chrome start page and search: btsearch.name [Solved]
44 min read
Glad that your system is running well. I am not sure where the extension is coming fromโฆespecially if you have already uninstalled and downloaded a fresh copy of Chrome to your systemโฆ.but if you are not wanting the youtube downloader you can remove it as an extension by pressing the trashcan next to it in Chrome Extensions.
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\utente\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
2.97 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 35.03% Memory free
5.93 Gb Paging File | 3.26 Gb Available in Paging File | 54.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 181.60 Gb Free Space | 40.49% Space Free | Partition Type: NTFS
Drive E: | 1.99 Gb Total Space | 1.76 Gb Free Space | 88.37% Space Free | Partition Type: FAT32
Computer Name: PC | User Name: utente | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\utente\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\OAhlp.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\OAcat.exe (Emsisoft GmbH)
PRC - C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\windows\explorer.exe (Microsoft Corporation)
PRC - C:\windows\System32\spool\drivers\w32x86\3\WrtProc.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
PRC - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\Eraser\Eraser.exe (The Eraser Project)
PRC - C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\windows\System32\atieclxx.exe (AMD)
PRC - C:\windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
PRC - C:\windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\23.0.1271.97\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\23.0.1271.97\libglesv2.dll ()
MOD - C:\Program Files\Google\Chrome\Application\23.0.1271.97\libegl.dll ()
MOD - C:\Program Files\Google\Chrome\Application\23.0.1271.97\avutil-51.dll ()
MOD - C:\Program Files\Google\Chrome\Application\23.0.1271.97\avformat-54.dll ()
MOD - C:\Program Files\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtGui4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtNetwork4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtScript4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtSql4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtDeclarative4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\QtCore4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\dblite.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qgif4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dda6d8c7413334b605fcf590a702e9f1\Microsoft.VisualBasic.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\bf0286e181064f9ded08895c7f23967d\System.Core.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\94eb4ca06f43edf88bbdecd3729657d5\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b6d66d3c48e430796c17d0497ce37972\System.ServiceProcess.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c519a7e1b063eb63b43fa5b3a782c641\System.Design.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\b867fbc0d573ac5e5fe71143d9caf43b\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\adc8998d96ca331d17cef00b1ef95a5f\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4be7719ea0e1f2ba2d3fde051d1ef7ab\System.Transactions.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\b9565c454a22ca564978b05db4186f22\System.Data.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7827588b8043e8be3184c8a64a867fc\PresentationFramework.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e4ea95056046fdf87f06ae807308b627\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2a34e74599686e7383ae90670a994cdf\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\11ebcba65c931267301739008a883e60\Accessibility.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\03dd2b7701ca5cfe696d4ca5a0f7b8bb\PresentationCore.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\caa9d8bca3092573cdbb67c8e81bf0f3\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\395fc7d9f333940351a74aaab5d6ae99\System.Security.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\167c8c3817ba1f48fe7396cc56f557e3\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9d054fc9618b81d5703af1662cd11135\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\50c67f851ae3df2d0ab7d86fd1c5c7e0\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ebdaeaeb9f66c9035b5f11431f10cda4\mscorlib.ni.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\ScanModule.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMScnSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMDB_N.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMCommon.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMISM.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMTree.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMImageSplitter.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMView.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSave.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMPageVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMImgVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMINSO.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\OutlookVBA.dll ()
MOD - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\Vodafone.View.Taskbar.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMPDFView.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\SlideBarDLL.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMOffice.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMProp.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PerformOcr.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMStatus.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3503.18374__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3503.18350__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3503.18376__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3503.18369__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3503.18360__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3503.18471__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3503.18426__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3503.18471__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3503.18427__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3503.18446__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3503.18360__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3503.18419__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3503.18426__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3503.18472__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3503.18470__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3503.18406__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3503.18409__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3503.18377__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3503.18439__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3503.18363__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3503.18376__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3503.18415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3503.18408__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3503.18382__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3503.18415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3503.18407__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3503.18402__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3503.18417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3503.18383__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3503.18407__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3503.18408__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3503.18417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3428.28302__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3428.28329__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3428.28305__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3428.28298__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3428.28324__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3428.28296__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3428.28297__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3428.28354__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3428.28304__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3428.28302__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3428.28310__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3428.28324__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3428.28303__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3428.28316__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3428.28309__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3428.28323__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3428.28311__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Foundation\2.0.3428.28310__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3503.18465__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3503.18463__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3503.18478__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3428.28301__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3428.28310__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3503.18344__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3503.18356__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3503.18368__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3503.18348__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3503.18347__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3428.28309__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3428.28316__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Server\2.0.3503.18346__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server\2.0.3503.18345__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3503.18464__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMDocVW.dll ()
MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_it_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMAnoSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMAppBar.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\NetFun2k.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMANO.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\FT.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll ()
MOD - C:\Windows\System32\msjetoledb40.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMApSet.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\nsSign.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PHooKDlg.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMIEVW.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\PMVoice.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMENC.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\KMAESLib.dll ()
MOD - C:\Program Files\KONICA MINOLTA\PageScope Box Operator3\MCharSet.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\Qem.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\NsOEMKey.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\Import.dll ()
MOD - C:\Program Files\NewSoft\Presto! PageManager 9.03\ComClass.dll ()
========== Services (SafeList) ==========
SRV - (MSDTC) โ File not found
SRV - (MBAMService) โ C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) โ C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) โ C:\windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SvcOnlineArmor) โ C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) โ C:\Program Files\Online Armor\OAcat.exe (Emsisoft GmbH)
SRV - (AVP) โ C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
SRV - (EpsonCustomerResearchParticipation) โ C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (ServiceLayer) โ C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (VmbService) โ C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) โ C:\windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (CSObjectsSrv) โ C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (IAANTMON) โ C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (AMD External Events Utility) โ C:\windows\System32\atiesrxx.exe (AMD)
SRV - (btwdins) โ C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (yksvc) โ C:\Windows\System32\yk62x86.dll (Marvell)
SRV - (StorSvc) โ C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) โ C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) โ C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) โ C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (RoxMediaDB10) โ c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (AEADIFilters) โ C:\windows\System32\AEADISRV.EXE (Andrea Electronics Corporation)
========== Driver Services (SafeList) ==========
DRV - (RkHit) โ C:\windows\system32\drivers\RKHit.sys File not found
DRV - (MRENDIS5) โ C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) โ C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (MBAMProtector) โ C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (taphss6) โ C:\Windows\System32\drivers\taphss6.sys (Anchorfree Inc.)
DRV - (HssDRV6) โ C:\Windows\System32\drivers\hssdrv6.sys (AnchorFree Inc.)
DRV - (KLIF) โ C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (oahlpXX) โ C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OAnet) โ C:\Windows\System32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) โ C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) โ C:\Windows\System32\drivers\OADriver.sys ()
DRV - (kl1) โ C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) โ C:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (UsbserFilt) โ C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) โ C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) โ C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) โ C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (KLIM6) โ C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV - (vodafone_K3805-z_cdc_ecm) โ C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) โ C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) โ C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) โ C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (FsUsbExDisk) โ C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NETw5s32) โ C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (CSCrySec) โ C:\Windows\System32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) โ C:\Windows\System32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (klmouflt) โ C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (atikmdag) โ C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) โ C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (ewusbnet) โ C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) โ C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) โ C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (yukonw7) โ C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (vmbus) โ C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) โ C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) โ C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) โ C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) โ C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) โ C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) โ C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) โ C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (AgereSoftModem) โ C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (netw5v32) โ C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (hpdskflt) โ C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard)
DRV - (Accelerometer) โ C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard)
DRV - (5U876UVC) โ C:\Windows\System32\drivers\5U876.sys (Ricoh co.,Ltd.)
DRV - (mfetdik) โ C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HpqKbFiltr) โ C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (pccsmcfd) โ C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (MREMP50) โ C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) โ C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pfc) โ C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/08/26 13:44:54 | 000,000,000 | โD | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | โD | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | โD | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\[removed] [2012/10/25 14:26:42 | 000,000,000 | โD | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/08/26 13:44:54 | 000,000,000 | โD | M]
[2012/09/17 15:23:28 | 000,000,000 | โD | M] (No name found) โ C:\Users\utente\AppData\Roaming\mozilla\Extensions
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: YouTube Downloader NPAPI (Enabled) = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocfnbdnkiipodbhenicdkamolggckhnl\3.0.0.0_0\YouTube Downloader-np.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Javaโข Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: WOT = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.3_0\
CHR - Extension: YouTube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: YouTube Downloader = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocfnbdnkiipodbhenicdkamolggckhnl\3.0.0.0_0\
CHR - Extension: Gmail = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/12/29 10:59:21 | 000,000,098 | โ- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" โatRestart File not found
O4 - HKLM..\Run: [FUFAXRCV] C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [PMSpeed] C:\Program Files\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE (NewSoft Technology Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WrtMon.exe] C:\windows\System32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
O4 - HKCU..\Run: [EPSON WF-7515 Series] C:\windows\System32\spool\DRIVERS\W32X86\3\E_TATIHCE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 100
O8 - Extra context menu item: Aggiungi ad Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Invia immagine alla periferica &Bluetooth;โฆ - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Invia pagina alla periferica &Bluetooth;โฆ - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{65C17FEC-4D94-4AF8-917D-6111DA444667}: NameServer = 83.224.70.93 83.224.66.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{98ECAE4D-7803-485D-B168-2FF52E90694F}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC3BBE37-C7E4-4597-9FD9-51FEBDCB221B}: NameServer = 8.8.8.8,8.8.8.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.24
7.20,156.154.70.1,156.154.71.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF42F48F-3663-45FD-8BB4-4F3844DC57A5}: DhcpNameServer = 8.8.8.8
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\PROGRA~1\ONLINE~2\oaevent.dll (Emsisoft GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/12/28 19:00:12 | 000,000,000 | โ- | M] () - C:\autoexec.bat โ [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] โ "%1" %*
O35 - HKLM\..exefile [open] โ "%1" %*
O37 - HKLM\โฆcom [@ = comfile] โ "%1" %*
O37 - HKLM\โฆexe [@ = exefile] โ "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv50 - C:\windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/01/06 15:43:41 | 000,000,000 | โD | C] โ C:\Users\utente\Desktop\alessandro
[2013/01/05 23:44:14 | 000,602,112 | โ- | C] (OldTimer Tools) โ C:\Users\utente\Desktop\OTL.exe
[2013/01/05 23:23:09 | 000,000,000 | โD | C] โ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/01/03 15:37:49 | 000,000,000 | โD | C] โ C:\Users\utente\AppData\Roaming\OnlineArmor
[2013/01/03 15:37:49 | 000,000,000 | โD | C] โ C:\ProgramData\OnlineArmor
[2013/01/03 15:33:15 | 000,000,000 | โD | C] โ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2013/01/03 15:33:14 | 000,031,768 | โ- | C] (Emsisoft) โ C:\windows\System32\drivers\OAnet.sys
[2013/01/03 15:33:14 | 000,027,648 | โ- | C] (Emsisoft) โ C:\windows\System32\drivers\OAmon.sys
[2013/01/03 15:33:10 | 000,000,000 | โD | C] โ C:\Program Files\Online Armor
[2013/01/03 15:19:04 | 000,040,776 | โ- | C] (Malwarebytes Corporation) โ C:\windows\System32\drivers\mbamswissarmy.sys
[2013/01/03 11:14:19 | 000,000,000 | โD | C] โ C:\Program Files\ESET
[2013/01/03 11:09:29 | 000,000,000 | โD | C] โ C:\Users\utente\Desktop\matita
[2013/01/03 01:01:26 | 000,000,000 | โD | C] โ C:\windows\ERDNT
[2013/01/03 00:46:04 | 000,000,000 | โD | C] โ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/03 00:46:02 | 000,021,104 | โ- | C] (Malwarebytes Corporation) โ C:\windows\System32\drivers\mbam.sys
[2013/01/03 00:46:02 | 000,000,000 | โD | C] โ C:\Program Files\Malwarebytes' Anti-Malware
[2012/12/30 18:32:26 | 000,000,000 | โD | C] โ C:\windows\ERUNT
[2012/12/30 18:32:07 | 000,000,000 | โD | C] โ C:\JRT
[2012/12/30 18:00:33 | 000,497,009 | โ- | C] (Oleg N. Scherbakov) โ C:\Users\utente\Desktop\JRT.exe
[2012/12/29 10:57:17 | 000,000,000 | โD | C] โ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/12/29 10:57:17 | 000,000,000 | โD | C] โ C:\Program Files\ERUNT
[2012/12/28 19:46:20 | 000,000,000 | โD | C] โ C:\Users\utente\Desktop\whatthetech
[2012/12/28 19:26:23 | 000,000,000 | โD | C] โ C:\Users\utente\AppData\Roaming\Anvisoft
[2012/12/28 19:24:57 | 000,000,000 | โD | C] โ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft
[2012/12/28 19:24:52 | 000,000,000 | โD | C] โ C:\ProgramData\Anvisoft
[2012/12/28 19:24:48 | 000,000,000 | โD | C] โ C:\Program Files\Anvisoft
[2012/12/28 18:59:27 | 000,000,000 | โD | C] โ C:\Program Files\Enigma Software Group
[2012/12/28 18:58:21 | 000,000,000 | โD | C] โ C:\Program Files\Common Files\Wise Installation Wizard
[2012/12/28 15:32:02 | 000,000,000 | โD | C] โ C:\ProgramData\XoftSpySE
[2012/12/28 11:51:08 | 000,000,000 | โD | C] โ C:\Users\utente\AppData\Roaming\Malwarebytes
[2012/12/28 11:50:44 | 000,000,000 | โD | C] โ C:\ProgramData\Malwarebytes
[2012/12/28 11:50:30 | 000,000,000 | โD | C] โ C:\Users\utente\AppData\Local\Programs
[2012/12/28 10:52:26 | 000,000,000 | โD | C] โ C:\Program Files\YouTube Downloader
[2012/12/28 10:51:31 | 000,000,000 | โD | C] โ C:\Users\utente\Desktop\november rain
[2012/12/28 10:05:10 | 000,000,000 | โD | C] โ C:\Users\utente\Desktop\SENE
[2012/12/19 22:59:34 | 000,000,000 | โD | C] โ C:\Users\utente\Desktop\Nuova cartella (2)
[2012/12/19 10:51:52 | 000,000,000 | โD | C] โ C:\Users\utente\Desktop\murrina
========== Files - Modified Within 30 Days ==========
[2013/01/06 23:10:02 | 000,000,978 | โ- | M] () โ C:\windows\tasks\Adobe Flash Player Updater.job
[2013/01/06 22:34:01 | 000,001,138 | โ- | M] () โ C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/06 21:47:18 | 000,000,436 | โ- | M] () โ C:\windows\tasks\12-28-2012_155302.job
[2013/01/06 21:47:02 | 000,067,584 | โS- | M] () โ C:\windows\bootstat.dat
[2013/01/06 15:40:07 | 000,001,134 | โ- | M] () โ C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/05 23:44:20 | 000,602,112 | โ- | M] (OldTimer Tools) โ C:\Users\utente\Desktop\OTL.exe
[2013/01/05 23:23:17 | 000,002,235 | โ- | M] () โ C:\Users\utente\Desktop\Google Chrome.lnk
[2013/01/04 18:39:30 | 000,020,944 | -Hโ | M] () โ C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/04 18:39:30 | 000,020,944 | -Hโ | M] () โ C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/03 15:49:53 | 000,327,680 | โ- | M] () โ C:\windows\System32\Ikeext.etl
[2013/01/03 15:49:22 | 2387,816,448 | -HS- | M] () โ C:\hiberfil.sys
[2013/01/03 15:19:04 | 000,040,776 | โ- | M] (Malwarebytes Corporation) โ C:\windows\System32\drivers\mbamswissarmy.sys
[2013/01/03 11:06:25 | 000,001,763 | โ- | M] () โ C:\Users\utente\Desktop\1497-1478-thickbox.jpg
[2013/01/03 11:05:03 | 000,006,470 | โ- | M] () โ C:\Users\utente\Desktop\1497-1478-large.jpg
[2013/01/03 00:46:04 | 000,001,067 | โ- | M] () โ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/31 10:51:18 | 001,435,522 | โ- | M] () โ C:\Users\utente\Desktop\Diffida INPS-6600-01-10-2012-0125753 Pagamento F24.jpg
[2012/12/31 10:50:02 | 000,714,449 | โ- | M] () โ C:\Users\utente\Desktop\Diffida INPS-6600-01-10-2012-0125753 Pagamento F24.pdf
[2012/12/30 20:22:45 | 000,701,426 | โ- | M] () โ C:\windows\System32\perfh010.dat
[2012/12/30 20:22:45 | 000,618,912 | โ- | M] () โ C:\windows\System32\perfh009.dat
[2012/12/30 20:22:45 | 000,128,740 | โ- | M] () โ C:\windows\System32\perfc010.dat
[2012/12/30 20:22:45 | 000,107,232 | โ- | M] () โ C:\windows\System32\perfc009.dat
[2012/12/30 18:29:59 | 000,497,009 | โ- | M] (Oleg N. Scherbakov) โ C:\Users\utente\Desktop\JRT.exe
[2012/12/30 17:58:01 | 000,325,312 | โ- | M] () โ C:\Users\utente\Desktop\Booking.com Extranet - -.pdf maughelli 31 dicembre.pdf
[2012/12/29 10:59:21 | 000,000,098 | โ- | M] () โ C:\windows\System32\drivers\etc\Hosts
[2012/12/29 10:57:18 | 000,000,894 | โ- | M] () โ C:\Users\utente\Desktop\NTREGOPT.lnk
[2012/12/29 10:57:18 | 000,000,875 | โ- | M] () โ C:\Users\utente\Desktop\ERUNT.lnk
[2012/12/28 23:44:24 | 000,000,512 | โ- | M] () โ C:\Users\utente\Desktop\MBR.dat
[2012/12/28 22:22:56 | 000,550,017 | โ- | M] () โ C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 19:00:12 | 000,000,000 | โ- | M] () โ C:\autoexec.bat
[2012/12/28 10:52:33 | 000,000,000 | โ- | M] () โ C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | โ- | M] () โ C:\mozilla.cfg
[2012/12/18 16:53:03 | 003,115,570 | โ- | M] () โ C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/17 12:34:42 | 000,000,326 | โ- | M] () โ C:\windows\tasks\HPCeeScheduleForutente.job
[2012/12/16 22:15:14 | 000,000,218 | โ- | M] () โ C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 16:49:28 | 000,021,104 | โ- | M] (Malwarebytes Corporation) โ C:\windows\System32\drivers\mbam.sys
[2012/12/14 11:36:47 | 000,271,046 | โ- | M] () โ C:\Users\utente\Desktop\collier.pdf
[2012/12/12 20:11:29 | 000,697,272 | โ- | M] (Adobe Systems Incorporated) โ C:\windows\System32\FlashPlayerApp.exe
[2012/12/12 20:11:29 | 000,073,656 | โ- | M] (Adobe Systems Incorporated) โ C:\windows\System32\FlashPlayerCPLApp.cpl
[2012/12/10 09:48:08 | 000,470,393 | โ- | M] () โ C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:28 | 001,040,996 | โ- | M] () โ C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:29 | 000,612,798 | โ- | M] () โ C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:11 | 000,219,495 | โ- | M] () โ C:\Users\utente\Desktop\versamenti ingegneria398.jpg
========== Files Created - No Company Name ==========
[2013/01/05 23:23:17 | 000,002,235 | โ- | C] () โ C:\Users\utente\Desktop\Google Chrome.lnk
[2013/01/03 15:33:14 | 000,208,320 | โ- | C] () โ C:\windows\System32\drivers\OADriver.sys
[2013/01/03 15:33:14 | 000,044,992 | โ- | C] () โ C:\windows\System32\drivers\oahlp32.sys
[2013/01/03 11:06:01 | 000,001,763 | โ- | C] () โ C:\Users\utente\Desktop\1497-1478-thickbox.jpg
[2013/01/03 11:04:58 | 000,006,470 | โ- | C] () โ C:\Users\utente\Desktop\1497-1478-large.jpg
[2013/01/03 00:46:04 | 000,001,067 | โ- | C] () โ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/31 10:51:17 | 001,435,522 | โ- | C] () โ C:\Users\utente\Desktop\Diffida INPS-6600-01-10-2012-0125753 Pagamento F24.jpg
[2012/12/31 10:50:02 | 000,714,449 | โ- | C] () โ C:\Users\utente\Desktop\Diffida INPS-6600-01-10-2012-0125753 Pagamento F24.pdf
[2012/12/30 17:57:49 | 000,325,312 | โ- | C] () โ C:\Users\utente\Desktop\Booking.com Extranet - -.pdf maughelli 31 dicembre.pdf
[2012/12/29 10:57:18 | 000,000,894 | โ- | C] () โ C:\Users\utente\Desktop\NTREGOPT.lnk
[2012/12/29 10:57:18 | 000,000,875 | โ- | C] () โ C:\Users\utente\Desktop\ERUNT.lnk
[2012/12/28 23:46:54 | 000,550,017 | โ- | C] () โ C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/28 23:44:24 | 000,000,512 | โ- | C] () โ C:\Users\utente\Desktop\MBR.dat
[2012/12/28 19:00:12 | 000,000,000 | โ- | C] () โ C:\autoexec.bat
[2012/12/28 15:53:02 | 000,000,436 | โ- | C] () โ C:\windows\tasks\12-28-2012_155302.job
[2012/12/28 10:52:33 | 000,000,000 | โ- | C] () โ C:\Users\utente\AppData\Local\Preferences
[2012/12/28 10:52:33 | 000,000,000 | โ- | C] () โ C:\mozilla.cfg
[2012/12/18 16:52:55 | 003,115,570 | โ- | C] () โ C:\Users\utente\Desktop\multa 2009 fallimento lolli 445.pdf
[2012/12/16 22:15:14 | 000,000,218 | โ- | C] () โ C:\Users\utente\AppData\Local\recently-used.xbel
[2012/12/14 11:36:43 | 000,271,046 | โ- | C] () โ C:\Users\utente\Desktop\collier.pdf
[2012/12/10 09:48:08 | 000,470,393 | โ- | C] () โ C:\Users\utente\Desktop\pagamento nic401.pdf
[2012/12/10 00:53:26 | 001,040,996 | โ- | C] () โ C:\Users\utente\Desktop\esami400.pdf
[2012/12/10 00:37:28 | 000,612,798 | โ- | C] () โ C:\Users\utente\Desktop\versamenti ingegneria399.pdf
[2012/12/10 00:36:10 | 000,219,495 | โ- | C] () โ C:\Users\utente\Desktop\versamenti ingegneria398.jpg
[2012/09/01 10:32:47 | 000,000,030 | โ- | C] () โ C:\windows\iedit_.INI
[2012/05/17 11:00:28 | 000,116,189 | โ- | C] () โ C:\windows\System32\drivers\klin.dat
[2012/05/17 11:00:28 | 000,098,168 | โ- | C] () โ C:\windows\System32\drivers\klick.dat
[2012/04/18 10:33:44 | 000,017,408 | โ- | C] () โ C:\Users\utente\AppData\Local\WebpageIcons.db
[2012/02/08 16:26:32 | 000,258,348 | โ- | C] () โ C:\Users\utente\AppData\Local\rx_image32.Cache
[2011/12/03 17:00:13 | 000,000,827 | โ- | C] () โ C:\windows\Brpfx04a.ini
[2011/12/03 17:00:13 | 000,000,161 | โ- | C] () โ C:\windows\brpcfx.ini
[2011/12/03 16:58:32 | 000,106,496 | โ- | C] () โ C:\windows\System32\BrMuSNMP.dll
[2011/12/03 16:52:17 | 000,000,420 | โ- | C] () โ C:\windows\BRWMARK.INI
[2011/12/03 16:52:17 | 000,000,065 | โ- | C] () โ C:\windows\System32\BD7820N.DAT
[2011/08/31 21:11:40 | 000,000,040 | -HS- | C] () โ C:\ProgramData\.zreglib
[2011/03/11 11:43:54 | 000,029,763 | โ- | C] () โ C:\windows\System32\drivers\klopp.dat
[2010/11/23 00:27:55 | 000,000,600 | โ- | C] () โ C:\Users\utente\AppData\Roaming\winscp.rnd
[2010/09/08 10:07:40 | 000,159,464 | Rโ | C] () โ C:\ProgramData\DeviceManager.xml.rc4
========== ZeroAccess Check ==========
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () โ C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll โ [2010/07/27 15:03:24 | 012,867,584 | โ- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll โ [2009/07/14 02:15:20 | 000,605,696 | โ- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll โ [2009/07/14 02:16:17 | 000,342,528 | โ- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2010/01/11 21:08:57 | 000,004,183 | โ- | M] () MD5=4CF10EA9BAB7750F41A7E154AECAF977 โ C:\Windows\PolicyDefinitions\it-IT\Explorer.adml
[2010/01/11 21:08:57 | 000,004,183 | โ- | M] () MD5=4CF10EA9BAB7750F41A7E154AECAF977 โ C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_it-it_af819edf95d3f553\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 22:34:46 | 000,003,836 | โ- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 โ C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 22:34:46 | 000,003,836 | โ- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 โ C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2009/10/06 07:06:36 | 002,613,248 | โ- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_523cdab8f40fe558\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | โ- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | โ- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | โ- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | โ- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | โ- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF โ C:\Windows\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | โ- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | โ- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | โ- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | โ- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | โ- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
[2009/10/06 06:53:03 | 002,613,248 | โ- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_51c00e6ddae85c4b\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2010/01/11 21:08:35 | 000,025,088 | โ- | M] (Microsoft Corporation) MD5=D871BB5958AEF9F493B330FCB533DE6B โ C:\Windows\it-IT\explorer.exe.mui
[2010/01/11 21:08:35 | 000,025,088 | โ- | M] (Microsoft Corporation) MD5=D871BB5958AEF9F493B330FCB533DE6B โ C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_it-it_9273a66a9f204dea\explorer.exe.mui
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/01/03 01:02:32 | 000,155,304 | โ- | M] () MD5=C97DA409A1F8909E135A43544A045F4D โ C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: EXPLORER.GIF >
[2002/08/24 16:39:32 | 000,000,144 | โ- | M] () MD5=C6F37D67EA0A5C873F4A9DE08913E4AD โ C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\postnuke\pn-0.7.2.1_Phoenix\html\modules\Stats\images\explorer.gif
< MD5 for: IEXPLORE.BAT >
[2012/12/15 19:52:46 | 000,024,911 | โ- | M] () MD5=93357EBDABCC46C66143D6DAAFDF4400 โ C:\JRT\iexplore.bat
< MD5 for: IEXPLORE.EXE >
[2010/09/08 05:36:39 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_b3c5cc459f4108f2\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | โ- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D โ C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/07/14 02:17:29 | 000,673,048 | โ- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2010/11/04 06:54:54 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_b3987f3a85deec23\iexplore.exe
[2010/09/08 05:31:24 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_b34dce2a8616cbea\iexplore.exe
[2010/11/04 06:54:59 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_b402ac8b9f13f917\iexplore.exe
[2010/12/18 06:32:25 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_b3e23cc79f2c4cea\iexplore.exe
[2010/12/18 06:33:54 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_b384dff685ed56b3\iexplore.exe
[2011/02/24 06:45:11 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 โ C:\Program Files\Internet Explorer\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | โ- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 โ C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2010/01/11 21:08:57 | 000,005,632 | โ- | M] (Microsoft Corporation) MD5=25762CE531381E3240DF74F039B5744F โ C:\Program Files\Internet Explorer\it-IT\iexplore.exe.mui
[2010/01/11 21:08:57 | 000,005,632 | โ- | M] (Microsoft Corporation) MD5=25762CE531381E3240DF74F039B5744F โ C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_it-it_399e585587f3842e\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2013/01/03 11:13:21 | 000,132,806 | โ- | M] () MD5=962087FB939EDF18F9F68B058B3CF57A โ C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf
< MD5 for: SERVICES >
[2009/06/10 22:39:37 | 000,017,463 | โ- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 โ C:\Windows\System32\drivers\etc\services
[2009/06/10 22:39:37 | 000,017,463 | โ- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 โ C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.DAT >
[2012/12/14 05:08:43 | 000,001,445 | โ- | M] () MD5=18134F4CA7DBCC5437D715A28E283D86 โ C:\JRT\services.dat
< MD5 for: SERVICES.EXE >
[2009/07/14 02:14:36 | 000,259,072 | โ- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 โ C:\Windows\System32\services.exe
[2009/07/14 02:14:36 | 000,259,072 | โ- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 โ C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2010/01/11 21:08:33 | 000,018,944 | โ- | M] (Microsoft Corporation) MD5=A655D2AC28162C1EB0080B2DC7B7ABC4 โ C:\Windows\System32\it-IT\services.exe.mui
[2010/01/11 21:08:33 | 000,018,944 | โ- | M] (Microsoft Corporation) MD5=A655D2AC28162C1EB0080B2DC7B7ABC4 โ C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_it-it_f67e66645173b0b7\services.exe.mui
< MD5 for: SERVICES.GIF >
[2002/10/06 19:00:53 | 000,001,497 | โ- | M] () MD5=7735A8919EB725BEE2C1F5412AEB1CBE โ C:\Users\utente\Documents\Documents\INGEGNERIA\Progetti\dedicated\aaa Cpanel Dedicated web hosting, website host, server, Atjeu LLC_file\services.gif
[2002/06/16 11:38:56 | 000,000,525 | โ- | M] () MD5=9AC87980AFE072913590D88B7B471820 โ C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\images\services.gif
[2002/09/30 18:34:20 | 000,000,255 | โ- | M] () MD5=C80515821C9CB1F4DCEA089CE3A0AF6F โ C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\status2final\images\services.gif
< MD5 for: SERVICES.INC >
[2002/06/15 17:07:00 | 000,000,358 | โ- | M] () MD5=8762E7C17EBF73171BBBC23C79A45235 โ C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\templates\services.inc
< MD5 for: SERVICES.LNK >
[2009/07/14 05:41:45 | 000,001,288 | โ- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 โ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 05:41:45 | 000,001,288 | โ- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 โ C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 22:26:14 | 000,002,866 | โ- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 โ C:\Windows\System32\wbem\services.mof
[2009/06/10 22:26:14 | 000,002,866 | โ- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 โ C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2010/01/11 21:08:32 | 000,092,755 | โ- | M] () MD5=1452B2812DA789ABB1998CB07F97524A โ C:\Windows\System32\it-IT\services.msc
[2010/01/11 21:08:32 | 000,092,755 | โ- | M] () MD5=1452B2812DA789ABB1998CB07F97524A โ C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_it-it_30c0365027dd4aaa\services.msc
[2009/06/10 22:21:09 | 000,092,745 | โ- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 โ C:\Windows\System32\services.msc
[2009/06/10 22:21:09 | 000,092,745 | โ- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 โ C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PNG >
[2008/03/27 04:57:28 | 000,003,334 | โ- | M] () MD5=5FF3A00670DE8D80ADA4BD034B55D154 โ C:\Program Files\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Red\services.png
[2008/03/27 04:38:18 | 000,003,827 | โ- | M] () MD5=BFC0958B73C61EE6C5EEA8D8C6073D26 โ C:\Program Files\CoffeeCup Software\CoffeeCup Free HTML Editor\Graphics\CoffeeCup Graphics Pack Samples\Blue\services.png
< MD5 for: SERVICES.PTXML >
[2009/07/13 21:20:01 | 000,001,061 | โ- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 โ C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 21:20:01 | 000,001,061 | โ- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 โ C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: SERVICES.RDB >
[2012/04/19 07:43:10 | 000,178,348 | โ- | M] () MD5=039C8CFBD74EE07F38CD9E4C7D95C5C6 โ C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2012/04/19 07:43:10 | 000,000,453 | โ- | M] () MD5=3D2ADA15FEF5B5FF468243161543D610 โ C:\Program Files\OpenOffice.org 3\program\services.rdb
[2012/04/13 05:55:44 | 000,008,060 | โ- | M] () MD5=7CA7D7150EC46321162F932ADCF5F35B โ C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb
< MD5 for: SERVICES.TXT >
[2002/06/16 19:14:16 | 000,000,033 | โ- | M] () MD5=5DFABC09BF8025F4EAE9ADD8B1EE9466 โ C:\Users\utente\Documents\Documents\INGEGNERIA\software installato\monitor\serverstats\upload\data\services.txt
< MD5 for: WINLOGON.ADML >
[2010/01/11 21:08:55 | 000,009,430 | โ- | M] () MD5=7A3DF5FA7925B53A60E9B3A0764A296B โ C:\Windows\PolicyDefinitions\it-IT\WinLogon.adml
[2010/01/11 21:08:55 | 000,009,430 | โ- | M] () MD5=7A3DF5FA7925B53A60E9B3A0764A296B โ C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_it-it_218530d508607cbf\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 22:43:18 | 000,005,237 | โ- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C โ C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 22:43:18 | 000,005,237 | โ- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C โ C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | โ- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D โ C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 07:17:59 | 000,285,696 | โ- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD โ C:\Windows\System32\winlogon.exe
[2009/10/28 07:17:59 | 000,285,696 | โ- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD โ C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 06:52:08 | 000,285,696 | โ- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 โ C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | โ- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF โ C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/01/11 21:08:32 | 000,024,064 | โ- | M] (Microsoft Corporation) MD5=10F25BD9440B0451952225BCAAB284E2 โ C:\Windows\System32\it-IT\winlogon.exe.mui
[2010/01/11 21:08:32 | 000,024,064 | โ- | M] (Microsoft Corporation) MD5=10F25BD9440B0451952225BCAAB284E2 โ C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_it-it_5779b0d82f94f530\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2010/01/11 21:08:33 | 000,001,080 | โ- | M] () MD5=B5CE50ECD88A87597DE1E8DE71AC2ADF โ C:\Windows\System32\wbem\it-IT\winlogon.mfl
[2010/01/11 21:08:33 | 000,001,080 | โ- | M] () MD5=B5CE50ECD88A87597DE1E8DE71AC2ADF โ C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_it-it_b53c02a34acd4ec5\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 21:37:34 | 000,003,192 | โ- | M] () MD5=DF722B96F32A61783BC310FACF10240B โ C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 21:37:34 | 000,003,192 | โ- | M] () MD5=DF722B96F32A61783BC310FACF10240B โ C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2012/12/28 23:48:02 | 000,013,690 | โ- | M] () โ C:\AdwCleaner[S1].txt
[2012/12/28 19:00:12 | 000,000,000 | โ- | M] () โ C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () โ C:\bootmgr
[2012/12/21 09:00:05 | 000,000,000 | โ- | M] () โ C:\ctapi_out_gr.txt
[2008/04/11 09:07:18 | 000,012,936 | โ- | M] () โ C:\eula.3082.txt
[2009/03/02 22:47:38 | 000,049,233 | โ- | M] () โ C:\fat32format.exe
[2008/04/11 09:07:18 | 000,001,110 | โ- | M] () โ C:\globdata.ini
[2013/01/03 15:49:22 | 2387,816,448 | -HS- | M] () โ C:\hiberfil.sys
[2008/04/11 07:03:48 | 000,562,688 | โ- | M] (Microsoft Corporation) โ C:\install.exe
[2008/04/11 09:07:18 | 000,000,843 | โ- | M] () โ C:\install.ini
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () โ C:\IO.SYS
[2012/12/28 10:52:33 | 000,000,000 | โ- | M] () โ C:\mozilla.cfg
[2010/08/22 19:33:57 | 000,000,000 | RHS- | M] () โ C:\MSDOS.SYS
[2013/01/03 15:49:27 | 3183,755,264 | -HS- | M] () โ C:\pagefile.sys
[2010/04/15 10:20:33 | 000,982,458 | โ- | M] () โ C:\Setup Log 2010-04-15 #001.txt
[2012/02/08 16:06:27 | 000,065,745 | โ- | M] () โ C:\testFindSector.log
[2009/10/19 23:43:50 | 000,047,104 | โ- | M] () โ C:\Thumbs.db
[2008/04/11 09:07:18 | 000,005,686 | โ- | M] () โ C:\vcredist.bmp
[2008/04/11 09:09:38 | 003,797,292 | โ- | M] () โ C:\VC_RED.cab
[2008/04/11 09:11:40 | 000,233,472 | โ- | M] () โ C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | โ- | M] () โ C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | โ- | M] () โ C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | โ- | M] () โ C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | โ- | M] () โ C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | -Hโ | M] () โ C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/17 04:23:20 | 000,019,968 | โ- | M] (Windows ยฎ 2000 DDK provider) โ C:\windows\system32\spool\prtprocs\w32x86\DELR1pc.dll
[2009/07/14 02:15:35 | 000,022,528 | โ- | M] (Microsoft Corporation) โ C:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 02:16:19 | 000,029,696 | โ- | M] (Microsoft Corporation) โ C:\windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | โ- | M] (Microsoft Corporation) โ C:\windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () โ C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/14 18:36:17 | 000,000,221 | -HS- | M] () โ C:\Users\utente\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/12/28 22:22:56 | 000,550,017 | โ- | M] () โ C:\Users\utente\Desktop\AdwCleaner.exe
[2012/12/30 18:29:59 | 000,497,009 | โ- | M] (Oleg N. Scherbakov) โ C:\Users\utente\Desktop\JRT.exe
[2013/01/05 23:44:20 | 000,602,112 | โ- | M] (OldTimer Tools) โ C:\Users\utente\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:FB1B13D8
< End of report >
I see that you have several extensions on Chrome again. I wonder if Youtube downloader is part of an installation that "comes along" with an extension you already downloaded? I am going to do some research and find out because it is only on your Chrome browser that I see it.I had already removed it with the previous chrome. I can't understand why it's back
I wonder if these are now part of the standard Google Chrome install? I will keep looking and see what I can come up with.CHR - Extension: Google Drive = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: WOT = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.3_0\
CHR - Extension: YouTube = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: YouTube Downloader = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocfnbdnkiipodbhenicdkamolggckhnl\3.0.0.0_0\
CHR - Extension: Gmail = C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
I removed the you tube downloader extension: I have no other extension available, excluding WOT
a really strange thing happened two days ago. But I can't remeber if it were before or after the reinstall of chrome: while openning chrome I saw in the bottom something like "โฆ connecting to https://fbfreegifts.com/ " but never happened again. I checked now in downloads history and found out that the file with virus, the you tube downloader extension I downloaded instead of the update of any audio converter is at this link hxxps://fbfreegifts.com/usersoftware/setupnew.exe
Run OTL.exe
- Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :Files C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocfnbdnkiipodbhenicdkamolggckhnl\3.0.0.0_0\YouTube Downloader-np.dll C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ C:\Users\utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocfnbdnkiipodbhenicdkamolggckhnl\3.0.0.0_0\ :Commands [emptytemp] [resethosts] [start explorer] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered. There will be a log created when it completes that I will need in your next reply. Reboot when it is done.
- Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Post the new OTL log and let me know how your system is running.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI