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\Toolbar3.TBSB01620 Chiave Eliminata : HKLM\SOFTWARE\Classes\Toolbar3.TBSB01620.1 Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D} Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148} Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C} Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E} Chiave Eliminata : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook Chiave Eliminata : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1 Chiave Eliminata : HKLM\Software\Iminent Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7B63B2922B174135AFC0E1377DD81EC2} Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3} Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\49CF605F02C7954F4E139D18828DE298CD59217C Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\504244733D18C8F63FF584AEB290E3904E791693 Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7D6D030B3D73FCCA3D4E45319380F315DFBE7A54 Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1 Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Valore Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [] ***** [Browser Internet] ***** -\\ Internet Explorer v8.0.7600.16766 Sostituito : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=IT&userid=648a6e50-a123-46e1-bf56-c2b2964cfe4f&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} –> hxxp://www.google.com Sostituito : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=IT&userid=648a6e50-a123-46e1-bf56-c2b2964cfe4f&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} –> hxxp://www.google.com Sostituito : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=IT&userid=648a6e50-a123-46e1-bf56-c2b2964cfe4f&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} –> hxxp://www.google.com Sostituito : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=IT&userid=648a6e50-a123-46e1-bf56-c2b2964cfe4f&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} –> hxxp://www.google.com -\\ Google Chrome v23.0.1271.97 File : C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File Pulito. ************************* AdwCleaner[S1].txt - [13559 octets] - [28/12/2012 23:47:50] ########## EOF - C:\AdwCleaner[S1].txt - [13620 octets] ##########

Attachments:

Hi,

Good job!!

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL


    :Services

    :OTL
    IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://btsearch.name
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKCU\..\SearchScopes,DefaultScope = {8d492f70-ea37-453e-a0e4-9d709483a4cd}
    IE - HKCU\..\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}: "URL" = http://btsearch.name/results.php?q={searchTerms}
    O33 - MountPoints2\{1c434c24-1fdc-11e1-916b-8948ce200d89}\Shell - "" = AutoRun
    O33 - MountPoints2\{1c434c24-1fdc-11e1-916b-8948ce200d89}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{2401276b-4718-11e1-8c0d-869dba3b719a}\Shell - "" = AutoRun
    O33 - MountPoints2\{2401276b-4718-11e1-8c0d-869dba3b719a}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{3dc5bb52-7099-11df-80d2-d8d385117a41}\Shell - "" = AutoRun
    O33 - MountPoints2\{3dc5bb52-7099-11df-80d2-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{4760c7e9-7a41-11df-b999-0027138b4d63}\Shell - "" = AutoRun
    O33 - MountPoints2\{4760c7e9-7a41-11df-b999-0027138b4d63}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{9690b8c2-708b-11df-8e80-d8d385117a41}\Shell - "" = AutoRun
    O33 - MountPoints2\{9690b8c2-708b-11df-8e80-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{9690b8cb-708b-11df-8e80-d8d385117a41}\Shell - "" = AutoRun
    O33 - MountPoints2\{9690b8cb-708b-11df-8e80-d8d385117a41}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{a3c521a8-7a4d-11df-8036-0027138b4d63}\Shell - "" = AutoRun
    O33 - MountPoints2\{a3c521a8-7a4d-11df-8036-0027138b4d63}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\Shell - "" = AutoRun
    O33 - MountPoints2\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{fb160359-d177-11e0-95ae-a0e442636015}\Shell - "" = AutoRun
    O33 - MountPoints2\{fb160359-d177-11e0-95ae-a0e442636015}\Shell\AutoRun\command - "" = D:\setup_vmb_lite.exe /checkApplicationPresence
    O33 - MountPoints2\D\Shell - "" = AutoRun
    O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
    [1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
    [1 C:\Users\utente\Desktop\*.tmp files -> C:\Users\utente\Desktop\*.tmp -> ]
    [2010/11/23 08:37:23 | 000,000,600 | —- | C] () – C:\Users\utente\AppData\Local\PUTTY.RND
    [2010/11/23 00:16:57 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\GetRightToGo
    [2012/08/16 15:02:34 | 000,000,000 | —D | M] – C:\Users\utente\AppData\Roaming\OpenCandy

    :Files
    ipconfig /flushdns /c

    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

Post the new OTL log and let me know how your system is running now. :)
RunFix result

All processes killed
Error: Unable to interpret in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8d492f70-ea37-453e-a0e4-9d709483a4cd}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1c434c24-1fdc-11e1-916b-8948ce200d89}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1c434c24-1fdc-11e1-916b-8948ce200d89}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1c434c24-1fdc-11e1-916b-8948ce200d89}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1c434c24-1fdc-11e1-916b-8948ce200d89}\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2401276b-4718-11e1-8c0d-869dba3b719a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2401276b-4718-11e1-8c0d-869dba3b719a}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2401276b-4718-11e1-8c0d-869dba3b719a}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2401276b-4718-11e1-8c0d-869dba3b719a}\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3dc5bb52-7099-11df-80d2-d8d385117a41}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3dc5bb52-7099-11df-80d2-d8d385117a41}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3dc5bb52-7099-11df-80d2-d8d385117a41}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3dc5bb52-7099-11df-80d2-d8d385117a41}\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4760c7e9-7a41-11df-b999-0027138b4d63}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4760c7e9-7a41-11df-b999-0027138b4d63}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4760c7e9-7a41-11df-b999-0027138b4d63}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4760c7e9-7a41-11df-b999-0027138b4d63}\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9690b8c2-708b-11df-8e80-d8d385117a41}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9690b8c2-708b-11df-8e80-d8d385117a41}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9690b8c2-708b-11df-8e80-d8d385117a41}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9690b8c2-708b-11df-8e80-d8d385117a41}\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9690b8cb-708b-11df-8e80-d8d385117a41}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9690b8cb-708b-11df-8e80-d8d385117a41}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9690b8cb-708b-11df-8e80-d8d385117a41}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9690b8cb-708b-11df-8e80-d8d385117a41}\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3c521a8-7a4d-11df-8036-0027138b4d63}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3c521a8-7a4d-11df-8036-0027138b4d63}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3c521a8-7a4d-11df-8036-0027138b4d63}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3c521a8-7a4d-11df-8036-0027138b4d63}\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f29fd0c3-1f64-11e1-9f86-af203c63d3e1}\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb160359-d177-11e0-95ae-a0e442636015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fb160359-d177-11e0-95ae-a0e442636015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb160359-d177-11e0-95ae-a0e442636015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fb160359-d177-11e0-95ae-a0e442636015}\ not found.
File D:\setup_vmb_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ not found.
File D:\setup_vmc_lite.exe /checkApplicationPresence not found.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCall.dll deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCalla.dll deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCalla17.dll deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCalla18.exe deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCalla19.dll deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCalla2.dll deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCalla20.dll deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCalla21.dll deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseCustomCalla21.exe deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP\WiseData.ini deleted successfully.
C:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP folder deleted successfully.
C:\Users\utente\Desktop\~WRL0003.tmp deleted successfully.
C:\Users\utente\AppData\Local\PUTTY.RND moved successfully.
C:\Users\utente\AppData\Roaming\GetRightToGo folder moved successfully.
Folder C:\Users\utente\AppData\Roaming\OpenCandy\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Configurazione IP di Windows
Cache del resolver DNS svuotata.
C:\Users\utente\Desktop\cmd.bat deleted successfully.
C:\Users\utente\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: utente
->Temp folder emptied: 109484311 bytes
->Temporary Internet Files folder emptied: 4123919 bytes
->Java cache emptied: 10834092 bytes
->Google Chrome cache emptied: 415538076 bytes
->Flash cache emptied: 57670 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 82534 bytes
RecycleBin emptied: 63544972 bytes

Total Files Cleaned = 576.00 mb

C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 12292012_105833

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Opening chrome I'm still getting btsearch.name tab. :(

New Runscan without LOP and Purity check (I did paste the Custom Scan of the Are You Infected topic)



OTL logfile created on: 12/29/2012 11:13:37 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\utente\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 1.36 Gb Available Physical Memory | 45.98% Memory free
5.93 Gb Paging File | 4.04 Gb Available in Paging File | 68.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 188.04 Gb Free Space | 41.93% Space Free | Partition Type: NTFS
Drive E: | 1.99 Gb Total Space | 1.76 Gb Free Space | 88.37% Space Free | Partition Type: FAT32

Computer Name: PC | User Name: utente | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\utente\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe (Anvisoft)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerSrv.exe ()
PRC - C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()
PRC - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\EPSON Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\EPSON Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
PRC - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\Eraser\Eraser.exe (The Eraser Project)
PRC - C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - c:\program files\windows defender\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\sqlite3.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtGui4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtNetwork4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtScript4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtSql4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtDeclarative4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtCore4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\dblite.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qgif4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dda6d8c7413334b605fcf590a702e9f1\Microsoft.VisualBasic.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\bf0286e181064f9ded08895c7f23967d\System.Core.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\94eb4ca06f43edf88bbdecd3729657d5\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b6d66d3c48e430796c17d0497ce37972\System.ServiceProcess.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c519a7e1b063eb63b43fa5b3a782c641\System.Design.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\b867fbc0d573ac5e5fe71143d9caf43b\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\adc8998d96ca331d17cef00b1ef95a5f\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4be7719ea0e1f2ba2d3fde051d1ef7ab\System.Transactions.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\b9565c454a22ca564978b05db4186f22\System.Data.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7827588b8043e8be3184c8a64a867fc\PresentationFramework.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e4ea95056046fdf87f06ae807308b627\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2a34e74599686e7383ae90670a994cdf\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\11ebcba65c931267301739008a883e60\Accessibility.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\03dd2b7701ca5cfe696d4ca5a0f7b8bb\PresentationCore.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\caa9d8bca3092573cdbb67c8e81bf0f3\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\395fc7d9f333940351a74aaab5d6ae99\System.Security.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\167c8c3817ba1f48fe7396cc56f557e3\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9d054fc9618b81d5703af1662cd11135\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\50c67f851ae3df2d0ab7d86fd1c5c7e0\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ebdaeaeb9f66c9035b5f11431f10cda4\mscorlib.ni.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\ScanModule.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMScnSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMDB_N.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMCommon.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMISM.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMTree.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMImageSplitter.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMView.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSave.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMPageVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMImgVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMINSO.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\OutlookVBA.dll ()
MOD - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\Vodafone.View.Taskbar.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMPDFView.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\SlideBarDLL.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMOffice.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMProp.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PerformOcr.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMStatus.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3503.18374__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3503.18350__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3503.18376__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3503.18369__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3503.18360__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3503.18471__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3503.18426__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3503.18471__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3503.18427__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3503.18446__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3503.18360__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3503.18419__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3503.18426__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3503.18472__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3503.18470__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3503.18406__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3503.18409__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3503.18377__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3503.18439__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3503.18363__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3503.18376__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3503.18415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3503.18408__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3503.18382__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3503.18415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3503.18407__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3503.18402__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3503.18417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3503.18383__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3503.18407__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3503.18408__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3503.18417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3428.28302__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3428.28329__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3428.28305__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3428.28298__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3428.28324__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3428.28296__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3428.28297__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3428.28354__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3428.28304__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3428.28302__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3428.28310__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3428.28324__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3428.28303__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3428.28316__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3428.28309__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3428.28323__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3428.28311__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Foundation\2.0.3428.28310__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3503.18465__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3503.18463__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3503.18478__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3428.28301__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3428.28310__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3503.18344__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3503.18356__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3503.18368__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3503.18348__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3503.18347__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3428.28309__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3428.28316__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Server\2.0.3503.18346__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server\2.0.3503.18345__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3503.18464__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMDocVW.dll ()
MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_it_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMAnoSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMAppBar.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\NetFun2k.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMANO.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\FT.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll ()
MOD - C:\Windows\System32\msjetoledb40.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMApSet.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\nsSign.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PHooKDlg.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMIEVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMVoice.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMENC.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMAESLib.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\MCharSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\Qem.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\NsOEMKey.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\Import.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\ComClass.dll ()
MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\sqlite3.dll ()


========== Services (SafeList) ==========

SRV - (asdsrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe (Anvisoft)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (ADBlockerSrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerSrv.exe ()
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
SRV - (EpsonCustomerResearchParticipation) – C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (VmbService) – C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (CSObjectsSrv) – C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (yksvc) – C:\Windows\System32\yk62x86.dll (Marvell)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (RoxMediaDB10) – c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (AEADIFilters) – C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV - (RkHit) – C:\windows\system32\drivers\RKHit.sys File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (asdrs) – C:\Windows\System32\drivers\asdrs.sys (Anvisoft)
DRV - (asdws) – C:\Windows\System32\drivers\asdws.sys ()
DRV - (asdrm) – C:\Windows\System32\drivers\asdrm.sys (Anvisoft)
DRV - (taphss6) – C:\Windows\System32\drivers\taphss6.sys (Anchorfree Inc.)
DRV - (HssDRV6) – C:\Windows\System32\drivers\hssdrv6.sys (AnchorFree Inc.)
DRV - (KLIF) – C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (asdnet) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\sys\x86\asdnet.sys ()
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (KLIM6) – C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV - (vodafone_K3805-z_cdc_ecm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) – C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) – C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (FsUsbExDisk) – C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NETw5s32) – C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (CSCrySec) – C:\Windows\System32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) – C:\Windows\System32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (klmouflt) – C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (netw5v32) – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (hpdskflt) – C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard)
DRV - (Accelerometer) – C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard)
DRV - (5U876UVC) – C:\Windows\System32\drivers\5U876.sys (Ricoh co.,Ltd.)
DRV - (mfetdik) – C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pfc) – C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://btsearch.name
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
IE - HKCU\..\SearchScopes,DefaultScope = {8d492f70-ea37-453e-a0e4-9d709483a4cd}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKCU\..\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}: "URL" = http://btsearch.name/results.php?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]

[2012/09/17 15:23:28 | 000,000,000 | —D | M] (No name found) – C:\Users\utente\AppData\Roaming\mozilla\Extensions

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Custom search (Enabled)
CHR - default_search_provider: search_url = http://btsearch.name/results.php?q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\utente\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Orbit Downloader (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Flickr\u2122 Downloader = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebkkoejhhdbbohdhikahjanhbiegfhmi\3.0.0.0_0\
CHR - Extension: Qtube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhakcmpgccbfnmamojhjhaflhnfdooaa\1.11_0\
CHR - Extension: Gmail = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/12/29 10:59:21 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (YouTube Downloader) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
O3 - HKLM\..\Toolbar: (YouTube Downloader) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
O4 - HKLM..\Run: [ADBlocker] C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
O4 - HKLM..\Run: [Anvi Smart Defender] C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" –atRestart File not found
O4 - HKLM..\Run: [FUFAXRCV] C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [PMSpeed] C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE (NewSoft Technology Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
O4 - HKLM..\Run: [YouTube Downloader_Helper] C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()
O4 - HKCU..\Run: [EPSON WF-7515 Series] C:\windows\System32\spool\DRIVERS\W32X86\3\E_TATIHCE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe (Sonic Solutions)
O4 - Startup: C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 100
O8 - Extra context menu item: Aggiungi ad Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{65C17FEC-4D94-4AF8-917D-6111DA444667}: NameServer = 83.224.70.93 83.224.66.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{98ECAE4D-7803-485D-B168-2FF52E90694F}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC3BBE37-C7E4-4597-9FD9-51FEBDCB221B}: NameServer = 8.8.8.8,8.8.8.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.24
7.20,156.154.70.1,156.154.71.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF42F48F-3663-45FD-8BB4-4F3844DC57A5}: DhcpNameServer = 8.8.8.8
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/12/28 19:00:12 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv50 - C:\windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/29 10:58:33 | 000,000,000 | —D | C] – C:\_OTL
[2012/12/29 10:57:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/12/29 10:57:17 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/12/28 21:58:23 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/28 19:47:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:46:20 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\whatthetech
[2012/12/28 19:26:23 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Anvisoft
[2012/12/28 19:25:19 | 000,022,864 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrs.sys
[2012/12/28 19:25:19 | 000,016,208 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrm.sys
[2012/12/28 19:24:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft
[2012/12/28 19:24:52 | 000,000,000 | —D | C] – C:\ProgramData\Anvisoft
[2012/12/28 19:24:48 | 000,000,000 | —D | C] – C:\Program Files\Anvisoft
[2012/12/28 18:59:27 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/12/28 18:58:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/12/28 15:32:02 | 000,000,000 | —D | C] – C:\ProgramData\XoftSpySE
[2012/12/28 11:51:08 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Malwarebytes
[2012/12/28 11:50:44 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/12/28 11:50:30 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Local\Programs
[2012/12/28 10:52:26 | 000,000,000 | —D | C] – C:\Program Files\YouTube Downloader
[2012/12/28 10:51:31 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\november rain
[2012/12/28 10:05:10 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\SENE
[2012/12/19 22:59:34 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\Nuova cartella (2)
[2012/12/19 10:51:52 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\murrina
[2012/12/06 12:40:37 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\paypal
[2012/12/05 23:02:32 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\bedandcinema.com
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\Program Files\ColorDetector200
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Color Detector 2.0
[2012/12/04 11:57:04 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\BedAndCinema
[2012/11/30 10:05:27 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Local\{1192868A-6E88-42D4-87F8-FBDD2CB86138}

========== Files - Modified Within 30 Days ==========

[2012/12/29 11:10:01 | 000,000,978 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/12/29 11:08:42 | 000,001,134 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/29 11:08:02 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/29 11:08:02 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/29 11:00:52 | 000,065,536 | —- | M] () – C:\windows\System32\Ikeext.etl
[2012/12/29 11:00:41 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/12/29 11:00:33 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2012/12/29 10:59:21 | 000,000,098 | —- | M] () – C:\windows\System32\drivers\etc\Hosts
[2012/12/29 10:57:28 | 000,001,074 | —- | M] () – C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/12/29 10:57:18 | 000,000,894 | —- | M] () – C:\Users\utente\Desktop\NTREGOPT.lnk
[2012/12/29 10:57:18 | 000,000,875 | —- | M] () – C:\Users\utente\Desktop\ERUNT.lnk
[2012/12/29 10:54:00 | 000,001,164 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001UA.job
[2012/12/29 10:52:39 | 000,001,138 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/28 23:44:24 | 000,000,512 | —- | M] () – C:\Users\utente\Desktop\MBR.dat
[2012/12/28 22:22:56 | 000,550,017 | —- | M] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 21:59:21 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:25:19 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | M] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/12/28 16:02:32 | 000,698,570 | —- | M] () – C:\windows\System32\perfh010.dat
[2012/12/28 16:02:32 | 000,616,008 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/12/28 16:02:32 | 000,127,764 | —- | M] () – C:\windows\System32\perfc010.dat
[2012/12/28 16:02:32 | 000,106,388 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/12/28 15:54:56 | 000,000,436 | —- | M] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 15:05:52 | 000,001,112 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001Core.job
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2012/12/18 16:53:03 | 003,115,570 | —- | M] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/17 12:34:42 | 000,000,326 | —- | M] () – C:\windows\tasks\HPCeeScheduleForutente.job
[2012/12/16 22:15:14 | 000,000,218 | —- | M] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:47 | 000,271,046 | —- | M] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/12 20:11:29 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2012/12/12 20:11:29 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2012/12/10 09:48:08 | 000,470,393 | —- | M] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:28 | 001,040,996 | —- | M] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:29 | 000,612,798 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:11 | 000,219,495 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | M] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/03 11:38:02 | 000,001,363 | —- | M] () – C:\Users\utente\Desktop\Internet Explorer (No Add-ons).lnk
[2012/12/01 23:29:29 | 001,088,880 | —- | M] () – C:\Users\utente\Desktop\telecomando258.jpg
[2012/11/29 16:42:25 | 000,870,035 | —- | M] () – C:\Users\utente\Desktop\raccomandata NIC257.pdf
[2012/11/29 15:50:56 | 000,689,825 | —- | M] () – C:\Users\utente\Desktop\denuncia carabinieri 29-11.pdf
[2012/11/29 15:50:04 | 000,339,597 | —- | M] () – C:\Users\utente\Desktop\consegna chiavi255.pdf

========== Files Created - No Company Name ==========

[2012/12/29 10:57:28 | 000,001,074 | —- | C] () – C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/12/29 10:57:18 | 000,000,894 | —- | C] () – C:\Users\utente\Desktop\NTREGOPT.lnk
[2012/12/29 10:57:18 | 000,000,875 | —- | C] () – C:\Users\utente\Desktop\ERUNT.lnk
[2012/12/28 23:46:54 | 000,550,017 | —- | C] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 23:44:24 | 000,000,512 | —- | C] () – C:\Users\utente\Desktop\MBR.dat
[2012/12/28 19:25:19 | 000,014,160 | —- | C] () – C:\windows\System32\drivers\asdws.sys
[2012/12/28 19:25:19 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | C] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:00:12 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2012/12/28 15:53:02 | 000,000,436 | —- | C] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\mozilla.cfg
[2012/12/18 16:52:55 | 003,115,570 | —- | C] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/16 22:15:14 | 000,000,218 | —- | C] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:43 | 000,271,046 | —- | C] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/10 09:48:08 | 000,470,393 | —- | C] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:26 | 001,040,996 | —- | C] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:28 | 000,612,798 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:10 | 000,219,495 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | C] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/06 12:04:15 | 000,634,564 | —- | C] () – C:\Users\utente\Desktop\5 carta identità codice fiscale.pdf
[2012/12/01 23:29:29 | 001,088,880 | —- | C] () – C:\Users\utente\Desktop\telecomando258.jpg
[2012/11/29 16:42:23 | 000,870,035 | —- | C] () – C:\Users\utente\Desktop\raccomandata NIC257.pdf
[2012/11/29 15:50:56 | 000,689,825 | —- | C] () – C:\Users\utente\Desktop\denuncia carabinieri 29-11.pdf
[2012/11/29 15:50:04 | 000,339,597 | —- | C] () – C:\Users\utente\Desktop\consegna chiavi255.pdf
[2012/09/01 10:32:47 | 000,000,030 | —- | C] () – C:\windows\iedit_.INI
[2012/05/17 11:00:28 | 000,116,189 | —- | C] () – C:\windows\System32\drivers\klin.dat
[2012/05/17 11:00:28 | 000,098,168 | —- | C] () – C:\windows\System32\drivers\klick.dat
[2012/04/18 10:33:44 | 000,017,408 | —- | C] () – C:\Users\utente\AppData\Local\WebpageIcons.db
[2012/02/08 16:26:32 | 000,258,348 | —- | C] () – C:\Users\utente\AppData\Local\rx_image32.Cache
[2011/12/03 17:00:13 | 000,000,827 | —- | C] () – C:\windows\Brpfx04a.ini
[2011/12/03 17:00:13 | 000,000,161 | —- | C] () – C:\windows\brpcfx.ini
[2011/12/03 16:58:32 | 000,106,496 | —- | C] () – C:\windows\System32\BrMuSNMP.dll
[2011/12/03 16:52:17 | 000,000,420 | —- | C] () – C:\windows\BRWMARK.INI
[2011/12/03 16:52:17 | 000,000,065 | —- | C] () – C:\windows\System32\BD7820N.DAT
[2011/08/31 21:11:40 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2011/03/11 11:43:54 | 000,029,763 | —- | C] () – C:\windows\System32\drivers\klopp.dat
[2010/11/23 00:27:55 | 000,000,600 | —- | C] () – C:\Users\utente\AppData\Roaming\winscp.rnd
[2010/09/08 10:07:40 | 000,159,464 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4

========== ZeroAccess Check ==========

[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2010/07/27 15:03:24 | 012,867,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/14 02:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/01/11 21:08:57 | 000,004,183 | —- | M] () MD5=4CF10EA9BAB7750F41A7E154AECAF977 – C:\Windows\PolicyDefinitions\it-IT\Explorer.adml
[2010/01/11 21:08:57 | 000,004,183 | —- | M] () MD5=4CF10EA9BAB7750F41A7E154AECAF977 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_it-it_af819edf95d3f553\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2009/10/06 07:06:36 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_523cdab8f40fe558\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
[2009/10/06 06:53:03 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_51c00e6ddae85c4b\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/01/11 21:08:35 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=D871BB5958AEF9F493B330FCB533DE6B – C:\Windows\it-IT\explorer.exe.mui
[2010/01/11 21:08:35 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=D871BB5958AEF9F493B330FCB533DE6B – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_it-it_9273a66a9f204dea\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2012/12/29 11:08:51 | 000,031,898 | —- | M] () MD5=60A15EC89644ED2D65A4E8BDAB784D36 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: EXPLORER.GIF >
[2002/08/24 16:39:32 | 000,000,144 | —- | M] () MD5=C6F37D67EA0A5C873F4A9DE08913E4AD – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\postnuke\pn-0.7.2.1_Phoenix\html\modules\Stats\images\explorer.gif

< MD5 for: IEXPLORE.EXE >
[2010/09/08 05:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_b3c5cc459f4108f2\iexplore.exe
[2009/07/14 02:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2010/11/04 06:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_b3987f3a85deec23\iexplore.exe
[2010/09/08 05:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_b34dce2a8616cbea\iexplore.exe
[2010/11/04 06:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_b402ac8b9f13f917\iexplore.exe
[2010/12/18 06:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_b3e23cc79f2c4cea\iexplore.exe
[2010/12/18 06:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_b384dff685ed56b3\iexplore.exe
[2011/02/24 06:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Program Files\Internet Explorer\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2010/01/11 21:08:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=25762CE531381E3240DF74F039B5744F – C:\Program Files\Internet Explorer\it-IT\iexplore.exe.mui
[2010/01/11 21:08:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=25762CE531381E3240DF74F039B5744F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_it-it_399e585587f3842e\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2012/12/28 20:48:28 | 000,143,348 | —- | M] () MD5=2F98EDD136C1286396B06C3736AD9624 – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf

< MD5 for: SERVICES >
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.EXE >
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/01/11 21:08:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=A655D2AC28162C1EB0080B2DC7B7ABC4 – C:\Windows\System32\it-IT\services.exe.mui
[2010/01/11 21:08:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=A655D2AC28162C1EB0080B2DC7B7ABC4 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_it-it_f67e66645173b0b7\services.exe.mui

< MD5 for: SERVICES.GIF >
[2002/10/06 19:00:53 | 000,001,497 | —- | M] () MD5=7735A8919EB725BEE2C1F5412AEB1CBE – C:\Users\utente\Documents\Documents\INGEGNERIA\Progetti\dedicated\aaa Cpanel Dedicated web hosting, website host, server, Atjeu LLC_file\services.gif
[2002/06/16 11:38:56 | 000,000,525 | —- | M] () MD5=9AC87980AFE072913590D88B7B471820 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\images\services.gif
[2002/09/30 18:34:20 | 000,000,255 | —- | M] () MD5=C80515821C9CB1F4DCEA089CE3A0AF6F – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\status2final\images\services.gif

< MD5 for: SERVICES.INC >
[2002/06/15 17:07:00 | 000,000,358 | —- | M] () MD5=8762E7C17EBF73171BBBC23C79A45235 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\templates\services.inc

< MD5 for: SERVICES.LNK >
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2010/01/11 21:08:32 | 000,092,755 | —- | M] () MD5=1452B2812DA789ABB1998CB07F97524A – C:\Windows\System32\it-IT\services.msc
[2010/01/11 21:08:32 | 000,092,755 | —- | M] () MD5=1452B2812DA789ABB1998CB07F97524A – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_it-it_30c0365027dd4aaa\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PNG >
[2008/03/27 04:57:28 | 000,003,334 | —- | M] () MD5=5FF3A00670DE8D80ADA4BD034B55D154 – C:\Program Files\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Red\services.png
[2008/03/27 04:38:18 | 000,003,827 | —- | M] () MD5=BFC0958B73C61EE6C5EEA8D8C6073D26 – C:\Program Files\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Blue\services.png

< MD5 for: SERVICES.PTXML >
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: SERVICES.RDB >
[2012/04/19 07:43:10 | 000,178,348 | —- | M] () MD5=039C8CFBD74EE07F38CD9E4C7D95C5C6 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2012/04/19 07:43:10 | 000,000,453 | —- | M] () MD5=3D2ADA15FEF5B5FF468243161543D610 – C:\Program Files\OpenOffice.org 3\program\services.rdb
[2012/04/13 05:55:44 | 000,008,060 | —- | M] () MD5=7CA7D7150EC46321162F932ADCF5F35B – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb

< MD5 for: SERVICES.TXT >
[2002/06/16 19:14:16 | 000,000,033 | —- | M] () Unable to obtain MD5 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\data\services.txt

< MD5 for: WINLOGON.ADML >
[2010/01/11 21:08:55 | 000,009,430 | —- | M] () MD5=7A3DF5FA7925B53A60E9B3A0764A296B – C:\Windows\PolicyDefinitions\it-IT\WinLogon.adml
[2010/01/11 21:08:55 | 000,009,430 | —- | M] () MD5=7A3DF5FA7925B53A60E9B3A0764A296B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_it-it_218530d508607cbf\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/10/28 07:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\System32\winlogon.exe
[2009/10/28 07:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 06:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/01/11 21:08:32 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=10F25BD9440B0451952225BCAAB284E2 – C:\Windows\System32\it-IT\winlogon.exe.mui
[2010/01/11 21:08:32 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=10F25BD9440B0451952225BCAAB284E2 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_it-it_5779b0d82f94f530\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/01/11 21:08:33 | 000,001,080 | —- | M] () MD5=B5CE50ECD88A87597DE1E8DE71AC2ADF – C:\Windows\System32\wbem\it-IT\winlogon.mfl
[2010/01/11 21:08:33 | 000,001,080 | —- | M] () MD5=B5CE50ECD88A87597DE1E8DE71AC2ADF – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_it-it_b53c02a34acd4ec5\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012/12/28 23:48:02 | 000,013,690 | —- | M] () – C:\AdwCleaner[S1].txt
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2012/12/21 09:00:05 | 000,000,000 | —- | M] () – C:\ctapi_out_gr.txt
[2008/04/11 09:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 09:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 09:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 09:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 09:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 09:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 09:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 09:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 09:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 09:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2009/03/02 22:47:38 | 000,049,233 | —- | M] () – C:\fat32format.exe
[2008/04/11 09:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/12/29 11:00:33 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 07:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 09:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 07:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 07:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 07:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 07:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 07:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 07:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 07:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 09:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 07:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 07:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/12/29 11:00:39 | 3183,755,264 | -HS- | M] () – C:\pagefile.sys
[2010/04/15 10:20:33 | 000,982,458 | —- | M] () – C:\Setup Log 2010-04-15 #001.txt
[2012/12/28 11:50:07 | 000,147,038 | —- | M] () – C:\TDSSKiller.2.8.15.0_28.12.2012_11.49.07_log.txt
[2012/02/08 16:06:27 | 000,065,745 | —- | M] () – C:\testFindSector.log
[2009/10/19 23:43:50 | 000,047,104 | —- | M] () – C:\Thumbs.db
[2008/04/11 09:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 09:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 09:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | -H– | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/17 04:23:20 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\windows\system32\spool\prtprocs\w32x86\DELR1pc.dll
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/14 18:36:17 | 000,000,221 | -HS- | M] () – C:\Users\utente\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/12/28 22:22:56 | 000,550,017 | —- | M] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 21:59:21 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:FB1B13D8

< End of report >
Hi,

With Chrome the fastest and easiest way to fix that is usually a fresh install of Chrome. Give that a shot and let me know how it works for you along with the fix below….


Run OTL.exe
  • Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL


    :Services

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://btsearch.name
    IE - HKCU\..\URLSearchHook: {031afb00-725a-4ede-9d27-a2b5fac89e9a} - C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll (HotSummerWind Software)
    IE - HKCU\..\SearchScopes,DefaultScope = {8d492f70-ea37-453e-a0e4-9d709483a4cd}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKCU\..\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}: "URL" = http://btsearch.name/results.php?q={searchTerms}

    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

Post the new OTL log and also be sure to get a fresh install of Google Chrome. Let me know how your system is running. :)
This is the result of RunFix

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{031afb00-725a-4ede-9d27-a2b5fac89e9a} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031afb00-725a-4ede-9d27-a2b5fac89e9a}\ deleted successfully.
C:\PROGRA~1\YOUTUB~1\YouTube Downloader.dll moved successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8d492f70-ea37-453e-a0e4-9d709483a4cd}\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: utente
->Temp folder emptied: 19871867 bytes
->Temporary Internet Files folder emptied: 67977 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 6903007 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 53116 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 26,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 12302012_105105

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…




And this is the RunScan log file


OTL logfile created on: 12/30/2012 11:10:43 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\utente\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 46.14% Memory free
5.93 Gb Paging File | 4.20 Gb Available in Paging File | 70.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 186.60 Gb Free Space | 41.61% Space Free | Partition Type: NTFS
Drive E: | 1.99 Gb Total Space | 1.76 Gb Free Space | 88.37% Space Free | Partition Type: FAT32

Computer Name: PC | User Name: utente | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\utente\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe (Anvisoft)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerSrv.exe ()
PRC - C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()
PRC - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\EPSON Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\EPSON Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
PRC - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\Eraser\Eraser.exe (The Eraser Project)
PRC - C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\sqlite3.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtGui4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtNetwork4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtScript4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtSql4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtDeclarative4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtCore4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\dblite.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qgif4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dda6d8c7413334b605fcf590a702e9f1\Microsoft.VisualBasic.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\bf0286e181064f9ded08895c7f23967d\System.Core.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\94eb4ca06f43edf88bbdecd3729657d5\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b6d66d3c48e430796c17d0497ce37972\System.ServiceProcess.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c519a7e1b063eb63b43fa5b3a782c641\System.Design.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\b867fbc0d573ac5e5fe71143d9caf43b\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\adc8998d96ca331d17cef00b1ef95a5f\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4be7719ea0e1f2ba2d3fde051d1ef7ab\System.Transactions.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\b9565c454a22ca564978b05db4186f22\System.Data.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7827588b8043e8be3184c8a64a867fc\PresentationFramework.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e4ea95056046fdf87f06ae807308b627\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2a34e74599686e7383ae90670a994cdf\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\11ebcba65c931267301739008a883e60\Accessibility.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\03dd2b7701ca5cfe696d4ca5a0f7b8bb\PresentationCore.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\caa9d8bca3092573cdbb67c8e81bf0f3\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\395fc7d9f333940351a74aaab5d6ae99\System.Security.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\167c8c3817ba1f48fe7396cc56f557e3\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9d054fc9618b81d5703af1662cd11135\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\50c67f851ae3df2d0ab7d86fd1c5c7e0\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ebdaeaeb9f66c9035b5f11431f10cda4\mscorlib.ni.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\ScanModule.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMScnSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMDB_N.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMCommon.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMISM.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMTree.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMImageSplitter.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMView.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSave.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMPageVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMImgVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMINSO.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\OutlookVBA.dll ()
MOD - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\Vodafone.View.Taskbar.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMPDFView.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\SlideBarDLL.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMOffice.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMProp.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PerformOcr.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMStatus.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3503.18374__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3503.18350__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3503.18376__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3503.18369__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3503.18360__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3503.18471__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3503.18426__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3503.18471__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3503.18427__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3503.18446__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3503.18360__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3503.18419__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3503.18426__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3503.18472__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3503.18470__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3503.18406__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3503.18409__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3503.18377__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3503.18439__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3503.18363__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3503.18376__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3503.18415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3503.18408__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3503.18382__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3503.18415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3503.18407__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3503.18402__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3503.18417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3503.18383__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3503.18407__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3503.18408__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3503.18417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3428.28302__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3428.28329__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3428.28305__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3428.28298__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3428.28324__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3428.28296__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3428.28297__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3428.28354__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3428.28304__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3428.28302__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3428.28310__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3428.28324__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3428.28303__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3428.28316__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3428.28309__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3428.28323__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3428.28311__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Foundation\2.0.3428.28310__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3503.18465__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3503.18463__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3503.18478__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3428.28301__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3428.28310__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3503.18344__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3503.18356__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3503.18368__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3503.18348__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3503.18347__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3428.28309__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3428.28316__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Server\2.0.3503.18346__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server\2.0.3503.18345__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3503.18464__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMDocVW.dll ()
MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_it_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMAnoSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMAppBar.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\NetFun2k.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMANO.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\FT.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll ()
MOD - C:\Windows\System32\msjetoledb40.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMApSet.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\nsSign.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PHooKDlg.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMIEVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMVoice.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMENC.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMAESLib.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\MCharSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\Qem.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\NsOEMKey.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\Import.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\ComClass.dll ()
MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\sqlite3.dll ()


========== Services (SafeList) ==========

SRV - (asdsrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe (Anvisoft)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (ADBlockerSrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerSrv.exe ()
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
SRV - (EpsonCustomerResearchParticipation) – C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (VmbService) – C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (CSObjectsSrv) – C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (yksvc) – C:\Windows\System32\yk62x86.dll (Marvell)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (RoxMediaDB10) – c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (AEADIFilters) – C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV - (RkHit) – C:\windows\system32\drivers\RKHit.sys File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (asdrs) – C:\Windows\System32\drivers\asdrs.sys (Anvisoft)
DRV - (asdws) – C:\Windows\System32\drivers\asdws.sys ()
DRV - (asdrm) – C:\Windows\System32\drivers\asdrm.sys (Anvisoft)
DRV - (taphss6) – C:\Windows\System32\drivers\taphss6.sys (Anchorfree Inc.)
DRV - (HssDRV6) – C:\Windows\System32\drivers\hssdrv6.sys (AnchorFree Inc.)
DRV - (KLIF) – C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (asdnet) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\sys\x86\asdnet.sys ()
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (KLIM6) – C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV - (vodafone_K3805-z_cdc_ecm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) – C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) – C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (FsUsbExDisk) – C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NETw5s32) – C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (CSCrySec) – C:\Windows\System32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) – C:\Windows\System32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (klmouflt) – C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (netw5v32) – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (hpdskflt) – C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard)
DRV - (Accelerometer) – C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard)
DRV - (5U876UVC) – C:\Windows\System32\drivers\5U876.sys (Ricoh co.,Ltd.)
DRV - (mfetdik) – C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pfc) – C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://btsearch.name
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope = {8d492f70-ea37-453e-a0e4-9d709483a4cd}
IE - HKCU\..\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}: "URL" = http://btsearch.name/results.php?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]

[2012/09/17 15:23:28 | 000,000,000 | —D | M] (No name found) – C:\Users\utente\AppData\Roaming\mozilla\Extensions

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Custom search (Enabled)
CHR - default_search_provider: search_url = http://btsearch.name/results.php?q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\utente\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Orbit Downloader (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Flickr\u2122 Downloader = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebkkoejhhdbbohdhikahjanhbiegfhmi\3.0.0.0_0\
CHR - Extension: Qtube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhakcmpgccbfnmamojhjhaflhnfdooaa\1.11_0\
CHR - Extension: Gmail = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/12/29 10:59:21 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - No CLSID value found.
O4 - HKLM..\Run: [ADBlocker] C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
O4 - HKLM..\Run: [Anvi Smart Defender] C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" –atRestart File not found
O4 - HKLM..\Run: [FUFAXRCV] C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [PMSpeed] C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE (NewSoft Technology Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
O4 - HKLM..\Run: [YouTube Downloader_Helper] C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()
O4 - HKCU..\Run: [EPSON WF-7515 Series] C:\windows\System32\spool\DRIVERS\W32X86\3\E_TATIHCE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe (Sonic Solutions)
O4 - Startup: C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 100
O8 - Extra context menu item: Aggiungi ad Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{65C17FEC-4D94-4AF8-917D-6111DA444667}: NameServer = 83.224.70.93 83.224.66.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{98ECAE4D-7803-485D-B168-2FF52E90694F}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC3BBE37-C7E4-4597-9FD9-51FEBDCB221B}: NameServer = 8.8.8.8,8.8.8.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.24
7.20,156.154.70.1,156.154.71.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF42F48F-3663-45FD-8BB4-4F3844DC57A5}: DhcpNameServer = 8.8.8.8
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/12/28 19:00:12 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv50 - C:\windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/29 10:58:33 | 000,000,000 | —D | C] – C:\_OTL
[2012/12/29 10:57:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/12/29 10:57:17 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/12/28 21:58:23 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/28 19:47:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:46:20 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\whatthetech
[2012/12/28 19:26:23 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Anvisoft
[2012/12/28 19:25:19 | 000,022,864 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrs.sys
[2012/12/28 19:25:19 | 000,016,208 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrm.sys
[2012/12/28 19:24:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft
[2012/12/28 19:24:52 | 000,000,000 | —D | C] – C:\ProgramData\Anvisoft
[2012/12/28 19:24:48 | 000,000,000 | —D | C] – C:\Program Files\Anvisoft
[2012/12/28 18:59:27 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/12/28 18:58:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/12/28 15:32:02 | 000,000,000 | —D | C] – C:\ProgramData\XoftSpySE
[2012/12/28 11:51:08 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Malwarebytes
[2012/12/28 11:50:44 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/12/28 11:50:30 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Local\Programs
[2012/12/28 10:52:26 | 000,000,000 | —D | C] – C:\Program Files\YouTube Downloader
[2012/12/28 10:51:31 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\november rain
[2012/12/28 10:05:10 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\SENE
[2012/12/19 22:59:34 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\Nuova cartella (2)
[2012/12/19 10:51:52 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\murrina
[2012/12/06 12:40:37 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\paypal
[2012/12/05 23:02:32 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\bedandcinema.com
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\Program Files\ColorDetector200
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Color Detector 2.0
[2012/12/04 11:57:04 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\BedAndCinema

========== Files - Modified Within 30 Days ==========

[2012/12/30 11:14:45 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/30 11:14:45 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/30 11:10:06 | 000,000,978 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/12/30 11:06:39 | 000,001,134 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/30 11:05:58 | 000,065,536 | —- | M] () – C:\windows\System32\Ikeext.etl
[2012/12/30 11:05:46 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/12/30 11:05:39 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2012/12/30 10:54:00 | 000,001,164 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001UA.job
[2012/12/30 10:50:01 | 000,001,138 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/29 17:56:15 | 000,000,436 | —- | M] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/29 13:18:32 | 000,001,112 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001Core.job
[2012/12/29 10:59:21 | 000,000,098 | —- | M] () – C:\windows\System32\drivers\etc\Hosts
[2012/12/29 10:57:28 | 000,001,074 | —- | M] () – C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/12/29 10:57:18 | 000,000,894 | —- | M] () – C:\Users\utente\Desktop\NTREGOPT.lnk
[2012/12/29 10:57:18 | 000,000,875 | —- | M] () – C:\Users\utente\Desktop\ERUNT.lnk
[2012/12/28 23:44:24 | 000,000,512 | —- | M] () – C:\Users\utente\Desktop\MBR.dat
[2012/12/28 22:22:56 | 000,550,017 | —- | M] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 21:59:21 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:25:19 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | M] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/12/28 16:02:32 | 000,698,570 | —- | M] () – C:\windows\System32\perfh010.dat
[2012/12/28 16:02:32 | 000,616,008 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/12/28 16:02:32 | 000,127,764 | —- | M] () – C:\windows\System32\perfc010.dat
[2012/12/28 16:02:32 | 000,106,388 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2012/12/18 16:53:03 | 003,115,570 | —- | M] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/17 12:34:42 | 000,000,326 | —- | M] () – C:\windows\tasks\HPCeeScheduleForutente.job
[2012/12/16 22:15:14 | 000,000,218 | —- | M] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:47 | 000,271,046 | —- | M] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/12 20:11:29 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2012/12/12 20:11:29 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2012/12/10 09:48:08 | 000,470,393 | —- | M] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:28 | 001,040,996 | —- | M] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:29 | 000,612,798 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:11 | 000,219,495 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | M] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/03 11:38:02 | 000,001,363 | —- | M] () – C:\Users\utente\Desktop\Internet Explorer (No Add-ons).lnk
[2012/12/01 23:29:29 | 001,088,880 | —- | M] () – C:\Users\utente\Desktop\telecomando258.jpg

========== Files Created - No Company Name ==========

[2012/12/29 10:57:28 | 000,001,074 | —- | C] () – C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/12/29 10:57:18 | 000,000,894 | —- | C] () – C:\Users\utente\Desktop\NTREGOPT.lnk
[2012/12/29 10:57:18 | 000,000,875 | —- | C] () – C:\Users\utente\Desktop\ERUNT.lnk
[2012/12/28 23:46:54 | 000,550,017 | —- | C] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 23:44:24 | 000,000,512 | —- | C] () – C:\Users\utente\Desktop\MBR.dat
[2012/12/28 19:25:19 | 000,014,160 | —- | C] () – C:\windows\System32\drivers\asdws.sys
[2012/12/28 19:25:19 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | C] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:00:12 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2012/12/28 15:53:02 | 000,000,436 | —- | C] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\mozilla.cfg
[2012/12/18 16:52:55 | 003,115,570 | —- | C] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/16 22:15:14 | 000,000,218 | —- | C] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:43 | 000,271,046 | —- | C] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/10 09:48:08 | 000,470,393 | —- | C] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:26 | 001,040,996 | —- | C] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:28 | 000,612,798 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:10 | 000,219,495 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | C] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/06 12:04:15 | 000,634,564 | —- | C] () – C:\Users\utente\Desktop\5 carta identità codice fiscale.pdf
[2012/12/01 23:29:29 | 001,088,880 | —- | C] () – C:\Users\utente\Desktop\telecomando258.jpg
[2012/09/01 10:32:47 | 000,000,030 | —- | C] () – C:\windows\iedit_.INI
[2012/05/17 11:00:28 | 000,116,189 | —- | C] () – C:\windows\System32\drivers\klin.dat
[2012/05/17 11:00:28 | 000,098,168 | —- | C] () – C:\windows\System32\drivers\klick.dat
[2012/04/18 10:33:44 | 000,017,408 | —- | C] () – C:\Users\utente\AppData\Local\WebpageIcons.db
[2012/02/08 16:26:32 | 000,258,348 | —- | C] () – C:\Users\utente\AppData\Local\rx_image32.Cache
[2011/12/03 17:00:13 | 000,000,827 | —- | C] () – C:\windows\Brpfx04a.ini
[2011/12/03 17:00:13 | 000,000,161 | —- | C] () – C:\windows\brpcfx.ini
[2011/12/03 16:58:32 | 000,106,496 | —- | C] () – C:\windows\System32\BrMuSNMP.dll
[2011/12/03 16:52:17 | 000,000,420 | —- | C] () – C:\windows\BRWMARK.INI
[2011/12/03 16:52:17 | 000,000,065 | —- | C] () – C:\windows\System32\BD7820N.DAT
[2011/08/31 21:11:40 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2011/03/11 11:43:54 | 000,029,763 | —- | C] () – C:\windows\System32\drivers\klopp.dat
[2010/11/23 00:27:55 | 000,000,600 | —- | C] () – C:\Users\utente\AppData\Roaming\winscp.rnd
[2010/09/08 10:07:40 | 000,159,464 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4

========== ZeroAccess Check ==========

[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2010/07/27 15:03:24 | 012,867,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/14 02:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/01/11 21:08:57 | 000,004,183 | —- | M] () MD5=4CF10EA9BAB7750F41A7E154AECAF977 – C:\Windows\PolicyDefinitions\it-IT\Explorer.adml
[2010/01/11 21:08:57 | 000,004,183 | —- | M] () MD5=4CF10EA9BAB7750F41A7E154AECAF977 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_it-it_af819edf95d3f553\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2009/10/06 07:06:36 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_523cdab8f40fe558\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
[2009/10/06 06:53:03 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_51c00e6ddae85c4b\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/01/11 21:08:35 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=D871BB5958AEF9F493B330FCB533DE6B – C:\Windows\it-IT\explorer.exe.mui
[2010/01/11 21:08:35 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=D871BB5958AEF9F493B330FCB533DE6B – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_it-it_9273a66a9f204dea\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2012/12/29 11:08:51 | 000,031,898 | —- | M] () MD5=60A15EC89644ED2D65A4E8BDAB784D36 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: EXPLORER.GIF >
[2002/08/24 16:39:32 | 000,000,144 | —- | M] () MD5=C6F37D67EA0A5C873F4A9DE08913E4AD – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\postnuke\pn-0.7.2.1_Phoenix\html\modules\Stats\images\explorer.gif

< MD5 for: IEXPLORE.EXE >
[2010/09/08 05:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_b3c5cc459f4108f2\iexplore.exe
[2009/07/14 02:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2010/11/04 06:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_b3987f3a85deec23\iexplore.exe
[2010/09/08 05:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_b34dce2a8616cbea\iexplore.exe
[2010/11/04 06:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_b402ac8b9f13f917\iexplore.exe
[2010/12/18 06:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_b3e23cc79f2c4cea\iexplore.exe
[2010/12/18 06:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_b384dff685ed56b3\iexplore.exe
[2011/02/24 06:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Program Files\Internet Explorer\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2010/01/11 21:08:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=25762CE531381E3240DF74F039B5744F – C:\Program Files\Internet Explorer\it-IT\iexplore.exe.mui
[2010/01/11 21:08:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=25762CE531381E3240DF74F039B5744F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_it-it_399e585587f3842e\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2012/12/28 20:48:28 | 000,143,348 | —- | M] () MD5=2F98EDD136C1286396B06C3736AD9624 – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf

< MD5 for: SERVICES >
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.EXE >
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/01/11 21:08:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=A655D2AC28162C1EB0080B2DC7B7ABC4 – C:\Windows\System32\it-IT\services.exe.mui
[2010/01/11 21:08:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=A655D2AC28162C1EB0080B2DC7B7ABC4 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_it-it_f67e66645173b0b7\services.exe.mui

< MD5 for: SERVICES.GIF >
[2002/10/06 19:00:53 | 000,001,497 | —- | M] () MD5=7735A8919EB725BEE2C1F5412AEB1CBE – C:\Users\utente\Documents\Documents\INGEGNERIA\Progetti\dedicated\aaa Cpanel Dedicated web hosting, website host, server, Atjeu LLC_file\services.gif
[2002/06/16 11:38:56 | 000,000,525 | —- | M] () MD5=9AC87980AFE072913590D88B7B471820 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\images\services.gif
[2002/09/30 18:34:20 | 000,000,255 | —- | M] () MD5=C80515821C9CB1F4DCEA089CE3A0AF6F – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\status2final\images\services.gif

< MD5 for: SERVICES.INC >
[2002/06/15 17:07:00 | 000,000,358 | —- | M] () MD5=8762E7C17EBF73171BBBC23C79A45235 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\templates\services.inc

< MD5 for: SERVICES.LNK >
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2010/01/11 21:08:32 | 000,092,755 | —- | M] () MD5=1452B2812DA789ABB1998CB07F97524A – C:\Windows\System32\it-IT\services.msc
[2010/01/11 21:08:32 | 000,092,755 | —- | M] () MD5=1452B2812DA789ABB1998CB07F97524A – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_it-it_30c0365027dd4aaa\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PNG >
[2008/03/27 04:57:28 | 000,003,334 | —- | M] () MD5=5FF3A00670DE8D80ADA4BD034B55D154 – C:\Program Files\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Red\services.png
[2008/03/27 04:38:18 | 000,003,827 | —- | M] () MD5=BFC0958B73C61EE6C5EEA8D8C6073D26 – C:\Program Files\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Blue\services.png

< MD5 for: SERVICES.PTXML >
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: SERVICES.RDB >
[2012/04/19 07:43:10 | 000,178,348 | —- | M] () MD5=039C8CFBD74EE07F38CD9E4C7D95C5C6 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2012/04/19 07:43:10 | 000,000,453 | —- | M] () MD5=3D2ADA15FEF5B5FF468243161543D610 – C:\Program Files\OpenOffice.org 3\program\services.rdb
[2012/04/13 05:55:44 | 000,008,060 | —- | M] () MD5=7CA7D7150EC46321162F932ADCF5F35B – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb

< MD5 for: SERVICES.TXT >
[2002/06/16 19:14:16 | 000,000,033 | —- | M] () MD5=5DFABC09BF8025F4EAE9ADD8B1EE9466 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\data\services.txt

< MD5 for: WINLOGON.ADML >
[2010/01/11 21:08:55 | 000,009,430 | —- | M] () MD5=7A3DF5FA7925B53A60E9B3A0764A296B – C:\Windows\PolicyDefinitions\it-IT\WinLogon.adml
[2010/01/11 21:08:55 | 000,009,430 | —- | M] () MD5=7A3DF5FA7925B53A60E9B3A0764A296B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_it-it_218530d508607cbf\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/10/28 07:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\System32\winlogon.exe
[2009/10/28 07:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 06:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/01/11 21:08:32 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=10F25BD9440B0451952225BCAAB284E2 – C:\Windows\System32\it-IT\winlogon.exe.mui
[2010/01/11 21:08:32 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=10F25BD9440B0451952225BCAAB284E2 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_it-it_5779b0d82f94f530\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/01/11 21:08:33 | 000,001,080 | —- | M] () MD5=B5CE50ECD88A87597DE1E8DE71AC2ADF – C:\Windows\System32\wbem\it-IT\winlogon.mfl
[2010/01/11 21:08:33 | 000,001,080 | —- | M] () MD5=B5CE50ECD88A87597DE1E8DE71AC2ADF – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_it-it_b53c02a34acd4ec5\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012/12/28 23:48:02 | 000,013,690 | —- | M] () – C:\AdwCleaner[S1].txt
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2012/12/21 09:00:05 | 000,000,000 | —- | M] () – C:\ctapi_out_gr.txt
[2008/04/11 09:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 09:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 09:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 09:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 09:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 09:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 09:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 09:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 09:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 09:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2009/03/02 22:47:38 | 000,049,233 | —- | M] () – C:\fat32format.exe
[2008/04/11 09:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/12/30 11:05:39 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 07:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 09:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 07:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 07:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 07:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 07:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 07:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 07:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 07:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 09:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 07:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 07:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/12/30 11:05:44 | 3183,755,264 | -HS- | M] () – C:\pagefile.sys
[2010/04/15 10:20:33 | 000,982,458 | —- | M] () – C:\Setup Log 2010-04-15 #001.txt
[2012/12/28 11:50:07 | 000,147,038 | —- | M] () – C:\TDSSKiller.2.8.15.0_28.12.2012_11.49.07_log.txt
[2012/02/08 16:06:27 | 000,065,745 | —- | M] () – C:\testFindSector.log
[2009/10/19 23:43:50 | 000,047,104 | —- | M] () – C:\Thumbs.db
[2008/04/11 09:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 09:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 09:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | -H– | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/17 04:23:20 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\windows\system32\spool\prtprocs\w32x86\DELR1pc.dll
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/14 18:36:17 | 000,000,221 | -HS- | M] () – C:\Users\utente\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/12/28 22:22:56 | 000,550,017 | —- | M] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 21:59:21 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:FB1B13D8

< End of report >



Besides:

:( I opened Chrome and I still get the start page as btserarch.name but now is forwarding to another page avg.name
To make a comparison I opened Internet explorer browser and I'm getting the same

Besides in task manager I still find a YouTube Downloader_Helper.exe :angry: that I suppose the it's the spyware. Perhaps we should be able to delete this one before a fresh install of chrome.

Again: I'm very worried but really I'd like to thank you for the time you are dedicating to my problem.
Hi,

Let's keep digging. Sometimes malware removal can take some time and different tools.

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.3.2 (12.29.2012:3)
OS: Windows 7 Professional x86
Ran by [removed] on 30/12/2012 at 18:32:31,07
Blog: http://thisisudax.blogspot.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-868304899-771622945-1420894305-1001\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-868304899-771622945-1420894305-1001\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\abouturls\\Tabs



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478d38-c3f9-4efb-9b51-7695eca05670}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}



~~~ Files

Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.1049.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.1049.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30/12/2012 at 18:43:47,76
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
For Your info: I changed the start page from btsearch.name to www.google.it and the search engines in chrome settings and for the first time they have not been modified to btsearch.name. The same I tried with Internet Explorer. :lol: I rebooted and in the task manager I keep on having that you tube downloader helper :angry:
Hi,

Let's keep going…we have some entries wanting to stick around….

Run OTL.exe
  • Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL


    :Services

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://btsearch.name
    IE - HKCU\..\SearchScopes,DefaultScope = {8d492f70-ea37-453e-a0e4-9d709483a4cd}
    IE - HKCU\..\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}: "URL" = http://btsearch.name/results.php?q={searchTerms}
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {031afb00-725a-4ede-9d27-a2b5fac89e9a} - No CLSID value found.
    O4 - HKLM..\Run: [YouTube Downloader_Helper] C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe ()

    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

Post the new OTL log and let me know how things are running now. :)
this the runfix log All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8d492f70-ea37-453e-a0e4-9d709483a4cd}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8d492f70-ea37-453e-a0e4-9d709483a4cd}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{031afb00-725a-4ede-9d27-a2b5fac89e9a}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031afb00-725a-4ede-9d27-a2b5fac89e9a}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{031afb00-725a-4ede-9d27-a2b5fac89e9a} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031afb00-725a-4ede-9d27-a2b5fac89e9a}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\YouTube Downloader_Helper deleted successfully. C:\Program Files\YouTube Downloader\YouTube Downloader_Helper.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: utente ->Temp folder emptied: 428003 bytes ->Temporary Internet Files folder emptied: 526702 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 347902417 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 57432 bytes RecycleBin emptied: 170594 bytes Total Files Cleaned = 333.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 12312012_111741 Files\Folders moved on Reboot… C:\Users\utente\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\utente\AppData\Local\Temp\tmp2874.tmp not found! File\Folder C:\Users\utente\AppData\Local\Temp\tmp299D.tmp not found! File\Folder C:\Users\utente\AppData\Local\Temp\tmp3754.tmp not found! File\Folder C:\Users\utente\AppData\Local\Temp\tmp38DB.tmp not found! File\Folder C:\Users\utente\AppData\Local\Temp\tmp3988.tmp not found! File\Folder C:\Users\utente\AppData\Local\Temp\tmp7D06.tmp not found! File\Folder C:\Users\utente\AppData\Local\Temp\tmp8EB3.tmp not found! File\Folder C:\Users\utente\AppData\Local\Temp\tmpC9DF.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{54A215C2-AE0E-49D5-B2E5-8ACDA101C0FE}.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{0CFDB711-5F84-4106-89FB-85C16D3B3ECD}.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{42FD76F5-B4D7-4878-8905-4ED423A785A1}.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{52BAA85C-AB5A-4DBA-9EDF-988C37B5AA66}.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7D4001C6-8F3C-40C2-A489-DAA86E866CD1}.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7EAAFF69-ADA0-4A90-B9EC-E2E335F6D571}.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{CD73E860-9872-4CBB-A95D-2DEDD204ED97}.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{EE3B72AC-CF9F-4834-892A-29E73F0EBC92}.tmp not found! File\Folder C:\Users\utente\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{F436A55A-4014-42E3-B9E8-85FBF43CB919}.tmp not found! PendingFileRenameOperations files… Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI