This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

chrome start page and search: btsearch.name [Solved]

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL Log

OTL logfile created on: 12/31/2012 11:26:21 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\utente\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

2.97 Gb Total Physical Memory | 1.32 Gb Available Physical Memory | 44.36% Memory free
5.93 Gb Paging File | 4.11 Gb Available in Paging File | 69.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 185.56 Gb Free Space | 41.38% Space Free | Partition Type: NTFS
Drive E: | 1.99 Gb Total Space | 1.76 Gb Free Space | 88.37% Space Free | Partition Type: FAT32

Computer Name: PC | User Name: utente | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\utente\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe (Anvisoft)
PRC - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerSrv.exe ()
PRC - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\EPSON Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\EPSON Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
PRC - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\Eraser\Eraser.exe (The Eraser Project)
PRC - C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\sqlite3.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll ()
MOD - C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtGui4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtNetwork4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtScript4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtSql4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtDeclarative4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtCore4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\dblite.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qgif4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dda6d8c7413334b605fcf590a702e9f1\Microsoft.VisualBasic.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\bf0286e181064f9ded08895c7f23967d\System.Core.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\94eb4ca06f43edf88bbdecd3729657d5\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b6d66d3c48e430796c17d0497ce37972\System.ServiceProcess.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c519a7e1b063eb63b43fa5b3a782c641\System.Design.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\b867fbc0d573ac5e5fe71143d9caf43b\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\adc8998d96ca331d17cef00b1ef95a5f\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4be7719ea0e1f2ba2d3fde051d1ef7ab\System.Transactions.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\b9565c454a22ca564978b05db4186f22\System.Data.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7827588b8043e8be3184c8a64a867fc\PresentationFramework.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e4ea95056046fdf87f06ae807308b627\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2a34e74599686e7383ae90670a994cdf\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\11ebcba65c931267301739008a883e60\Accessibility.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\03dd2b7701ca5cfe696d4ca5a0f7b8bb\PresentationCore.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\caa9d8bca3092573cdbb67c8e81bf0f3\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\395fc7d9f333940351a74aaab5d6ae99\System.Security.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\167c8c3817ba1f48fe7396cc56f557e3\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9d054fc9618b81d5703af1662cd11135\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\50c67f851ae3df2d0ab7d86fd1c5c7e0\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ebdaeaeb9f66c9035b5f11431f10cda4\mscorlib.ni.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\ScanModule.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMScnSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMDB_N.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMCommon.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMISM.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMTree.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMImageSplitter.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMView.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSave.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMPageVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMImgVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMINSO.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\OutlookVBA.dll ()
MOD - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\Vodafone.View.Taskbar.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMPDFView.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\SlideBarDLL.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMOffice.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMProp.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PerformOcr.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMStatus.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3503.18374__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3503.18350__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3503.18376__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3503.18369__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3503.18360__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3503.18471__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3503.18426__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3503.18471__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3503.18427__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3503.18446__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3503.18360__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3503.18419__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3503.18426__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3503.18472__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3503.18470__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3503.18406__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3503.18409__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3503.18377__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3503.18439__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3503.18363__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3503.18376__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3503.18415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3503.18408__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3503.18382__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3503.18415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3503.18407__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3503.18402__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3503.18417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3503.18383__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3503.18407__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3503.18408__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3503.18417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3428.28302__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3428.28329__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3428.28305__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3428.28298__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3428.28324__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3428.28296__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3428.28297__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3428.28354__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3428.28304__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3428.28302__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3428.28310__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3428.28324__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3428.28303__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3428.28316__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3428.28309__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3428.28323__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3428.28311__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Foundation\2.0.3428.28310__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3503.18465__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3503.18463__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3503.18478__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3428.28301__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3428.28310__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3503.18344__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3503.18356__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3503.18368__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3503.18348__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3503.18347__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3428.28309__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3428.28316__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Server\2.0.3503.18346__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server\2.0.3503.18345__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3503.18464__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMDocVW.dll ()
MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_it_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMAnoSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMAppBar.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\NetFun2k.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMANO.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\FT.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll ()
MOD - C:\Windows\System32\msjetoledb40.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMApSet.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\nsSign.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PHooKDlg.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMIEVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMVoice.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMENC.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMAESLib.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\MCharSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\Qem.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\NsOEMKey.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\Import.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\ComClass.dll ()
MOD - C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\sqlite3.dll ()


========== Services (SafeList) ==========

SRV - (asdsrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe (Anvisoft)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (ADBlockerSrv) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerSrv.exe ()
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
SRV - (EpsonCustomerResearchParticipation) – C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (VmbService) – C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (CSObjectsSrv) – C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (yksvc) – C:\Windows\System32\yk62x86.dll (Marvell)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (RoxMediaDB10) – c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (AEADIFilters) – C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV - (RkHit) – C:\windows\system32\drivers\RKHit.sys File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (asdrs) – C:\Windows\System32\drivers\asdrs.sys (Anvisoft)
DRV - (asdws) – C:\Windows\System32\drivers\asdws.sys ()
DRV - (asdrm) – C:\Windows\System32\drivers\asdrm.sys (Anvisoft)
DRV - (taphss6) – C:\Windows\System32\drivers\taphss6.sys (Anchorfree Inc.)
DRV - (HssDRV6) – C:\Windows\System32\drivers\hssdrv6.sys (AnchorFree Inc.)
DRV - (KLIF) – C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (asdnet) – C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\sys\x86\asdnet.sys ()
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (KLIM6) – C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV - (vodafone_K3805-z_cdc_ecm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) – C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) – C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (FsUsbExDisk) – C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NETw5s32) – C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (CSCrySec) – C:\Windows\System32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) – C:\Windows\System32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (klmouflt) – C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (netw5v32) – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (hpdskflt) – C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard)
DRV - (Accelerometer) – C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard)
DRV - (5U876UVC) – C:\Windows\System32\drivers\5U876.sys (Ricoh co.,Ltd.)
DRV - (mfetdik) – C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pfc) – C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\utente\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/08/26 13:44:54 | 000,000,000 | —D | M]

[2012/09/17 15:23:28 | 000,000,000 | —D | M] (No name found) – C:\Users\utente\AppData\Roaming\mozilla\Extensions

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\utente\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Orbit Downloader (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Flickr\u2122 Downloader = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebkkoejhhdbbohdhikahjanhbiegfhmi\3.0.0.0_0\
CHR - Extension: Qtube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhakcmpgccbfnmamojhjhaflhnfdooaa\1.11_0\
CHR - Extension: Gmail = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/12/29 10:59:21 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM..\Run: [ADBlocker] C:\Program Files\Anvisoft\Anvi Smart Defender\toolbox\adblocker\ADBlockerTray.exe ()
O4 - HKLM..\Run: [Anvi Smart Defender] C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe (Anvisoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" –atRestart File not found
O4 - HKLM..\Run: [FUFAXRCV] C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [PMSpeed] C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE (NewSoft Technology Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
O4 - HKCU..\Run: [EPSON WF-7515 Series] C:\windows\System32\spool\DRIVERS\W32X86\3\E_TATIHCE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe (Sonic Solutions)
O4 - Startup: C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 100
O8 - Extra context menu item: Aggiungi ad Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{65C17FEC-4D94-4AF8-917D-6111DA444667}: NameServer = 83.224.70.93 83.224.66.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{98ECAE4D-7803-485D-B168-2FF52E90694F}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC3BBE37-C7E4-4597-9FD9-51FEBDCB221B}: NameServer = 8.8.8.8,8.8.8.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.24
7.20,156.154.70.1,156.154.71.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF42F48F-3663-45FD-8BB4-4F3844DC57A5}: DhcpNameServer = 8.8.8.8
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/12/28 19:00:12 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv50 - C:\windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/30 18:32:26 | 000,000,000 | —D | C] – C:\windows\ERUNT
[2012/12/30 18:32:07 | 000,000,000 | —D | C] – C:\JRT
[2012/12/30 18:00:33 | 000,497,009 | —- | C] (Oleg N. Scherbakov) – C:\Users\utente\Desktop\JRT.exe
[2012/12/29 10:58:33 | 000,000,000 | —D | C] – C:\_OTL
[2012/12/29 10:57:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/12/29 10:57:17 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/12/28 21:58:23 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/28 19:47:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:46:20 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\whatthetech
[2012/12/28 19:26:23 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Anvisoft
[2012/12/28 19:25:19 | 000,022,864 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrs.sys
[2012/12/28 19:25:19 | 000,016,208 | —- | C] (Anvisoft) – C:\windows\System32\drivers\asdrm.sys
[2012/12/28 19:24:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft
[2012/12/28 19:24:52 | 000,000,000 | —D | C] – C:\ProgramData\Anvisoft
[2012/12/28 19:24:48 | 000,000,000 | —D | C] – C:\Program Files\Anvisoft
[2012/12/28 18:59:27 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/12/28 18:58:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/12/28 15:32:02 | 000,000,000 | —D | C] – C:\ProgramData\XoftSpySE
[2012/12/28 11:51:08 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Roaming\Malwarebytes
[2012/12/28 11:50:44 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/12/28 11:50:30 | 000,000,000 | —D | C] – C:\Users\utente\AppData\Local\Programs
[2012/12/28 10:52:26 | 000,000,000 | —D | C] – C:\Program Files\YouTube Downloader
[2012/12/28 10:51:31 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\november rain
[2012/12/28 10:05:10 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\SENE
[2012/12/19 22:59:34 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\Nuova cartella (2)
[2012/12/19 10:51:52 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\murrina
[2012/12/06 12:40:37 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\paypal
[2012/12/05 23:02:32 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\bedandcinema.com
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\Program Files\ColorDetector200
[2012/12/04 23:39:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Color Detector 2.0
[2012/12/04 11:57:04 | 000,000,000 | —D | C] – C:\Users\utente\Desktop\BedAndCinema

========== Files - Modified Within 30 Days ==========

[2012/12/31 11:34:06 | 000,001,138 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/31 11:34:06 | 000,001,134 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/31 11:29:44 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/31 11:29:44 | 000,020,944 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/31 11:21:03 | 000,065,536 | —- | M] () – C:\windows\System32\Ikeext.etl
[2012/12/31 11:20:52 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/12/31 11:20:45 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2012/12/31 11:10:00 | 000,000,978 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/12/31 10:54:00 | 000,001,164 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001UA.job
[2012/12/31 10:51:18 | 001,435,522 | —- | M] () – C:\Users\utente\Desktop\Diffida INPS-6600-01-10-2012-0125753 Pagamento F24.jpg
[2012/12/31 10:50:02 | 000,714,449 | —- | M] () – C:\Users\utente\Desktop\Diffida INPS-6600-01-10-2012-0125753 Pagamento F24.pdf
[2012/12/30 20:22:45 | 000,701,426 | —- | M] () – C:\windows\System32\perfh010.dat
[2012/12/30 20:22:45 | 000,618,912 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/12/30 20:22:45 | 000,128,740 | —- | M] () – C:\windows\System32\perfc010.dat
[2012/12/30 20:22:45 | 000,107,232 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/12/30 18:29:59 | 000,497,009 | —- | M] (Oleg N. Scherbakov) – C:\Users\utente\Desktop\JRT.exe
[2012/12/30 17:58:01 | 000,325,312 | —- | M] () – C:\Users\utente\Desktop\Booking.com Extranet - -.pdf maughelli 31 dicembre.pdf
[2012/12/30 17:45:05 | 000,000,436 | —- | M] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/30 12:54:00 | 000,001,112 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-868304899-771622945-1420894305-1001Core.job
[2012/12/29 10:59:21 | 000,000,098 | —- | M] () – C:\windows\System32\drivers\etc\Hosts
[2012/12/29 10:57:28 | 000,001,074 | —- | M] () – C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/12/29 10:57:18 | 000,000,894 | —- | M] () – C:\Users\utente\Desktop\NTREGOPT.lnk
[2012/12/29 10:57:18 | 000,000,875 | —- | M] () – C:\Users\utente\Desktop\ERUNT.lnk
[2012/12/28 23:44:24 | 000,000,512 | —- | M] () – C:\Users\utente\Desktop\MBR.dat
[2012/12/28 22:22:56 | 000,550,017 | —- | M] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 21:59:21 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe
[2012/12/28 19:25:19 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | M] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2012/12/18 16:53:03 | 003,115,570 | —- | M] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/17 12:34:42 | 000,000,326 | —- | M] () – C:\windows\tasks\HPCeeScheduleForutente.job
[2012/12/16 22:15:14 | 000,000,218 | —- | M] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:47 | 000,271,046 | —- | M] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/12 20:11:29 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2012/12/12 20:11:29 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2012/12/10 09:48:08 | 000,470,393 | —- | M] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:28 | 001,040,996 | —- | M] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:29 | 000,612,798 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:11 | 000,219,495 | —- | M] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | M] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/03 11:38:02 | 000,001,363 | —- | M] () – C:\Users\utente\Desktop\Internet Explorer (No Add-ons).lnk
[2012/12/01 23:29:29 | 001,088,880 | —- | M] () – C:\Users\utente\Desktop\telecomando258.jpg

========== Files Created - No Company Name ==========

[2012/12/31 10:51:17 | 001,435,522 | —- | C] () – C:\Users\utente\Desktop\Diffida INPS-6600-01-10-2012-0125753 Pagamento F24.jpg
[2012/12/31 10:50:02 | 000,714,449 | —- | C] () – C:\Users\utente\Desktop\Diffida INPS-6600-01-10-2012-0125753 Pagamento F24.pdf
[2012/12/30 17:57:49 | 000,325,312 | —- | C] () – C:\Users\utente\Desktop\Booking.com Extranet - -.pdf maughelli 31 dicembre.pdf
[2012/12/29 10:57:28 | 000,001,074 | —- | C] () – C:\Users\utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/12/29 10:57:18 | 000,000,894 | —- | C] () – C:\Users\utente\Desktop\NTREGOPT.lnk
[2012/12/29 10:57:18 | 000,000,875 | —- | C] () – C:\Users\utente\Desktop\ERUNT.lnk
[2012/12/28 23:46:54 | 000,550,017 | —- | C] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 23:44:24 | 000,000,512 | —- | C] () – C:\Users\utente\Desktop\MBR.dat
[2012/12/28 19:25:19 | 000,014,160 | —- | C] () – C:\windows\System32\drivers\asdws.sys
[2012/12/28 19:25:19 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Anvi Smart Defender.lnk
[2012/12/28 19:24:59 | 000,001,458 | —- | C] () – C:\Users\Public\Desktop\Anvi AD Blocker.lnk
[2012/12/28 19:00:12 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2012/12/28 15:53:02 | 000,000,436 | —- | C] () – C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | —- | C] () – C:\mozilla.cfg
[2012/12/18 16:52:55 | 003,115,570 | —- | C] () – C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/16 22:15:14 | 000,000,218 | —- | C] () – C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:43 | 000,271,046 | —- | C] () – C:\Users\utente\Desktop\collier.pdf
[2012/12/10 09:48:08 | 000,470,393 | —- | C] () – C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:26 | 001,040,996 | —- | C] () – C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:28 | 000,612,798 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:10 | 000,219,495 | —- | C] () – C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/12/06 12:04:54 | 000,559,107 | —- | C] () – C:\Users\utente\Desktop\vodafone308.pdf
[2012/12/06 12:04:15 | 000,634,564 | —- | C] () – C:\Users\utente\Desktop\5 carta identità codice fiscale.pdf
[2012/12/01 23:29:29 | 001,088,880 | —- | C] () – C:\Users\utente\Desktop\telecomando258.jpg
[2012/09/01 10:32:47 | 000,000,030 | —- | C] () – C:\windows\iedit_.INI
[2012/05/17 11:00:28 | 000,116,189 | —- | C] () – C:\windows\System32\drivers\klin.dat
[2012/05/17 11:00:28 | 000,098,168 | —- | C] () – C:\windows\System32\drivers\klick.dat
[2012/04/18 10:33:44 | 000,017,408 | —- | C] () – C:\Users\utente\AppData\Local\WebpageIcons.db
[2012/02/08 16:26:32 | 000,258,348 | —- | C] () – C:\Users\utente\AppData\Local\rx_image32.Cache
[2011/12/03 17:00:13 | 000,000,827 | —- | C] () – C:\windows\Brpfx04a.ini
[2011/12/03 17:00:13 | 000,000,161 | —- | C] () – C:\windows\brpcfx.ini
[2011/12/03 16:58:32 | 000,106,496 | —- | C] () – C:\windows\System32\BrMuSNMP.dll
[2011/12/03 16:52:17 | 000,000,420 | —- | C] () – C:\windows\BRWMARK.INI
[2011/12/03 16:52:17 | 000,000,065 | —- | C] () – C:\windows\System32\BD7820N.DAT
[2011/08/31 21:11:40 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2011/03/11 11:43:54 | 000,029,763 | —- | C] () – C:\windows\System32\drivers\klopp.dat
[2010/11/23 00:27:55 | 000,000,600 | —- | C] () – C:\Users\utente\AppData\Roaming\winscp.rnd
[2010/09/08 10:07:40 | 000,159,464 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4

========== ZeroAccess Check ==========

[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2010/07/27 15:03:24 | 012,867,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/14 02:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/01/11 21:08:57 | 000,004,183 | —- | M] () MD5=4CF10EA9BAB7750F41A7E154AECAF977 – C:\Windows\PolicyDefinitions\it-IT\Explorer.adml
[2010/01/11 21:08:57 | 000,004,183 | —- | M] () MD5=4CF10EA9BAB7750F41A7E154AECAF977 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_it-it_af819edf95d3f553\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2009/10/06 07:06:36 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_523cdab8f40fe558\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
[2009/10/06 06:53:03 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_51c00e6ddae85c4b\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/01/11 21:08:35 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=D871BB5958AEF9F493B330FCB533DE6B – C:\Windows\it-IT\explorer.exe.mui
[2010/01/11 21:08:35 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=D871BB5958AEF9F493B330FCB533DE6B – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_it-it_9273a66a9f204dea\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2012/12/31 00:34:16 | 000,164,990 | —- | M] () MD5=CAB544C88AD0E14759DBF1D96FBE7F84 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: EXPLORER.GIF >
[2002/08/24 16:39:32 | 000,000,144 | —- | M] () MD5=C6F37D67EA0A5C873F4A9DE08913E4AD – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\postnuke\pn-0.7.2.1_Phoenix\html\modules\Stats\images\explorer.gif

< MD5 for: IEXPLORE.BAT >
[2012/12/15 19:52:46 | 000,024,911 | —- | M] () MD5=93357EBDABCC46C66143D6DAAFDF4400 – C:\JRT\iexplore.bat

< MD5 for: IEXPLORE.EXE >
[2010/09/08 05:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_b3c5cc459f4108f2\iexplore.exe
[2010/11/04 06:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_b3987f3a85deec23\iexplore.exe
[2010/09/08 05:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_b34dce2a8616cbea\iexplore.exe
[2010/11/04 06:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_b402ac8b9f13f917\iexplore.exe
[2010/12/18 06:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_b3e23cc79f2c4cea\iexplore.exe
[2010/12/18 06:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_b384dff685ed56b3\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Program Files\Internet Explorer\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe
[2009/07/14 02:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2011/02/24 06:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2010/01/11 21:08:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=25762CE531381E3240DF74F039B5744F – C:\Program Files\Internet Explorer\it-IT\iexplore.exe.mui
[2010/01/11 21:08:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=25762CE531381E3240DF74F039B5744F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_it-it_399e585587f3842e\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2012/12/31 00:38:31 | 000,155,632 | —- | M] () MD5=05B895E1CAF7211280D33FD56D66E3A0 – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf

< MD5 for: SERVICES >
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.DAT >
[2012/12/14 05:08:43 | 000,001,445 | —- | M] () MD5=18134F4CA7DBCC5437D715A28E283D86 – C:\JRT\services.dat

< MD5 for: SERVICES.EXE >
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/01/11 21:08:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=A655D2AC28162C1EB0080B2DC7B7ABC4 – C:\Windows\System32\it-IT\services.exe.mui
[2010/01/11 21:08:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=A655D2AC28162C1EB0080B2DC7B7ABC4 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_it-it_f67e66645173b0b7\services.exe.mui

< MD5 for: SERVICES.GIF >
[2002/10/06 19:00:53 | 000,001,497 | —- | M] () MD5=7735A8919EB725BEE2C1F5412AEB1CBE – C:\Users\utente\Documents\Documents\INGEGNERIA\Progetti\dedicated\aaa Cpanel Dedicated web hosting, website host, server, Atjeu LLC_file\services.gif
[2002/06/16 11:38:56 | 000,000,525 | —- | M] () MD5=9AC87980AFE072913590D88B7B471820 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\images\services.gif
[2002/09/30 18:34:20 | 000,000,255 | —- | M] () MD5=C80515821C9CB1F4DCEA089CE3A0AF6F – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\status2final\images\services.gif

< MD5 for: SERVICES.INC >
[2002/06/15 17:07:00 | 000,000,358 | —- | M] () MD5=8762E7C17EBF73171BBBC23C79A45235 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\templates\services.inc

< MD5 for: SERVICES.LNK >
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2010/01/11 21:08:32 | 000,092,755 | —- | M] () MD5=1452B2812DA789ABB1998CB07F97524A – C:\Windows\System32\it-IT\services.msc
[2010/01/11 21:08:32 | 000,092,755 | —- | M] () MD5=1452B2812DA789ABB1998CB07F97524A – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_it-it_30c0365027dd4aaa\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PNG >
[2008/03/27 04:57:28 | 000,003,334 | —- | M] () MD5=5FF3A00670DE8D80ADA4BD034B55D154 – C:\Program Files\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Red\services.png
[2008/03/27 04:38:18 | 000,003,827 | —- | M] () MD5=BFC0958B73C61EE6C5EEA8D8C6073D26 – C:\Program Files\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Blue\services.png

< MD5 for: SERVICES.PTXML >
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: SERVICES.RDB >
[2012/04/19 07:43:10 | 000,178,348 | —- | M] () MD5=039C8CFBD74EE07F38CD9E4C7D95C5C6 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2012/04/19 07:43:10 | 000,000,453 | —- | M] () MD5=3D2ADA15FEF5B5FF468243161543D610 – C:\Program Files\OpenOffice.org 3\program\services.rdb
[2012/04/13 05:55:44 | 000,008,060 | —- | M] () MD5=7CA7D7150EC46321162F932ADCF5F35B – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb

< MD5 for: SERVICES.TXT >
[2002/06/16 19:14:16 | 000,000,033 | —- | M] () MD5=5DFABC09BF8025F4EAE9ADD8B1EE9466 – C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\data\services.txt

< MD5 for: WINLOGON.ADML >
[2010/01/11 21:08:55 | 000,009,430 | —- | M] () MD5=7A3DF5FA7925B53A60E9B3A0764A296B – C:\Windows\PolicyDefinitions\it-IT\WinLogon.adml
[2010/01/11 21:08:55 | 000,009,430 | —- | M] () MD5=7A3DF5FA7925B53A60E9B3A0764A296B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_it-it_218530d508607cbf\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/10/28 07:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\System32\winlogon.exe
[2009/10/28 07:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 06:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/01/11 21:08:32 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=10F25BD9440B0451952225BCAAB284E2 – C:\Windows\System32\it-IT\winlogon.exe.mui
[2010/01/11 21:08:32 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=10F25BD9440B0451952225BCAAB284E2 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_it-it_5779b0d82f94f530\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/01/11 21:08:33 | 000,001,080 | —- | M] () MD5=B5CE50ECD88A87597DE1E8DE71AC2ADF – C:\Windows\System32\wbem\it-IT\winlogon.mfl
[2010/01/11 21:08:33 | 000,001,080 | —- | M] () MD5=B5CE50ECD88A87597DE1E8DE71AC2ADF – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_it-it_b53c02a34acd4ec5\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012/12/28 23:48:02 | 000,013,690 | —- | M] () – C:\AdwCleaner[S1].txt
[2012/12/28 19:00:12 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2012/12/21 09:00:05 | 000,000,000 | —- | M] () – C:\ctapi_out_gr.txt
[2008/04/11 09:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2009/03/02 22:47:38 | 000,049,233 | —- | M] () – C:\fat32format.exe
[2008/04/11 09:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/12/31 11:20:45 | 2387,816,448 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 07:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 09:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/12/28 10:52:33 | 000,000,000 | —- | M] () – C:\mozilla.cfg
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/12/31 11:20:50 | 3183,755,264 | -HS- | M] () – C:\pagefile.sys
[2010/04/15 10:20:33 | 000,982,458 | —- | M] () – C:\Setup Log 2010-04-15 #001.txt
[2012/12/28 11:50:07 | 000,147,038 | —- | M] () – C:\TDSSKiller.2.8.15.0_28.12.2012_11.49.07_log.txt
[2012/02/08 16:06:27 | 000,065,745 | —- | M] () – C:\testFindSector.log
[2009/10/19 23:43:50 | 000,047,104 | —- | M] () – C:\Thumbs.db
[2008/04/11 09:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 09:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 09:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | -H– | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/17 04:23:20 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\windows\system32\spool\prtprocs\w32x86\DELR1pc.dll
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/14 18:36:17 | 000,000,221 | -HS- | M] () – C:\Users\utente\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/12/28 22:22:56 | 000,550,017 | —- | M] () – C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 21:59:21 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\utente\Desktop\aswMBR.exe
[2012/12/30 18:29:59 | 000,497,009 | —- | M] (Oleg N. Scherbakov) – C:\Users\utente\Desktop\JRT.exe
[2012/12/28 19:47:16 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\utente\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:FB1B13D8

< End of report >
Jeff You're Great! Chrome shows not more trace of btsearch.name neither avg The same Internet explorer And I can't find anymore that you tube dowloader helper in memory You did a really great job! Let me thank thank thank you! I've been on the net sin 1993 and I thought my PC safe using a commercial and very considered Antivirus Suite: instead I found out I was blind! Thank You again and Happy New Year!
Justa a silly question: is there a place in this GREAT forum where to find some suggestion on which security tool to keep to avoid infections? Now I don't trust anymore my usual security measures

You did a really great job!
Let me thank thank thank you!

You are more than welcome and glad that I could help. :)
——–

is there a place in this GREAT forum where to find some suggestion on which security tool to keep to avoid infections?

There is all sorts of information on this site that you can look for that will give you all kinds of answers. The easiest answer is that to avoid infections as best you can (there is no 100% way to stop them) is to have your antivirus, firewall and other software on your system up-to-date and running. Apply this, along with a good dose of common sense in the sites that are out there to visit and you will be in pretty good shape. Sometimes you can do everything right and still get infected…it just happens unfortunately.
———

Providing there are no other malware related problems…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!!

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Press the Windows key + R and this will open the Run box. Copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Clean up with OTL:
  • Right-click and Run as Administrator OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.
If you didn't already have it I would keep Malwarebytes AntiMalware though.


Here are some tips to reduce the potential for spyware infection in the future:

1. Internet Explorer. Even if you don't use it as your main browser it should be kept up-to-date because that is the browser Windows uses for updates.
Make your Internet Explorer more secure
- This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. FireFox. If you use Firefox, I recommend installing the following add-ons to help make your Firefox browser more secure:
NoScript
AdBlock Plus

3. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
4. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

5. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

6. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

7. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read How to Prevent Malware found here and also PC Safety and Security - What Do I Need?.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
sorry for my late reply I never installed Combofix: I dowloaded it now but could you please confirm what I should do now? Should I run it as administrator and then Combofix /Uninstall? ps Happy New Year!
meanwhile I'm installing WOT and Malwarebytes' Anti-Malware Thank You for your kind suggestions. I will read the links you provided Just to let you know: A thing I noticed about my browsing is that after btsearch.name infected my notebook, now Internet surfing has some stop: I mean in the last days I get some " Oops! Google Chrome could not connect to " and lots of reload later pages. For example in this moment I'm not able to connect to malwarebytes download page

I never installed Combofix

Disregard those instructions…sorry about that.
———

A thing I noticed about my browsing is that after btsearch.name infected my notebook, now Internet surfing has some stop: I mean in the last days I get some " Oops! Google Chrome could not connect to " and lots of reload later pages.

Is this only in Google Chrome? If so, I would recommend uninstalling Google Chrome completely and then reinstalling the newest version. It is much more secure than any other version has been before. :)
ok I hope it's only a false alarm but I'm following your suggestion: I Installed Malwarebytes I ran OTL Cleanup and after reboot I deleted ERT from startup because and started and stop JRT by mistake. I opened Outlook and my kaspersky got crazy telling me outlook was trying to get access to password archive because of a .bat file. I denied and closed outlook. I rebooted but system got frozen. I was forced ton reboot again because nothing started after 15 minutes. After a very slow reboot now it seems working but Malwarebytes signs access of AVP (kaspersky) to dangerous site. I suppose it could be a conflict between the two antivirus.

I deleted ERT

:huh: What is that?
——-

Run a new scan with Malwarebytes and post the log…
———-

Also do the following:

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
nothing found by malwarebytes Malwarebytes Anti-Malware (Prova) 1.70.0.1100 www.malwarebytes.org Versione database: v2013.01.02.10 Windows 7 x86 NTFS Internet Explorer 8.0.7600.16385 utente :: PC [amministratore] Protezione: Attivata 03/01/2013 10:38:32 mbam-log-2013-01-03 (10-38-32).txt Tipo di scansione: Scansione veloce Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File di sistema | Euristica/Extra | Euristica/Shuriken | PUP | PUM Opzioni di scansione disattivate: P2P Elementi esaminati: 218936 Tempo impiegato: 12 minuti, 43 secondi Processi rilevati in memoria: 0 (non sono stati rilevati elementi nocivi) Moduli di memoria rilevati: 0 (non sono stati rilevati elementi nocivi) Chiavi di registro rilevate: 0 (non sono stati rilevati elementi nocivi) Valori di registro rilevati: 0 (non sono stati rilevati elementi nocivi) Voci rilevate nei dati di registro: 0 (non sono stati rilevati elementi nocivi) Cartelle rilevate: 0 (non sono stati rilevati elementi nocivi) File rilevati: 0 (non sono stati rilevati elementi nocivi) (fine) 2013/01/03 00:48:38 +0100 PC utente MESSAGE Starting protection 2013/01/03 00:48:39 +0100 PC utente MESSAGE Protection started successfully 2013/01/03 00:48:39 +0100 PC utente MESSAGE Starting IP protection 2013/01/03 00:48:44 +0100 PC utente MESSAGE IP Protection started successfully 2013/01/03 00:50:00 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60816, Process: avp.exe) 2013/01/03 00:50:00 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60817, Process: avp.exe) 2013/01/03 00:50:00 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60818, Process: avp.exe) 2013/01/03 00:50:00 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60819, Process: avp.exe) 2013/01/03 00:50:00 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60832, Process: avp.exe) 2013/01/03 00:50:00 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60833, Process: avp.exe) 2013/01/03 00:50:08 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60846, Process: avp.exe) 2013/01/03 00:50:08 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60847, Process: avp.exe) 2013/01/03 00:50:08 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60855, Process: avp.exe) 2013/01/03 00:50:08 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 60856, Process: avp.exe) 2013/01/03 00:54:57 +0100 PC (null) MESSAGE Starting protection 2013/01/03 00:54:58 +0100 PC (null) MESSAGE Protection started successfully 2013/01/03 00:54:58 +0100 PC (null) MESSAGE Starting IP protection 2013/01/03 00:55:02 +0100 PC (null) MESSAGE IP Protection started successfully 2013/01/03 01:03:10 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49324, Process: avp.exe) 2013/01/03 01:04:05 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49325, Process: avp.exe) 2013/01/03 01:05:23 +0100 PC utente MESSAGE Starting protection 2013/01/03 01:05:23 +0100 PC utente MESSAGE Protection started successfully 2013/01/03 01:05:23 +0100 PC utente MESSAGE Starting IP protection 2013/01/03 01:05:28 +0100 PC utente MESSAGE Executing scheduled update: Daily 2013/01/03 01:05:30 +0100 PC utente MESSAGE IP Protection started successfully 2013/01/03 01:05:33 +0100 PC utente MESSAGE Database already up-to-date 2013/01/03 01:17:37 +0100 PC utente MESSAGE Starting protection 2013/01/03 01:17:38 +0100 PC utente MESSAGE Protection started successfully 2013/01/03 01:17:38 +0100 PC utente MESSAGE Starting IP protection 2013/01/03 01:17:42 +0100 PC utente MESSAGE IP Protection started successfully 2013/01/03 01:24:05 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49284, Process: avp.exe) 2013/01/03 01:24:05 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49285, Process: avp.exe) 2013/01/03 01:25:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49334, Process: avp.exe) 2013/01/03 01:25:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49335, Process: avp.exe) 2013/01/03 01:25:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49336, Process: avp.exe) 2013/01/03 01:25:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49343, Process: avp.exe) 2013/01/03 01:25:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49347, Process: avp.exe) 2013/01/03 01:25:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49348, Process: avp.exe) 2013/01/03 01:25:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49359, Process: avp.exe) 2013/01/03 01:25:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49361, Process: avp.exe) 2013/01/03 01:26:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49407, Process: avp.exe) 2013/01/03 01:26:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49408, Process: avp.exe) 2013/01/03 01:26:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49433, Process: avp.exe) 2013/01/03 01:26:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49434, Process: avp.exe) 2013/01/03 01:26:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49435, Process: avp.exe) 2013/01/03 01:26:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49438, Process: avp.exe) 2013/01/03 01:26:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49444, Process: avp.exe) 2013/01/03 01:26:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49445, Process: avp.exe) 2013/01/03 01:26:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49449, Process: avp.exe) 2013/01/03 01:26:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49450, Process: avp.exe) 2013/01/03 01:26:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49455, Process: avp.exe) 2013/01/03 01:26:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49457, Process: avp.exe) 2013/01/03 01:35:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49572, Process: avp.exe) 2013/01/03 01:35:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49573, Process: avp.exe) 2013/01/03 10:35:09 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49794, Process: avp.exe) 2013/01/03 10:35:09 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49795, Process: avp.exe) 2013/01/03 10:35:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49890, Process: avp.exe) 2013/01/03 10:35:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49912, Process: avp.exe) 2013/01/03 10:35:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49913, Process: avp.exe) 2013/01/03 10:35:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49914, Process: avp.exe) 2013/01/03 10:35:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49915, Process: avp.exe) 2013/01/03 10:35:35 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49933, Process: avp.exe) 2013/01/03 10:35:43 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 49999, Process: avp.exe) 2013/01/03 10:35:43 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50000, Process: avp.exe) 2013/01/03 10:36:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50018, Process: avp.exe) 2013/01/03 10:36:16 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50029, Process: avp.exe) 2013/01/03 10:36:16 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50030, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50118, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50119, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50120, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50121, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50122, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50123, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50127, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50130, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50171, Process: avp.exe) 2013/01/03 10:39:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50172, Process: avp.exe) 2013/01/03 10:39:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50175, Process: avp.exe) 2013/01/03 10:39:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50178, Process: avp.exe) 2013/01/03 10:39:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50179, Process: avp.exe) 2013/01/03 10:39:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50180, Process: avp.exe) 2013/01/03 10:39:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50218, Process: avp.exe) 2013/01/03 10:39:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50219, Process: avp.exe) 2013/01/03 10:39:24 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50283, Process: avp.exe) 2013/01/03 10:39:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50290, Process: avp.exe) 2013/01/03 10:39:40 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50302, Process: avp.exe) 2013/01/03 10:39:40 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50303, Process: avp.exe) 2013/01/03 10:40:36 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50413, Process: avp.exe) 2013/01/03 10:40:37 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50414, Process: avp.exe) 2013/01/03 10:40:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50433, Process: avp.exe) 2013/01/03 10:40:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50434, Process: avp.exe) 2013/01/03 10:41:41 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50472, Process: avp.exe) 2013/01/03 10:41:42 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50473, Process: avp.exe) 2013/01/03 10:41:58 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50532, Process: avp.exe) 2013/01/03 10:41:58 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50539, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50582, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50583, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50595, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50597, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50602, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50607, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50614, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50615, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50616, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50617, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50681, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50682, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50683, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50687, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50688, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50702, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50703, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50712, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50723, Process: avp.exe) 2013/01/03 10:42:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50724, Process: avp.exe) 2013/01/03 10:42:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50736, Process: avp.exe) 2013/01/03 10:42:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50737, Process: avp.exe) 2013/01/03 10:42:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50740, Process: avp.exe) 2013/01/03 10:42:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50741, Process: avp.exe) 2013/01/03 10:43:11 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50780, Process: avp.exe) 2013/01/03 10:43:11 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50781, Process: avp.exe) 2013/01/03 10:43:27 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50790, Process: avp.exe) 2013/01/03 10:43:27 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50791, Process: avp.exe) 2013/01/03 10:43:27 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50794, Process: avp.exe) 2013/01/03 10:43:27 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50795, Process: avp.exe) 2013/01/03 10:43:36 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50810, Process: avp.exe) 2013/01/03 10:43:36 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50811, Process: avp.exe) 2013/01/03 10:43:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50827, Process: avp.exe) 2013/01/03 10:43:46 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50829, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50837, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50841, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50842, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50848, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50849, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50850, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50851, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50858, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50860, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50913, Process: avp.exe) 2013/01/03 10:43:55 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50914, Process: avp.exe) 2013/01/03 10:43:56 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50933, Process: avp.exe) 2013/01/03 10:43:56 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50934, Process: avp.exe) 2013/01/03 10:43:56 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50935, Process: avp.exe) 2013/01/03 10:43:56 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50936, Process: avp.exe) 2013/01/03 10:44:28 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50958, Process: avp.exe) 2013/01/03 10:44:28 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50959, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50980, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50981, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50986, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50987, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50988, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 50990, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51020, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51021, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51022, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51023, Process: avp.exe) 2013/01/03 10:44:45 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51038, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51200, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51202, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51203, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51204, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51205, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51206, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51216, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51221, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51223, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51231, Process: avp.exe) 2013/01/03 10:44:53 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51232, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51262, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51263, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51284, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51285, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51296, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51297, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51299, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51302, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51303, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 51306, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 51307, Process: avp.exe) 2013/01/03 10:45:01 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 51309, Process: avp.exe) 2013/01/03 10:45:09 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51311, Process: avp.exe) 2013/01/03 10:45:09 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51315, Process: avp.exe) 2013/01/03 10:45:09 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51316, Process: avp.exe) 2013/01/03 10:45:09 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 51340, Process: avp.exe) 2013/01/03 10:45:18 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51356, Process: avp.exe) 2013/01/03 10:45:18 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51357, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51384, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51385, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51388, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51389, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51394, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51395, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51396, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51397, Process: avp.exe) 2013/01/03 10:45:26 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 51399, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51410, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51411, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51412, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51415, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51439, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51478, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51479, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51482, Process: avp.exe) 2013/01/03 10:45:34 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51484, Process: avp.exe) 2013/01/03 10:45:42 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51487, Process: avp.exe) 2013/01/03 10:45:42 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51489, Process: avp.exe) 2013/01/03 10:45:42 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51490, Process: avp.exe) 2013/01/03 10:45:42 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51492, Process: avp.exe) 2013/01/03 10:45:42 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51519, Process: avp.exe) 2013/01/03 10:45:42 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51520, Process: avp.exe) 2013/01/03 10:45:51 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51542, Process: avp.exe) 2013/01/03 10:45:51 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51545, Process: avp.exe) 2013/01/03 10:45:51 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51546, Process: avp.exe) 2013/01/03 10:45:51 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51547, Process: avp.exe) 2013/01/03 10:46:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51554, Process: avp.exe) 2013/01/03 10:46:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51555, Process: avp.exe) 2013/01/03 10:46:23 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51575, Process: avp.exe) 2013/01/03 10:46:23 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51578, Process: avp.exe) 2013/01/03 10:46:23 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51579, Process: avp.exe) 2013/01/03 10:46:23 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51580, Process: avp.exe) 2013/01/03 10:46:23 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51599, Process: avp.exe) 2013/01/03 10:46:23 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51600, Process: avp.exe) 2013/01/03 10:46:31 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51613, Process: avp.exe) 2013/01/03 10:46:31 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51614, Process: avp.exe) 2013/01/03 10:46:48 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51627, Process: avp.exe) 2013/01/03 10:46:49 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51629, Process: avp.exe) 2013/01/03 10:46:57 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51664, Process: avp.exe) 2013/01/03 10:46:57 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51665, Process: avp.exe) 2013/01/03 10:46:58 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51669, Process: avp.exe) 2013/01/03 10:46:58 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51670, Process: avp.exe) 2013/01/03 10:46:58 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 51672, Process: avp.exe) 2013/01/03 10:47:06 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51683, Process: avp.exe) 2013/01/03 10:47:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51706, Process: avp.exe) 2013/01/03 10:47:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51707, Process: avp.exe) 2013/01/03 10:47:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51708, Process: avp.exe) 2013/01/03 10:47:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51709, Process: avp.exe) 2013/01/03 10:47:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51710, Process: avp.exe) 2013/01/03 10:47:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51737, Process: avp.exe) 2013/01/03 10:47:07 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51738, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51743, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51744, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51745, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51746, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51748, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51750, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51752, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51759, Process: avp.exe) 2013/01/03 10:47:15 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51760, Process: avp.exe) 2013/01/03 10:47:23 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51787, Process: avp.exe) 2013/01/03 10:47:23 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51789, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51824, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51825, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51826, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51827, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51852, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51853, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51854, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51858, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51867, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51868, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51873, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51874, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51875, Process: avp.exe) 2013/01/03 10:47:32 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51876, Process: avp.exe) 2013/01/03 10:47:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51878, Process: avp.exe) 2013/01/03 10:47:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51880, Process: avp.exe) 2013/01/03 10:47:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51882, Process: avp.exe) 2013/01/03 10:47:41 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51886, Process: avp.exe) 2013/01/03 10:47:41 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51887, Process: avp.exe) 2013/01/03 10:48:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51901, Process: avp.exe) 2013/01/03 10:48:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51902, Process: avp.exe) 2013/01/03 10:48:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51903, Process: avp.exe) 2013/01/03 10:48:38 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51904, Process: avp.exe) 2013/01/03 10:49:03 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51909, Process: avp.exe) 2013/01/03 10:49:03 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51910, Process: avp.exe) 2013/01/03 10:49:20 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51916, Process: avp.exe) 2013/01/03 10:49:20 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51919, Process: avp.exe) 2013/01/03 10:49:20 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51920, Process: avp.exe) 2013/01/03 10:49:20 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51921, Process: avp.exe) 2013/01/03 10:49:36 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51931, Process: avp.exe) 2013/01/03 10:49:36 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51932, Process: avp.exe) 2013/01/03 10:50:16 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51959, Process: avp.exe) 2013/01/03 10:50:16 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51960, Process: avp.exe) 2013/01/03 10:50:24 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51993, Process: avp.exe) 2013/01/03 10:50:24 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 51995, Process: avp.exe) 2013/01/03 10:50:24 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52007, Process: avp.exe) 2013/01/03 10:50:24 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52009, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52011, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52020, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52021, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52031, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52032, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52036, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52037, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 52042, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 52043, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 52049, Process: avp.exe) 2013/01/03 10:50:25 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 52051, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52057, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52058, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52061, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52064, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52065, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52066, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 62.149.140.24 (Type: outgoing, Port: 52069, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52072, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52073, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52078, Process: avp.exe) 2013/01/03 10:50:33 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52079, Process: avp.exe) 2013/01/03 10:58:04 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52138, Process: avp.exe) 2013/01/03 10:58:04 +0100 PC utente IP-BLOCK 93.170.104.62 (Type: outgoing, Port: 52139, Process: avp.exe)

there must be a conflict with kaspersky anyway

I agree with that. Looks like maybe the real-time protection of MBAM is conflicting with Kaspersky. Disable the real-time protection of Malwarebytes by opening Malwarebytes >> Protection tab >> uncheck Enable Filesystem protection/malicious website blocking >> Exit. Let me know if that clears this up.
ERT was a mistyping for ERUNT ESET result: it found one threat in a antyspyware I tried to remove btsearch before posting here: C:\Users\utente\Downloads\SpywareCease_Setup (1).exe multiple threats
First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.

Copy the contents of the code box > right click in the command window and select paste
del C:\Users\utente\Downloads\SpywareCease_Setup (1).exe
Press Enter
Close the Command Prompt window.

How is your system running? :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI