1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Generic host process error, problems with windows firewall

Discussion in 'Malware and Virus Removal Archive' started by geppoluc, 2011/05/16.

  1. 2011/05/16
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    [Resolved] Generic host process error, problems with windows firewall

    Hi guys,
    I am new to the forum and I think I need your help.
    My problem seems to be a common problem. I have looked at many postings and applied many suggested fixes with no results. I carefully read the posting rules and I will try to follow them as much as I can.

    Here is a description of the problem:

    The message "Generic Host Process for Win 32 services has encountered a problem and needs to close" comes up after several minutes of computer activity. Each time this message cause Sound Card, Firewall and other problems (the taskbar changes color). I also have some problems with windows update. If I go to the specified website, the browser gives me an error message saying that the server is not responding. I am not sure if this is a consequence of the problem I have or a consequence of all the mess I did trying to fix it. By the way I hope you ll be able to help me finding a solution.

    First of all, this is the log file of MBAM (unfortunately it's in Italian, but it seems to say that it did not find anything wrong):

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Versione database: 6587

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    16/05/2011 12.11.17
    mbam-log-2011-05-16 (12-11-17).txt

    Tipo di scansione: Scansione veloce
    Elementi esaminati: 178465
    Tempo trascorso: 6 minuti, 35 secondi

    Processi infetti in memoria: 0
    Moduli di memoria infetti: 0
    Chiavi di registro infette: 0
    Valori di registro infetti: 0
    Voci infette nei dati di registro: 0
    Cartelle infette: 0
    File infetti: 0

    Processi infetti in memoria:
    (Non sono stati rilevati elementi nocivi)

    Moduli di memoria infetti:
    (Non sono stati rilevati elementi nocivi)

    Chiavi di registro infette:
    (Non sono stati rilevati elementi nocivi)

    Valori di registro infetti:
    (Non sono stati rilevati elementi nocivi)

    Voci infette nei dati di registro:
    (Non sono stati rilevati elementi nocivi)

    Cartelle infette:
    (Non sono stati rilevati elementi nocivi)

    File infetti:
    (Non sono stati rilevati elementi nocivi)


    I did a complete scan of my system using both avira and Kaspersky and cleaned all they were able to find. But the problem persist.

    Now I will run GMER and post the results as soon as possible
     
  2. 2011/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard :)

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ===================================================

    Even, if you're Italian, please, don't format your logs in "italics ", because they're harder to read :)
     

  3. to hide this advert.

  4. 2011/05/16
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Thank you for your interest. I am trying to follow your guide step by step.

    I tried to run Gmer. It took a long time. For this reason I left (after three hours of scanning) the computer unattended. Now that I checked the results I discovered that the PC rebooted. I am not sure GMER finished the scan. For this reason I can not post the log file now. I need more time to run another scan

    PS I ll try to post my log files in english ;-)
     
  5. 2011/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Skip GMER for now...
     
  6. 2011/05/17
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Sorry, I read your suggestion too late. It's my office desktop and I was already gone home. So I'll skip to STEP 3 of your guide: MBR check.

    Here is the log file in english :D:

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000003d

    Kernel Drivers (total 128):
    0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
    0x806D2000 \WINDOWS\system32\hal.dll
    0x8A758000 \WINDOWS\system32\KDCOM.DLL
    0xBA4BC000 \WINDOWS\system32\BOOTVID.dll
    0xB9EB4000 sprh.sys
    0xBA5A8000 \WINDOWS\System32\Drivers\WMILIB.SYS
    0xB9E9C000 \WINDOWS\System32\Drivers\SCSIPORT.SYS
    0xB9E6E000 ACPI.sys
    0xB9E5D000 pci.sys
    0xBA0A8000 isapnp.sys
    0xBA670000 pciide.sys
    0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    0xBA0B8000 MountMgr.sys
    0xB9E3E000 ftdisk.sys
    0xBA5AA000 dmload.sys
    0xB9E18000 dmio.sys
    0xBA330000 PartMgr.sys
    0xBA0C8000 VolSnap.sys
    0xB9E00000 atapi.sys
    0xB9DE7000 nvata.sys
    0xBA0D8000 disk.sys
    0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xB9DC7000 fltmgr.sys
    0xB9DB5000 sr.sys
    0xB9D9E000 KSecDD.sys
    0xB9D8B000 WudfPf.sys
    0xB9CFE000 Ntfs.sys
    0xB9CD1000 NDIS.sys
    0xB9CB7000 Mup.sys
    0xBA118000 \SystemRoot\system32\DRIVERS\AmdK8.sys
    0xB8791000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
    0xB877D000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xB876C000 \SystemRoot\system32\DRIVERS\serial.sys
    0xB9516000 \SystemRoot\system32\DRIVERS\serenum.sys
    0xBA408000 \SystemRoot\system32\DRIVERS\fdc.sys
    0xB8758000 \SystemRoot\system32\DRIVERS\parport.sys
    0xB8B81000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0xBA410000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xBA418000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xBA420000 \SystemRoot\system32\DRIVERS\usbohci.sys
    0xB8734000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xBA428000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xB8B71000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xB8B61000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xB8B51000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xB8711000 \SystemRoot\system32\DRIVERS\ks.sys
    0xBA430000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    0xB8700000 \SystemRoot\system32\DRIVERS\el90xbc5.sys
    0xB86D8000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0xBA55C000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
    0xB868D000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
    0xB8656000 \SystemRoot\system32\DRIVERS\NVSNPU.SYS
    0xB861D000 \SystemRoot\System32\Drivers\ar57n1uk.SYS
    0xBA67E000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xBA608000 \SystemRoot\System32\Drivers\RootMdm.sys
    0xBA4A0000 \SystemRoot\System32\Drivers\Modem.SYS
    0xB8B41000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xBA56C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xB8606000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xB8B31000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xB8B21000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xBA4A8000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xB85F5000 \SystemRoot\system32\DRIVERS\psched.sys
    0xB8B11000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xBA4B0000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xBA338000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xB85C5000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xB8B01000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xBA60A000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xB8567000 \SystemRoot\system32\DRIVERS\update.sys
    0xBA588000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xBA278000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xADC31000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xBA66A000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xADC21000 \SystemRoot\system32\DRIVERS\NVENETFD.sys
    0xAB800000 \SystemRoot\system32\drivers\RtkHDAud.sys
    0xAB7DC000 \SystemRoot\system32\drivers\portcls.sys
    0xAD569000 \SystemRoot\system32\drivers\drmk.sys
    0xAD804000 \SystemRoot\system32\DRIVERS\flpydisk.sys
    0xBA66E000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xBA6CA000 \SystemRoot\System32\Drivers\Null.SYS
    0xBA5AE000 \SystemRoot\System32\Drivers\Beep.SYS
    0xAD7F4000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xAD7EC000 \SystemRoot\System32\drivers\vga.sys
    0xBA5B0000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xBA5B2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xAD7E4000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xAC8CA000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xB761F000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xAB709000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xAB6B0000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xAB688000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xAB666000 \SystemRoot\System32\drivers\afd.sys
    0xAD549000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xAC8C2000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
    0xAB63B000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xAB5A3000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xAD529000 \SystemRoot\System32\Drivers\Fips.SYS
    0xAB57D000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xB311A000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xAC504000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xA3F20000 \SystemRoot\system32\DRIVERS\avipbb.sys
    0xA5E8B000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0xA48C0000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xBA5BE000 \??\C:\Programmi\Avira\AntiVir Desktop\avgio.sys
    0xA48A0000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xA3F07000 \SystemRoot\System32\Drivers\dump_nvata.sys
    0xA69FF000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xA46FA000 \SystemRoot\System32\drivers\Dxapi.sys
    0xA4792000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xBA75D000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF3D8000 \SystemRoot\System32\ATMFD.DLL
    0xA35F2000 \SystemRoot\system32\DRIVERS\avgntflt.sys
    0xA46EE000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xA3575000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xBA636000 \SystemRoot\System32\Drivers\ParVdm.SYS
    0xA3455000 \SystemRoot\system32\DRIVERS\srv.sys
    0xB304A000 \SystemRoot\System32\Drivers\TDTCP.SYS
    0xA3252000 \SystemRoot\System32\Drivers\RDPWD.SYS
    0xA2E07000 \SystemRoot\system32\drivers\wdmaud.sys
    0xB37F5000 \SystemRoot\system32\drivers\sysaudio.sys
    0xA2C86000 \SystemRoot\System32\Drivers\HTTP.sys
    0xBFF60000 \SystemRoot\System32\RDPDD.dll
    0xBF012000 \SystemRoot\System32\nv4_disp.dll
    0x7C910000 \WINDOWS\system32\ntdll.dll
    0x10000000 \Programmi\DAEMON Tools Lite\Engine.dll

    Processes (total 55):
    0 System Idle Process
    4 System
    744 C:\WINDOWS\system32\smss.exe
    808 csrss.exe
    832 C:\WINDOWS\system32\winlogon.exe
    880 C:\WINDOWS\system32\services.exe
    900 C:\WINDOWS\system32\lsass.exe
    1072 C:\WINDOWS\system32\svchost.exe
    1140 svchost.exe
    1184 C:\WINDOWS\system32\svchost.exe
    1236 C:\WINDOWS\system32\svchost.exe
    1336 svchost.exe
    1412 svchost.exe
    1500 C:\WINDOWS\system32\spoolsv.exe
    1552 C:\Programmi\Avira\AntiVir Desktop\sched.exe
    1596 svchost.exe
    1664 C:\Programmi\Avira\AntiVir Desktop\avguard.exe
    1688 C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1716 svchost.exe
    1748 C:\Programmi\Avira\AntiVir Desktop\avshadow.exe
    1852 C:\Programmi\Java\jre6\bin\jqs.exe
    2000 C:\Programmi\NETGATE\Registry Cleaner\RegistryCleanerSrv.exe
    212 C:\WINDOWS\system32\nvsvc32.exe
    296 C:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
    332 C:\WINDOWS\system32\svchost.exe
    436 C:\Programmi\RealVNC\VNC4\winvnc4.exe
    536 C:\WINDOWS\system32\searchindexer.exe
    1372 alg.exe
    3944 C:\WINDOWS\explorer.exe
    4088 C:\WINDOWS\RTHDCPL.exe
    328 C:\WINDOWS\system32\rundll32.exe
    204 C:\WINDOWS\system32\rundll32.exe
    800 C:\Programmi\File comuni\Java\Java Update\jusched.exe
    1628 C:\Programmi\Scansoft\PaperPort\pptd40nt.exe
    1356 C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
    872 C:\WINDOWS\FixCamera.exe
    1368 C:\WINDOWS\vsnpstd3.exe
    2112 C:\WINDOWS\tsnpstd3.exe
    2216 C:\Programmi\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    2320 C:\Programmi\iTunes\iTunesHelper.exe
    2308 C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
    2368 C:\Programmi\DAEMON Tools Lite\DTLite.exe
    2236 C:\Programmi\NETGATE\Registry Cleaner\RegistryCleaner.exe
    2252 C:\WINDOWS\system32\ctfmon.exe
    2228 C:\Programmi\Skype\Phone\Skype.exe
    2556 C:\Programmi\Windows Desktop Search\WindowsSearch.exe
    2496 C:\Programmi\Widget vodafone.it\Widget vodafone.it.exe
    2752 C:\Programmi\iPod\bin\iPodService.exe
    220 csrss.exe
    3708 C:\WINDOWS\system32\winlogon.exe
    2704 C:\WINDOWS\system32\rdpclip.exe
    560 C:\Programmi\Mozilla Firefox\firefox.exe
    3984 C:\WINDOWS\system32\searchprotocolhost.exe
    2972 searchfilterhost.exe
    2400 C:\Documents and Settings\Mastrogiacom\Documenti\download\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

    PhysicalDrive0 Model Number: Maxtor6G160E0, Rev: KA101V00

    Size Device Name MBR Status
    --------------------------------------------
    149 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: 503FD2CC6F3632B90CEC9C763A09B1AF1755FCD5


    Done!
     
  7. 2011/05/17
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    DDS.txt

    Ok, going further with your guide i tryed to run dds script. I noticed a conflict with a Autocad that I solved uninstalling Autocad.

    Apart from that, while I was using firefox to read your guide a firefox page suddenly opened without clicking anywhere. If you want I can post the URL but I do not think it can be useful.

    These are all the problems I encountered today.

    Here follow the two log files generated by DDS.

    DDS.txt
    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Mastrogiacomo at 10.46.08.00 on 17/05/2011
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
    Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2031.869 [GMT 2:00]
    .
    AV: AntiVir Desktop *Disabled/Outdated* {0013F2B4-5C49-7C92-0300-000000000000}
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\Avira\AntiVir Desktop\sched.exe
    svchost.exe
    C:\Programmi\Avira\AntiVir Desktop\avguard.exe
    C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    svchost.exe
    C:\Programmi\Avira\AntiVir Desktop\avshadow.exe
    C:\Programmi\Java\jre6\bin\jqs.exe
    C:\Programmi\NETGATE\Registry Cleaner\RegistryCleanerSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Programmi\RealVNC\VNC4\WinVNC4.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Programmi\File comuni\Java\Java Update\jusched.exe
    C:\Programmi\Scansoft\PaperPort\pptd40nt.exe
    C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
    C:\WINDOWS\FixCamera.exe
    C:\WINDOWS\vsnpstd3.exe
    C:\WINDOWS\tsnpstd3.exe
    C:\Programmi\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
    C:\Programmi\iTunes\iTunesHelper.exe
    C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
    C:\Programmi\DAEMON Tools Lite\DTLite.exe
    C:\Programmi\NETGATE\Registry Cleaner\RegistryCleaner.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Skype\Phone\Skype.exe
    C:\Programmi\Windows Desktop Search\WindowsSearch.exe
    C:\Programmi\Widget vodafone.it\Widget vodafone.it.exe
    C:\Programmi\iPod\bin\iPodService.exe
    C:\Programmi\Windows NT\Accessori\WORDPAD.EXE
    C:\Programmi\Mozilla Firefox\firefox.exe
    C:\Programmi\Mozilla Firefox\plugin-container.exe
    C:\Programmi\Microsoft Office\Office12\OUTLOOK.EXE
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Documents and Settings\Mastrogiacom\Documenti\Download\dds.scr
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.it/
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\programmi\microsoft office\office12\GrooveShellExtensions.dll
    BHO: Guida per l'accesso a Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programmi\file comuni\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEFavClient.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmi\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmi\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEFavClient.dll
    TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\programmi\daemon tools toolbar\DTToolbar.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEFavClient.dll
    uRun: [DAEMON Tools Lite] "c:\programmi\daemon tools lite\DTLite.exe" -autorun
    uRun: [NETGATERegistryCleaner] c:\programmi\netgate\registry cleaner\RegistryCleaner.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Skype] "c:\programmi\skype\phone\Skype.exe" /nosplash /minimized
    uRun: [{B0032BBB-42EE-61FB-6366-9BE1CCA26BCF}] "c:\documents and settings\mastrogiacom\dati applicazioni\opag\utwu.exe "
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [SkyTel] SkyTel.EXE
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [nwiz] nwiz.exe /install
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    mRun: [SunJavaUpdateSched] "c:\programmi\file comuni\java\java update\jusched.exe "
    mRun: [PaperPort PTD] c:\programmi\scansoft\paperport\pptd40nt.exe
    mRun: [IndexSearch] c:\programmi\scansoft\paperport\IndexSearch.exe
    mRun: [GrooveMonitor] "c:\programmi\microsoft office\office12\GrooveMonitor.exe "
    mRun: [FixCamera] c:\windows\FixCamera.exe
    mRun: [snpstd3] c:\windows\vsnpstd3.exe
    mRun: [tsnpstd3] c:\windows\tsnpstd3.exe
    mRun: [Adobe Acrobat Speed Launcher] "c:\programmi\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe "
    mRun: [Acrobat Assistant 8.0] "c:\programmi\adobe\acrobat 9.0\acrobat\Acrotray.exe "
    mRun: [Adobe ARM] "c:\programmi\file comuni\adobe\arm\1.0\AdobeARM.exe "
    mRun: [QuickTime Task] "c:\programmi\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\programmi\itunes\iTunesHelper.exe "
    mRun: [avgnt] "c:\programmi\avira\antivir desktop\avgnt.exe" /min
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    StartupFolder: c:\docume~1\mastro~1\menuav~1\progra~1\esecuz~1\ritagl~1.lnk - c:\programmi\microsoft office\office12\ONENOTEM.EXE
    StartupFolder: c:\docume~1\mastro~1\menuav~1\progra~1\esecuz~1\widget~1.lnk - c:\programmi\widget vodafone.it\Widget vodafone.it.exe
    StartupFolder: c:\docume~1\alluse~1\menuav~1\progra~1\esecuz~1\window~1.lnk - c:\programmi\windows desktop search\WindowsSearch.exe
    IE: Append Link Target to Existing PDF - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&sporta in Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmi\messenger\msmsgs.exe
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
    DPF: {4819DFDF-ABC4-488C-A323-919848C51175}
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    TCP: {101FDF44-060D-4D30-83DF-4D0B289ACD21} = 130.192.3.21,130.192.3.24
    TCP: {51DB69B1-9045-4B51-8CBA-EAB917F96F78} = 130.192.3.21,130.192.3.24
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\programmi\microsoft office\office12\GrooveSystemServices.dll
    AppInit_DLLs: c:\windows\system32\acaptuser32.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\programmi\microsoft office\office12\GrooveShellExtensions.dll
    SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\programmi\windows desktop search\MSNLNamespaceMgr.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\docume~1\mastro~1\datiap~1\mozilla\firefox\profiles\g8lyo8ry.default\
    FF - plugin: c:\programmi\microsoft silverlight\4.0.60310.0\npctrlui.dll
    FF - plugin: c:\programmi\microsoft\office live\npOLW.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 avgio;avgio;c:\programmi\avira\antivir desktop\avgio.sys [2011-2-21 11608]
    R2 AntiVirScheduler;Avira AntiVir Scheduler;c:\programmi\avira\antivir desktop\sched.exe [2011-2-21 136360]
    R2 AntiVirService;Avira AntiVir Guard;c:\programmi\avira\antivir desktop\avguard.exe [2011-2-21 269480]
    R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-2-21 61960]
    R2 NGRegClnSrv;NETGATE Registry Cleaner Service;c:\programmi\netgate\registry cleaner\RegistryCleanerSrv.exe [2011-1-26 440912]
    S1 MpKsl4615eb98;MpKsl4615eb98;\??\c:\documents and settings\all users\dati applicazioni\microsoft\microsoft antimalware\definition updates\{e840dc17-e032-443a-a405-3becc643f14d}\mpksl4615eb98.sys --> c:\documents and settings\all users\dati applicazioni\microsoft\microsoft antimalware\definition updates\{e840dc17-e032-443a-a405-3becc643f14d}\MpKsl4615eb98.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.2.0;c:\windows\system32\drivers\libusb0.sys [2010-7-6 21504]
    S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2009-12-17 18432]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    S4 MSSQLServerADHelper100;Servizio SQL Server Active Directory Helper;c:\programmi\microsoft sql server\100\shared\sqladhlp.exe [2008-7-11 47128]
    S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
    S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\programmi\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-11 369688]
    .
    =============== Created Last 30 ================
    .
    2011-05-17 08:02:45 -------- d-----w- c:\docume~1\mastro~1\datiap~1\Opag
    2011-05-17 08:02:45 -------- d-----w- c:\docume~1\mastro~1\datiap~1\Onfiel
    2011-05-16 09:54:54 388096 ----a-r- c:\docume~1\mastro~1\datiap~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-05-16 09:54:53 -------- d-----w- c:\programmi\Trend Micro
    2011-05-16 08:59:26 112056 ----a-w- c:\windows\system32\acaptuser32.dll
    2011-05-12 12:55:53 98816 ----a-w- c:\windows\sed.exe
    2011-05-12 12:55:53 89088 ----a-w- c:\windows\MBR.exe
    2011-05-12 12:55:53 256512 ----a-w- c:\windows\PEV.exe
    2011-05-12 12:55:53 161792 ----a-w- c:\windows\SWREG.exe
    2011-05-12 12:34:08 222080 ------w- c:\windows\system32\MpSigStub.exe
    2011-05-12 08:24:27 -------- d-----w- c:\docume~1\mastro~1\datiap~1\DriverCure
    2011-05-12 08:24:25 -------- d-----w- c:\docume~1\mastro~1\datiap~1\ParetoLogic
    2011-05-12 08:24:09 -------- d-----w- c:\docume~1\alluse~1\datiap~1\ParetoLogic
    2011-05-11 10:18:33 -------- d-----w- c:\docume~1\mastro~1\datiap~1\Biwu
    2011-05-11 10:18:33 -------- d-----w- c:\docume~1\mastro~1\datiap~1\Awupme
    2011-05-09 09:26:45 -------- d-----w- c:\docume~1\mastro~1\datiap~1\Hyuzup
    2011-05-09 09:26:45 -------- d-----w- c:\docume~1\mastro~1\datiap~1\Booqyb
    2011-05-09 07:49:42 -------- d-----w- c:\docume~1\mastro~1\impost~1\datiap~1\Deployment
    2011-05-06 07:38:44 -------- d-----w- c:\docume~1\mastro~1\datiap~1\Otpiob
    2011-05-06 07:38:44 -------- d-----w- c:\docume~1\mastro~1\datiap~1\Opc
    2011-04-18 11:58:41 781272 ----a-w- c:\programmi\mozilla firefox\mozsqlite3.dll
    2011-04-18 11:58:40 89048 ----a-w- c:\programmi\mozilla firefox\libEGL.dll
    2011-04-18 11:58:40 465880 ----a-w- c:\programmi\mozilla firefox\libGLESv2.dll
    2011-04-18 11:58:40 1874904 ----a-w- c:\programmi\mozilla firefox\mozjs.dll
    2011-04-18 11:58:40 15832 ----a-w- c:\programmi\mozilla firefox\mozalloc.dll
    2011-04-18 11:58:39 1892184 ----a-w- c:\programmi\mozilla firefox\d3dx9_42.dll
    2011-04-18 11:58:38 1974616 ----a-w- c:\programmi\mozilla firefox\D3DCompiler_42.dll
    2011-04-18 11:58:38 142296 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
    .
    ==================== Find3M ====================
    .
    2011-03-07 05:33:45 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-04 06:36:21 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:53:31 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:05:47 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:05:47 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:05:47 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:42:13 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 12:54:06 5632 ----a-w- c:\windows\system32\xpsp4res.dll
    .
    =================== ROOTKIT ====================
    .
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: Maxtor_6G160E0 rev.KA101V00 -> Harddisk0\DR0 -> \Device\00000032
    .
    device: opened successfully
    user: MBR read successfully
    .
    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A66B730]<<
    _asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a671a10]; MOV EAX, [0x8a671a8c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
    1 ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\Harddisk0\DR0[0x8A764AB8]
    3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\0000006f[0x8A809570]
    5 ACPI[0xB9E74620] -> ntkrnlpa!IofCallDriver[0x804EE130] -> [0x8A764030]
    \Driver\nvata[0x8A731860] -> IRP_MJ_CREATE -> 0x8A66B730
    error: Read Funzione non corretta.
    kernel: MBR read successfully
    _asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
    detected disk devices:
    \Device\0000006e -> \??\IDE#DiskMaxtor_6G160E0__________________________KA101V00#3247483046394738202020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
    detected hooks:
    user & kernel MBR OK
    Warning: possible TDL3 rootkit infection !
    .
    ============= FINISH: 10.48.07.73 ===============
     
  8. 2011/05/17
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Here is the Attach.txt generated by DDS script:

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_11-03-05.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 25/03/2009 17.06.14
    System Uptime: 17/05/2011 9.18.30 (1 hours ago)
    .
    Motherboard: MSI | | MS-7252
    Processor: AMD Athlon(tm) 64 Processor 3500+ | CPU 1 | 2210/200mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 149 GiB total, 22.674 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
    Description: Mouse Microsoft PS/2
    Device ID: ACPI\PNP0F03\4&1A8C8C2E&0
    Manufacturer: Microsoft
    Name: Mouse Microsoft PS/2
    PNP Device ID: ACPI\PNP0F03\4&1A8C8C2E&0
    Service: i8042prt
    .
    Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
    Description: Nokia N70
    Device ID: ROOT\WPD\0000
    Manufacturer: Nokia
    Name: Nokia N70
    PNP Device ID: ROOT\WPD\0000
    Service: WUDFRd
    .
    ==== System Restore Points ===================
    .
    RP1: 12/05/2011 14.55.51 - Punto di arresto del sistema
    RP2: 13/05/2011 9.30.36 - Microsoft Office Outlook Connector installato
    RP3: 16/05/2011 11.54.53 - Installed HiJackThis
    RP4: 17/05/2011 10.15.10 - Autodesk CAD Manager Tools rimosso
    RP5: 17/05/2011 10.15.51 - Removed Autodesk Network License Manager
    .
    ==== Installed Programs ======================
    .
    Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
    Adobe Acrobat 9.4.4 - CPSID_83708
    Adobe AIR
    Adobe Community Help
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Media Player
    Aggiornamento critico per Windows Media Player 11 (KB959772)
    Aggiornamento della protezione per Windows Internet Explorer 7 (KB938127-v2)
    Aggiornamento della protezione per Windows Internet Explorer 7 (KB956390)
    Aggiornamento della protezione per Windows Internet Explorer 7 (KB961260)
    Aggiornamento della protezione per Windows Internet Explorer 7 (KB963027)
    Aggiornamento della protezione per Windows Internet Explorer 7 (KB969897)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB2183461)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB2360131)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB2416400)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB2482017)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB2497640)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB2510531)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB969897)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB971961)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB972260)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB974455)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB976325)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB978207)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB981332)
    Aggiornamento della protezione per Windows Internet Explorer 8 (KB982381)
    Aggiornamento della protezione per Windows Media Player (KB2378111)
    Aggiornamento della protezione per Windows Media Player (KB952069)
    Aggiornamento della protezione per Windows Media Player (KB954155)
    Aggiornamento della protezione per Windows Media Player (KB968816)
    Aggiornamento della protezione per Windows Media Player (KB973540)
    Aggiornamento della protezione per Windows Media Player (KB975558)
    Aggiornamento della protezione per Windows Media Player (KB978695)
    Aggiornamento della protezione per Windows Media Player 11 (KB936782)
    Aggiornamento della protezione per Windows Media Player 11 (KB954154)
    Aggiornamento della protezione per Windows XP (KB2079403)
    Aggiornamento della protezione per Windows XP (KB2115168)
    Aggiornamento della protezione per Windows XP (KB2121546)
    Aggiornamento della protezione per Windows XP (KB2160329)
    Aggiornamento della protezione per Windows XP (KB2229593)
    Aggiornamento della protezione per Windows XP (KB2259922)
    Aggiornamento della protezione per Windows XP (KB2279986)
    Aggiornamento della protezione per Windows XP (KB2286198)
    Aggiornamento della protezione per Windows XP (KB2296011)
    Aggiornamento della protezione per Windows XP (KB2296199)
    Aggiornamento della protezione per Windows XP (KB2347290)
    Aggiornamento della protezione per Windows XP (KB2360937)
    Aggiornamento della protezione per Windows XP (KB2387149)
    Aggiornamento della protezione per Windows XP (KB2393802)
    Aggiornamento della protezione per Windows XP (KB2412687)
    Aggiornamento della protezione per Windows XP (KB2419632)
    Aggiornamento della protezione per Windows XP (KB2423089)
    Aggiornamento della protezione per Windows XP (KB2436673)
    Aggiornamento della protezione per Windows XP (KB2440591)
    Aggiornamento della protezione per Windows XP (KB2443105)
    Aggiornamento della protezione per Windows XP (KB2476687)
    Aggiornamento della protezione per Windows XP (KB2478960)
    Aggiornamento della protezione per Windows XP (KB2478971)
    Aggiornamento della protezione per Windows XP (KB2479628)
    Aggiornamento della protezione per Windows XP (KB2479943)
    Aggiornamento della protezione per Windows XP (KB2481109)
    Aggiornamento della protezione per Windows XP (KB2483185)
    Aggiornamento della protezione per Windows XP (KB2485376)
    Aggiornamento della protezione per Windows XP (KB2485663)
    Aggiornamento della protezione per Windows XP (KB2503658)
    Aggiornamento della protezione per Windows XP (KB2506212)
    Aggiornamento della protezione per Windows XP (KB2506223)
    Aggiornamento della protezione per Windows XP (KB2507618)
    Aggiornamento della protezione per Windows XP (KB2508272)
    Aggiornamento della protezione per Windows XP (KB2508429)
    Aggiornamento della protezione per Windows XP (KB2509553)
    Aggiornamento della protezione per Windows XP (KB2511455)
    Aggiornamento della protezione per Windows XP (KB2524375)
    Aggiornamento della protezione per Windows XP (KB923561)
    Aggiornamento della protezione per Windows XP (KB923789)
    Aggiornamento della protezione per Windows XP (KB938464-v2)
    Aggiornamento della protezione per Windows XP (KB941569)
    Aggiornamento della protezione per Windows XP (KB946648)
    Aggiornamento della protezione per Windows XP (KB950760)
    Aggiornamento della protezione per Windows XP (KB950762)
    Aggiornamento della protezione per Windows XP (KB950974)
    Aggiornamento della protezione per Windows XP (KB951066)
    Aggiornamento della protezione per Windows XP (KB951376-v2)
    Aggiornamento della protezione per Windows XP (KB951698)
    Aggiornamento della protezione per Windows XP (KB951748)
    Aggiornamento della protezione per Windows XP (KB952004)
    Aggiornamento della protezione per Windows XP (KB952954)
    Aggiornamento della protezione per Windows XP (KB954459)
    Aggiornamento della protezione per Windows XP (KB954600)
    Aggiornamento della protezione per Windows XP (KB955069)
    Aggiornamento della protezione per Windows XP (KB956572)
    Aggiornamento della protezione per Windows XP (KB956744)
    Aggiornamento della protezione per Windows XP (KB956802)
    Aggiornamento della protezione per Windows XP (KB956803)
    Aggiornamento della protezione per Windows XP (KB956841)
    Aggiornamento della protezione per Windows XP (KB956844)
    Aggiornamento della protezione per Windows XP (KB957097)
    Aggiornamento della protezione per Windows XP (KB958215)
    Aggiornamento della protezione per Windows XP (KB958644)
    Aggiornamento della protezione per Windows XP (KB958687)
    Aggiornamento della protezione per Windows XP (KB958690)
    Aggiornamento della protezione per Windows XP (KB958869)
    Aggiornamento della protezione per Windows XP (KB959426)
    Aggiornamento della protezione per Windows XP (KB960225)
    Aggiornamento della protezione per Windows XP (KB960714)
    Aggiornamento della protezione per Windows XP (KB960715)
    Aggiornamento della protezione per Windows XP (KB960803)
    Aggiornamento della protezione per Windows XP (KB960859)
    Aggiornamento della protezione per Windows XP (KB961371)
    Aggiornamento della protezione per Windows XP (KB961373)
    Aggiornamento della protezione per Windows XP (KB961501)
    Aggiornamento della protezione per Windows XP (KB968537)
    Aggiornamento della protezione per Windows XP (KB969059)
    Aggiornamento della protezione per Windows XP (KB969898)
    Aggiornamento della protezione per Windows XP (KB969947)
    Aggiornamento della protezione per Windows XP (KB970238)
    Aggiornamento della protezione per Windows XP (KB970430)
    Aggiornamento della protezione per Windows XP (KB971468)
    Aggiornamento della protezione per Windows XP (KB971486)
    Aggiornamento della protezione per Windows XP (KB971557)
    Aggiornamento della protezione per Windows XP (KB971633)
    Aggiornamento della protezione per Windows XP (KB971657)
    Aggiornamento della protezione per Windows XP (KB972270)
    Aggiornamento della protezione per Windows XP (KB973346)
    Aggiornamento della protezione per Windows XP (KB973354)
    Aggiornamento della protezione per Windows XP (KB973507)
    Aggiornamento della protezione per Windows XP (KB973525)
    Aggiornamento della protezione per Windows XP (KB973869)
    Aggiornamento della protezione per Windows XP (KB973904)
    Aggiornamento della protezione per Windows XP (KB974112)
    Aggiornamento della protezione per Windows XP (KB974318)
    Aggiornamento della protezione per Windows XP (KB974392)
    Aggiornamento della protezione per Windows XP (KB974571)
    Aggiornamento della protezione per Windows XP (KB975025)
    Aggiornamento della protezione per Windows XP (KB975467)
    Aggiornamento della protezione per Windows XP (KB975560)
    Aggiornamento della protezione per Windows XP (KB975561)
    Aggiornamento della protezione per Windows XP (KB975562)
    Aggiornamento della protezione per Windows XP (KB975713)
    Aggiornamento della protezione per Windows XP (KB977165)
    Aggiornamento della protezione per Windows XP (KB977816)
    Aggiornamento della protezione per Windows XP (KB977914)
    Aggiornamento della protezione per Windows XP (KB978037)
    Aggiornamento della protezione per Windows XP (KB978251)
    Aggiornamento della protezione per Windows XP (KB978262)
    Aggiornamento della protezione per Windows XP (KB978338)
    Aggiornamento della protezione per Windows XP (KB978542)
    Aggiornamento della protezione per Windows XP (KB978601)
    Aggiornamento della protezione per Windows XP (KB978706)
    Aggiornamento della protezione per Windows XP (KB979309)
    Aggiornamento della protezione per Windows XP (KB979482)
    Aggiornamento della protezione per Windows XP (KB979559)
    Aggiornamento della protezione per Windows XP (KB979683)
    Aggiornamento della protezione per Windows XP (KB979687)
    Aggiornamento della protezione per Windows XP (KB980195)
    Aggiornamento della protezione per Windows XP (KB980218)
    Aggiornamento della protezione per Windows XP (KB980232)
    Aggiornamento della protezione per Windows XP (KB980436)
    Aggiornamento della protezione per Windows XP (KB981322)
    Aggiornamento della protezione per Windows XP (KB981852)
    Aggiornamento della protezione per Windows XP (KB981957)
    Aggiornamento della protezione per Windows XP (KB981997)
    Aggiornamento della protezione per Windows XP (KB982132)
    Aggiornamento della protezione per Windows XP (KB982214)
    Aggiornamento della protezione per Windows XP (KB982665)
    Aggiornamento della protezione per Windows XP (KB982802)
    Aggiornamento per Windows Internet Explorer 8 (KB971930)
    Aggiornamento per Windows Internet Explorer 8 (KB976662)
    Aggiornamento per Windows Internet Explorer 8 (KB976749)
    Aggiornamento per Windows Internet Explorer 8 (KB980182)
    Aggiornamento per Windows XP (KB2141007)
    Aggiornamento per Windows XP (KB2345886)
    Aggiornamento per Windows XP (KB2467659)
    Aggiornamento per Windows XP (KB951978)
    Aggiornamento per Windows XP (KB955759)
    Aggiornamento per Windows XP (KB955839)
    Aggiornamento per Windows XP (KB961503)
    Aggiornamento per Windows XP (KB967715)
    Aggiornamento per Windows XP (KB968389)
    Aggiornamento per Windows XP (KB971029)
    Aggiornamento per Windows XP (KB971737)
    Aggiornamento per Windows XP (KB973687)
    Aggiornamento per Windows XP (KB973815)
    Aggiornamento rapido per Windows Media Player 11 (KB939683)
    Aggiornamento rapido per Windows XP (KB2158563)
    Aggiornamento rapido per Windows XP (KB2443685)
    Aggiornamento rapido per Windows XP (KB942288-v3)
    Aggiornamento rapido per Windows XP (KB952287)
    Aggiornamento rapido per Windows XP (KB961118)
    Aggiornamento rapido per Windows XP (KB970653-v3)
    Aggiornamento rapido per Windows XP (KB976098-v2)
    Aggiornamento rapido per Windows XP (KB979306)
    Aggiornamento rapido per Windows XP (KB981793)
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Assistente per l'accesso a Windows Live
    Avira AntiVir Personal - Free Antivirus
    Compatibility Pack for the 2007 Office system
    Conviva LivePass
    DAEMON Tools Toolbar
    Dizionario Oxford-Paravia
    eMule
    Free Video Converter V 2.5
    Hama Webcam AC-150
    High Definition Audio Driver Package - KB888111
    HiJackThis
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB915800-v4)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB976002-v5)
    Hotfix per Microsoft Visual C# 2008 Express Edition SP1 - ITA (KB945282)
    Hotfix per Microsoft Visual C# 2008 Express Edition SP1 - ITA (KB946040)
    Hotfix per Microsoft Visual C# 2008 Express Edition SP1 - ITA (KB946308)
    Hotfix per Microsoft Visual C# 2008 Express Edition SP1 - ITA (KB947540)
    Hotfix per Microsoft Visual C# 2008 Express Edition SP1 - ITA (KB947789)
    HP Scanjet 4800 series 7.0
    hpg4850
    hpg4850QFolder
    iTunes
    Java 2 Runtime Environment, SE v1.4.2_04
    Java Auto Updater
    Java(TM) 6 Update 13
    JDownloader
    Junk Mail filter update
    Malwarebytes' Anti-Malware
    MathType 4
    MATLAB R2007a
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Italian Language Pack
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - ITA
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - ITA
    Microsoft .NET Framework 3.5 - Language Pack SP1 (italiano)
    Microsoft .NET Framework 3.5 Language Pack SP1 - ita
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Client Profile - Language Pack (ITA)
    Microsoft .NET Framework 4 Client Profile ITA Language Pack
    Microsoft .NET Framework 4 Extended
    Microsoft .NET Framework 4 Extended - Language Pack (ITA)
    Microsoft .NET Framework 4 Extended ITA Language Pack
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (Italian) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (Italian) 2007
    Microsoft Office Groove MUI (Italian) 2007
    Microsoft Office InfoPath MUI (Italian) 2007
    Microsoft Office Live Add-in 1.3
    Microsoft Office OneNote MUI (Italian) 2007
    Microsoft Office Outlook Connector
    Microsoft Office Outlook MUI (Italian) 2007
    Microsoft Office PowerPoint MUI (Italian) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (German) 2007
    Microsoft Office Proof (Italian) 2007
    Microsoft Office Proofing (Italian) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (Italian) 2007
    Microsoft Office Shared MUI (Italian) 2007
    Microsoft Office Word MUI (Italian) 2007
    Microsoft Silverlight
    Microsoft Software Update for Web Folders (Italian) 12
    Microsoft SQL Server 2008
    Microsoft SQL Server 2008 Browser
    Microsoft SQL Server 2008 Common Files
    Microsoft SQL Server 2008 Database Engine Services
    Microsoft SQL Server 2008 Database Engine Shared
    Microsoft SQL Server 2008 Management Objects
    Microsoft SQL Server 2008 Native Client
    Microsoft SQL Server 2008 RsFx Driver
    Microsoft SQL Server 2008 Setup Support Files (English)
    Microsoft SQL Server Compact 3.5 SP1 - Italiano
    Microsoft SQL Server Compact 3.5 SP1 Design Tools - Italiano
    Microsoft SQL Server VSS Writer
    Microsoft User-Mode Driver Framework Feature Pack 1.7
    Microsoft Visual C# 2008 Express Edition SP1 - ITA
    Microsoft Visual C# 2008 Express Edition with SP1 - ITA
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - ita
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
    Microsoft_VC80_CRT_x86
    Microsoft_VC80_MFC_x86
    Microsoft_VC80_MFCLOC_x86
    Microsoft_VC90_ATL_x86
    Microsoft_VC90_CRT_x86
    Microsoft_VC90_MFC_x86
    Mozilla Firefox 4.0.1 (x86 it)
    MSVC80_x86
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6.0 Parser (KB933579)
    Nero 6 Ultra Edition
    NETGATE Registry Cleaner
    Nokia Connectivity Cable Driver
    NVIDIA Drivers
    Pacchetto driver Windows - Hewlett-Packard Image (12/27/2006 8.0.0.0)
    PaperPort 8.0
    PC Connectivity Solution
    PDF-Creator with VDM Settings
    PSPad editor
    QuickTime
    Realtek High Definition Audio Driver
    Scan
    Security Update for 2007 Microsoft Office System (KB2288621)
    Security Update for 2007 Microsoft Office System (KB2288931)
    Security Update for 2007 Microsoft Office System (KB2345043)
    Security Update for 2007 Microsoft Office System (KB2466156)
    Security Update for 2007 Microsoft Office System (KB2509488)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
    Security Update for Microsoft Office Access 2007 (KB979440)
    Security Update for Microsoft Office Excel 2007 (KB2464583)
    Security Update for Microsoft Office Groove 2007 (KB2494047)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office PowerPoint 2007 (KB2464594)
    Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
    Security Update for Microsoft Office Publisher 2007 (KB2284697)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB2344993)
    Security Update for Windows Search 4 - KB963093
    Segoe UI
    Skype™ 5.3
    Sql Server Customer Experience Improvement Program
    SQL Server System CLR Types
    Strumento di caricamento di Windows Live
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office OneNote 2007 (KB980729)
    Update for Microsoft Office Outlook 2007 (KB2509470)
    Update for Outlook 2007 Junk Email Filter (KB2522999)
    Utilità di attivazione licenze di rete AutoCAD 2009
    VBA (2627.01)
    VBA (2627.3)
    VLC media player 0.9.9
    VNC Free Edition 4.1.3
    WebFldrs XP
    WebReg
    Widget vodafone.it
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player Firefox Plugin
    Windows Search 4.0
    Windows XP Service Pack 3
    WinRAR gestione archivi
    WinSCP 4.0.5
    XML Paper Specification Shared Components Language Pack 1.0
    .
    ==== End Of File ===========================
     
  9. 2011/05/17
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    I see you have P2P software ( Azures, Limewire, BitTorrent, uTorrent etc…) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here, and here.

    I would strongly recommend that you uninstall them, and read the links above for educational value!

    Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at WindowsBBS Malware and Virus removal.

    A Malware expert will have a look at your log in due course.
     
  10. 2011/05/17
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    I promptly uninstalled eMule (which is a long time since I do not use).
    thanks for the suggestion

    Should I now try to run GMER?
    I'll wait your approval
     
    Last edited: 2011/05/17
  11. 2011/05/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No, no GMER.
    We have a possible rootkit here.

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  12. 2011/05/18
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Ok, I ran TDSSKiller and this is the log file:

    2011/05/18 12:56:52.0895 4248 TDSS rootkit removing tool 2.5.1.0 May 13 2011 13:20:29
    2011/05/18 12:56:52.0957 4248 ================================================================================
    2011/05/18 12:56:52.0957 4248 SystemInfo:
    2011/05/18 12:56:52.0957 4248
    2011/05/18 12:56:52.0957 4248 OS Version: 5.1.2600 ServicePack: 3.0
    2011/05/18 12:56:52.0957 4248 Product type: Workstation
    2011/05/18 12:56:52.0957 4248 ComputerName: MASTROGIACOMO
    2011/05/18 12:56:52.0957 4248 UserName: Mastrogiacomo
    2011/05/18 12:56:52.0957 4248 Windows directory: C:\WINDOWS
    2011/05/18 12:56:52.0957 4248 System windows directory: C:\WINDOWS
    2011/05/18 12:56:52.0957 4248 Processor architecture: Intel x86
    2011/05/18 12:56:52.0957 4248 Number of processors: 1
    2011/05/18 12:56:52.0957 4248 Page size: 0x1000
    2011/05/18 12:56:52.0957 4248 Boot type: Normal boot
    2011/05/18 12:56:52.0957 4248 ================================================================================
    2011/05/18 12:56:53.0207 4248 Initialize success
    2011/05/18 12:56:56.0754 4688 ================================================================================
    2011/05/18 12:56:56.0754 4688 Scan started
    2011/05/18 12:56:56.0754 4688 Mode: Manual;
    2011/05/18 12:56:56.0754 4688 ================================================================================
    2011/05/18 12:56:57.0348 4688 ACPI (d766e636187b8f240bbfbabcd51eb2c6) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    2011/05/18 12:56:57.0473 4688 ACPIEC (49ac5cd87fbdda62f3e25190019e7627) C:\WINDOWS\system32\drivers\ACPIEC.sys
    2011/05/18 12:56:57.0567 4688 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    2011/05/18 12:56:57.0723 4688 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys
    2011/05/18 12:56:58.0020 4688 AmdK8 (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
    2011/05/18 12:56:58.0270 4688 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    2011/05/18 12:56:58.0379 4688 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    2011/05/18 12:56:58.0473 4688 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    2011/05/18 12:56:58.0660 4688 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    2011/05/18 12:56:58.0738 4688 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Programmi\Avira\AntiVir Desktop\avgio.sys
    2011/05/18 12:56:58.0863 4688 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
    2011/05/18 12:56:58.0942 4688 avipbb (5fedef54757b34fb611b9ec8fb399364) C:\WINDOWS\system32\DRIVERS\avipbb.sys
    2011/05/18 12:56:59.0004 4688 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    2011/05/18 12:56:59.0192 4688 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
    2011/05/18 12:56:59.0254 4688 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
    2011/05/18 12:56:59.0348 4688 BTHPORT (ad0da527dec931c85647cb265ceda13d) C:\WINDOWS\system32\Drivers\BTHport.sys
    2011/05/18 12:56:59.0488 4688 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
    2011/05/18 12:56:59.0973 4688 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    2011/05/18 12:57:00.0098 4688 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
    2011/05/18 12:57:00.0207 4688 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    2011/05/18 12:57:00.0301 4688 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    2011/05/18 12:57:00.0363 4688 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    2011/05/18 12:57:00.0832 4688 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    2011/05/18 12:57:00.0973 4688 dmboot (82bc125a8ed33f5f0e75f2aac1065323) C:\WINDOWS\system32\drivers\dmboot.sys
    2011/05/18 12:57:01.0176 4688 dmio (e959ddc0ea7ac11ee5e5602e2a364310) C:\WINDOWS\system32\drivers\dmio.sys
    2011/05/18 12:57:01.0285 4688 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    2011/05/18 12:57:01.0348 4688 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    2011/05/18 12:57:01.0473 4688 Dot4 (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
    2011/05/18 12:57:01.0551 4688 Dot4Print (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
    2011/05/18 12:57:01.0692 4688 dot4usb (707e8402ecaf9c87a7dd15615f0cfea2) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
    2011/05/18 12:57:01.0832 4688 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    2011/05/18 12:57:01.0973 4688 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
    2011/05/18 12:57:02.0113 4688 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    2011/05/18 12:57:02.0192 4688 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    2011/05/18 12:57:02.0317 4688 Fips (2cfea3326981a18c6baf2bd9be76225b) C:\WINDOWS\system32\drivers\Fips.sys
    2011/05/18 12:57:02.0379 4688 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    2011/05/18 12:57:02.0488 4688 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    2011/05/18 12:57:02.0551 4688 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    2011/05/18 12:57:02.0676 4688 Ftdisk (f3269a6ee547ea87b949a1cea4816b38) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    2011/05/18 12:57:02.0754 4688 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
    2011/05/18 12:57:02.0879 4688 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    2011/05/18 12:57:02.0988 4688 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
    2011/05/18 12:57:03.0113 4688 HidBth (a330f15b4f438c1998f57db753cf7455) C:\WINDOWS\system32\DRIVERS\hidbth.sys
    2011/05/18 12:57:03.0238 4688 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    2011/05/18 12:57:03.0379 4688 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
    2011/05/18 12:57:03.0598 4688 i8042prt (610726e28af55b95043c5c35a727e320) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    2011/05/18 12:57:03.0676 4688 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    2011/05/18 12:57:03.0988 4688 IntcAzAudAddService (fa9a9468f982835e99c1ec21257f7e60) C:\WINDOWS\system32\drivers\RtkHDAud.sys
    2011/05/18 12:57:04.0270 4688 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    2011/05/18 12:57:04.0363 4688 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    2011/05/18 12:57:04.0473 4688 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    2011/05/18 12:57:04.0520 4688 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    2011/05/18 12:57:04.0676 4688 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    2011/05/18 12:57:04.0738 4688 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    2011/05/18 12:57:04.0832 4688 isapnp (0953594beb81cc72fcc62d37921b25a6) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    2011/05/18 12:57:04.0942 4688 Kbdclass (28b6eace513ca7eaba3b809ad4bc274d) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    2011/05/18 12:57:05.0004 4688 kbdhid (4c61c226bdda2ef1672b2c5f4e56625e) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
    2011/05/18 12:57:05.0176 4688 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    2011/05/18 12:57:05.0301 4688 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
    2011/05/18 12:57:05.0504 4688 libusb0 (9ca5457634090eb1f2923f40eac4b6df) C:\WINDOWS\system32\DRIVERS\libusb0.sys
    2011/05/18 12:57:05.0629 4688 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    2011/05/18 12:57:05.0692 4688 Modem (8cb6636806d76b85fafaee94d75f5129) C:\WINDOWS\system32\drivers\Modem.sys
    2011/05/18 12:57:05.0770 4688 Mouclass (e904ebed608055a2bfb824c07f59766c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    2011/05/18 12:57:05.0863 4688 mouhid (d7662f0cf5b77bbbe3202716f5bd5318) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    2011/05/18 12:57:05.0973 4688 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    2011/05/18 12:57:06.0098 4688 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    2011/05/18 12:57:06.0160 4688 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    2011/05/18 12:57:06.0285 4688 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    2011/05/18 12:57:06.0379 4688 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    2011/05/18 12:57:06.0457 4688 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2011/05/18 12:57:06.0520 4688 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    2011/05/18 12:57:06.0645 4688 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    2011/05/18 12:57:06.0738 4688 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
    2011/05/18 12:57:06.0879 4688 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
    2011/05/18 12:57:06.0957 4688 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
    2011/05/18 12:57:07.0113 4688 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    2011/05/18 12:57:07.0192 4688 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
    2011/05/18 12:57:07.0301 4688 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    2011/05/18 12:57:07.0348 4688 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    2011/05/18 12:57:07.0488 4688 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    2011/05/18 12:57:07.0551 4688 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
    2011/05/18 12:57:07.0676 4688 Netaapl (7afd0e39ab15cb355487b7cc19f4e2c5) C:\WINDOWS\system32\DRIVERS\netaapl.sys
    2011/05/18 12:57:07.0770 4688 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    2011/05/18 12:57:07.0879 4688 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2011/05/18 12:57:08.0020 4688 nmwcd (4a8a2aa0706b659175169decf198e9d7) C:\WINDOWS\system32\drivers\ccdcmb.sys
    2011/05/18 12:57:08.0270 4688 nmwcdc (fd3e61831095ac62e6840d986b5a2016) C:\WINDOWS\system32\drivers\ccdcmbo.sys
    2011/05/18 12:57:08.0379 4688 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    2011/05/18 12:57:08.0442 4688 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    2011/05/18 12:57:08.0551 4688 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    2011/05/18 12:57:08.0738 4688 nv (ce58f42b11be20a47c3d8d2f38da254e) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    2011/05/18 12:57:09.0035 4688 nvata (c03e15101f6d9e82cd9b0e7d715f5de3) C:\WINDOWS\system32\DRIVERS\nvata.sys
    2011/05/18 12:57:09.0098 4688 NVENETFD (b9333604527e02cd2223f200c0bae7e0) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
    2011/05/18 12:57:09.0176 4688 nvnetbus (5e9e55f7ee644c7c5fd78a206fbe37ab) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
    2011/05/18 12:57:09.0285 4688 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    2011/05/18 12:57:09.0348 4688 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    2011/05/18 12:57:09.0488 4688 Parport (4e9408a178b2d955871c2cdd278de3c3) C:\WINDOWS\system32\DRIVERS\parport.sys
    2011/05/18 12:57:09.0551 4688 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    2011/05/18 12:57:09.0645 4688 ParVdm (0dabef655a444cb1e193626fb1d24b9f) C:\WINDOWS\system32\drivers\ParVdm.sys
    2011/05/18 12:57:09.0738 4688 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
    2011/05/18 12:57:09.0863 4688 PCI (f40a46892afebb0314536b849d57c11e) C:\WINDOWS\system32\DRIVERS\pci.sys
    2011/05/18 12:57:09.0957 4688 PCIIde (b2df00d650fd6c4ee781740ed3c8e67f) C:\WINDOWS\system32\DRIVERS\pciide.sys
    2011/05/18 12:57:10.0051 4688 Pcmcia (815c50f2b1d1562800bdce8be895000e) C:\WINDOWS\system32\drivers\Pcmcia.sys
    2011/05/18 12:57:10.0426 4688 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    2011/05/18 12:57:10.0520 4688 Processor (b479f50e883b2297a5f7f212aaee6f6c) C:\WINDOWS\system32\DRIVERS\processr.sys
    2011/05/18 12:57:10.0613 4688 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    2011/05/18 12:57:10.0707 4688 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    2011/05/18 12:57:10.0988 4688 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    2011/05/18 12:57:11.0129 4688 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    2011/05/18 12:57:11.0238 4688 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    2011/05/18 12:57:11.0285 4688 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    2011/05/18 12:57:11.0395 4688 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    2011/05/18 12:57:11.0457 4688 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    2011/05/18 12:57:11.0504 4688 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    2011/05/18 12:57:11.0676 4688 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
    2011/05/18 12:57:11.0738 4688 redbook (393fc252593323b624b230eca6b85e63) C:\WINDOWS\system32\DRIVERS\redbook.sys
    2011/05/18 12:57:11.0926 4688 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
    2011/05/18 12:57:12.0020 4688 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
    2011/05/18 12:57:12.0129 4688 RsFx0102 (fedd2710b75be3ecf078adace790c423) C:\WINDOWS\system32\DRIVERS\RsFx0102.sys
    2011/05/18 12:57:12.0301 4688 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    2011/05/18 12:57:12.0363 4688 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    2011/05/18 12:57:12.0395 4688 Serial (fdbd9d64e2e03270021d424f0dccf79d) C:\WINDOWS\system32\DRIVERS\serial.sys
    2011/05/18 12:57:12.0535 4688 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    2011/05/18 12:57:12.0692 4688 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
    2011/05/18 12:57:13.0176 4688 SNPSTD3 (9c2475cf197f538555b6d9beeadec0a6) C:\WINDOWS\system32\DRIVERS\snpstd3.sys
    2011/05/18 12:57:13.0629 4688 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    2011/05/18 12:57:13.0723 4688 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
    2011/05/18 12:57:13.0723 4688 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
    2011/05/18 12:57:13.0723 4688 sptd - detected LockedFile.Multi.Generic (1)
    2011/05/18 12:57:13.0863 4688 sr (618718cae288bf7cbd8fcbab2577d932) C:\WINDOWS\system32\DRIVERS\sr.sys
    2011/05/18 12:57:13.0926 4688 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
    2011/05/18 12:57:14.0051 4688 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
    2011/05/18 12:57:14.0207 4688 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
    2011/05/18 12:57:14.0301 4688 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    2011/05/18 12:57:14.0363 4688 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    2011/05/18 12:57:14.0645 4688 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    2011/05/18 12:57:14.0770 4688 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    2011/05/18 12:57:14.0957 4688 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    2011/05/18 12:57:15.0035 4688 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    2011/05/18 12:57:15.0145 4688 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    2011/05/18 12:57:15.0598 4688 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    2011/05/18 12:57:15.0785 4688 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    2011/05/18 12:57:15.0942 4688 upperdev (587e643a4e2ffd9a00f114b057ceb773) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
    2011/05/18 12:57:16.0082 4688 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\WINDOWS\system32\Drivers\usbaapl.sys
    2011/05/18 12:57:16.0160 4688 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    2011/05/18 12:57:16.0270 4688 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    2011/05/18 12:57:16.0395 4688 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    2011/05/18 12:57:16.0473 4688 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
    2011/05/18 12:57:16.0582 4688 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    2011/05/18 12:57:16.0676 4688 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\DRIVERS\usbser.sys
    2011/05/18 12:57:16.0770 4688 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    2011/05/18 12:57:16.0895 4688 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
    2011/05/18 12:57:17.0004 4688 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    2011/05/18 12:57:17.0145 4688 VolSnap (e46c1b5a56da7da603d09dfcc79ec59e) C:\WINDOWS\system32\drivers\VolSnap.sys
    2011/05/18 12:57:17.0238 4688 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    2011/05/18 12:57:17.0363 4688 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
    2011/05/18 12:57:17.0551 4688 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    2011/05/18 12:57:17.0770 4688 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
    2011/05/18 12:57:17.0895 4688 WudfPf (6ff66513d372d479ef1810223c8d20ce) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    2011/05/18 12:57:17.0942 4688 WudfRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    2011/05/18 12:57:18.0035 4688 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
    2011/05/18 12:57:18.0035 4688 ================================================================================
    2011/05/18 12:57:18.0035 4688 Scan finished
    2011/05/18 12:57:18.0035 4688 ================================================================================
    2011/05/18 12:57:18.0051 3336 Detected object count: 2
    2011/05/18 12:57:47.0910 3336 LockedFile.Multi.Generic(sptd) - User select action: Skip
    2011/05/18 12:57:47.0926 3336 \HardDisk0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
    2011/05/18 12:57:47.0926 3336 \HardDisk0 - ok
    2011/05/18 12:57:47.0926 3336 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
    2011/05/18 12:57:58.0582 5568 Deinitialize success
     
  13. 2011/05/18
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Ok, after the rootkit cure the PC seems to work better. At least I am now able to update windows !! :D

    After more than 6 hour I had no "generic host process" errors.
    I do not know if the problem is solved but it seems to be.
    I am running a Malwarebytes' Anti-Malware scan.
    I'll keep you updated
     
    Last edited: 2011/05/18
  14. 2011/05/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good news :)

    We'll run couple more checks to make sure, all bad guys are dead.

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  15. 2011/05/19
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Ok, I already have a copy of combofix but I will download a new one and run it following your instructions.
     
    Last edited: 2011/05/19
  16. 2011/05/19
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Ok, I ran Combofix and the PC did not reboot...good, isn't it?
    Here is the log file (unfortunately the logic is still in italian but quite understandable in my opinion, if you have any problem I can translate or run it again changing some settings):
    ComboFix 11-05-18.03 - Mastrogiacomo 19/05/2011 12.07.16.3.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2031.1559 [GMT 2:00]
    Eseguito da: c:\documents and settings\Mastrogiacom\Desktop\ComboFix.exe
    AV: AntiVir Desktop *Disabled/Outdated* {0013F2B4-5C49-7C92-0300-000000000000}
    .
    .
    ((((((((((((((((((((((((( Files Creati Da 2011-04-19 al 2011-05-19 )))))))))))))))))))))))))))))))))))
    .
    .
    2011-05-17 08:02 . 2011-05-18 13:22 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\Opag
    2011-05-17 08:02 . 2011-05-18 13:14 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\Onfiel
    2011-05-16 09:54 . 2011-05-16 09:54 388096 ----a-r- c:\documents and settings\Mastrogiacom\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2011-05-16 09:54 . 2011-05-16 09:54 -------- d-----w- c:\programmi\Trend Micro
    2011-05-16 08:59 . 2010-09-22 16:47 112056 ----a-w- c:\windows\system32\acaptuser32.dll
    2011-05-12 12:34 . 2011-02-02 16:11 222080 ------w- c:\windows\system32\MpSigStub.exe
    2011-05-12 08:24 . 2011-05-12 08:24 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\DriverCure
    2011-05-12 08:24 . 2011-05-12 08:24 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\ParetoLogic
    2011-05-12 08:24 . 2011-05-12 09:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ParetoLogic
    2011-05-11 10:18 . 2011-05-11 12:24 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\Biwu
    2011-05-11 10:18 . 2011-05-11 12:19 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\Awupme
    2011-05-09 22:51 . 2011-05-09 22:51 -------- d-s---w- c:\documents and settings\LocalService\Documenti
    2011-05-09 19:38 . 2011-05-09 19:38 -------- d-s---w- c:\documents and settings\LocalService\Preferiti
    2011-05-09 09:26 . 2011-05-09 12:46 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\Hyuzup
    2011-05-09 09:26 . 2011-05-09 12:12 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\Booqyb
    2011-05-09 07:49 . 2011-05-09 07:50 -------- d-----w- c:\documents and settings\Mastrogiacom\Impostazioni locali\Dati applicazioni\Deployment
    2011-05-06 07:38 . 2011-05-09 12:46 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\Otpiob
    2011-05-06 07:38 . 2011-05-09 09:28 -------- d-----w- c:\documents and settings\Mastrogiacom\Dati applicazioni\Opc
    2011-05-04 14:06 . 2011-05-04 14:06 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Identities
    2011-05-04 14:06 . 2011-05-04 14:06 -------- d-----w- c:\documents and settings\NetworkService\Dati applicazioni\Windows Desktop Search
    2011-05-04 14:06 . 2011-05-04 14:06 -------- d-----w- c:\documents and settings\NetworkService\Dati applicazioni\Apple Computer
    2011-05-04 14:05 . 2011-05-04 14:05 -------- d-----w- c:\documents and settings\NetworkService\Menu Avvio
    2011-05-04 05:41 . 2011-05-04 14:05 -------- d-s---w- c:\documents and settings\NetworkService\Documenti
    2011-05-04 05:40 . 2011-05-04 05:41 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Adobe
    2011-05-03 12:36 . 2011-05-04 14:06 -------- d-s---w- c:\documents and settings\NetworkService\Preferiti
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-04-04 07:30 . 2011-02-21 16:54 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
    2011-03-07 05:33 . 2009-03-25 16:01 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-04 06:36 . 2004-08-19 12:00 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:53 . 2004-08-19 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:05 . 2004-08-19 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:05 . 2004-08-19 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:05 . 2004-08-19 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:42 . 2004-08-19 12:00 385024 ----a-w- c:\windows\system32\html.iec
    2011-04-29 15:27 . 2011-04-18 11:58 142296 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-05-13_09.32.49 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2011-01-11 08:59 . 2011-01-11 08:59 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_214ee422\vcomp90.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90rus.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90kor.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90jpn.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90ita.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90fra.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esp.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90esn.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90enu.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90deu.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90cht.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_467ea28b\mfc90chs.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90u.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfcm90.dll
    + 2011-01-10 21:03 . 2011-01-10 21:03 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_189d6662\vcomp.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80KOR.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80JPN.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80ITA.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80FRA.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80ESP.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80ENU.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80DEU.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80CHT.dll
    + 2011-01-10 20:32 . 2011-01-10 20:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80CHS.dll
    + 2011-01-11 02:05 . 2011-01-11 02:05 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\mfcm80u.dll
    + 2011-01-11 02:23 . 2011-01-11 02:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\mfcm80.dll
    + 2011-01-10 19:21 . 2011-01-10 19:21 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_7837863c\ATL80.dll
    + 2011-05-19 08:20 . 2011-05-19 08:20 16384 c:\windows\Temp\Perflib_Perfdata_1a4.dat
    - 2011-04-15 07:02 . 2011-04-15 07:02 25214 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Distiller.exe
    + 2011-04-15 07:02 . 2011-05-16 09:01 25214 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Distiller.exe
    - 2011-04-15 07:02 . 2011-04-15 07:02 36294 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Acrobat_Standard.exe
    + 2011-04-15 07:02 . 2011-05-16 09:01 36294 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Acrobat_Standard.exe
    + 2011-04-15 07:02 . 2011-05-16 09:01 38926 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Acrobat_3D.exe
    - 2011-04-15 07:02 . 2011-04-15 07:02 38926 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Acrobat_3D.exe
    - 2011-04-15 07:02 . 2011-04-15 07:02 38926 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Acrobat.exe
    + 2011-04-15 07:02 . 2011-05-16 09:01 38926 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Acrobat.exe
    - 2010-01-26 10:35 . 2011-04-15 07:02 65536 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_A3DReviewer.exe
    + 2010-01-26 10:35 . 2011-05-16 09:01 65536 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_A3DReviewer.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
    + 2011-05-18 12:14 . 2011-05-18 12:14 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    - 2011-04-15 01:14 . 2011-04-15 01:14 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    - 2011-04-15 07:02 . 2011-04-15 07:02 7278 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_ELEMENTS_DT.exe
    + 2011-04-15 07:02 . 2011-05-16 09:01 7278 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_ELEMENTS_DT.exe
    + 2011-01-11 08:59 . 2011-01-11 08:59 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcm90.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_65b7a93a\atl90.dll
    + 2011-01-11 02:27 . 2011-01-11 02:27 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\msvcr80.dll
    + 2011-01-11 02:24 . 2011-01-11 02:24 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\msvcp80.dll
    + 2011-01-11 02:08 . 2011-01-11 02:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\msvcm80.dll
    + 2009-03-25 16:03 . 2011-05-18 10:59 297256 c:\windows\system32\FNTCACHE.DAT
    + 2011-05-18 12:14 . 2011-05-18 12:14 223232 c:\windows\Installer\3fae0b.msi
    + 2011-05-18 12:14 . 2011-05-18 12:14 459264 c:\windows\Installer\3fae05.msi
    - 2010-01-26 10:35 . 2011-04-15 07:02 335872 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\SC_Designer_PFM.70DBED24_B579_40CB_AB0B_F1221A3E9EC5.exe
    + 2010-01-26 10:35 . 2011-05-16 09:01 335872 c:\windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\SC_Designer_PFM.70DBED24_B579_40CB_AB0B_F1221A3E9EC5.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
    + 2011-05-16 08:08 . 2011-05-16 08:08 371272 c:\windows\Installer\{5335DADB-34BA-4AE8-A519-648D78498846}\SkypeIcon.exe
    + 2011-01-11 08:59 . 2011-01-11 08:59 3780936 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90u.dll
    + 2011-01-11 08:59 . 2011-01-11 08:59 3766088 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_d5fe2ecb\mfc90.dll
    + 2011-01-10 20:50 . 2011-01-10 20:50 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\mfc80u.dll
    + 2011-01-10 20:50 . 2011-01-10 20:50 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\mfc80.dll
    + 2011-05-16 09:54 . 2011-05-16 09:54 1094656 c:\windows\Installer\8b726.msi
    + 2011-04-29 10:27 . 2011-04-29 10:27 4158464 c:\windows\Installer\3fae3e.msp
    + 2011-04-28 03:42 . 2011-04-28 03:42 4990976 c:\windows\Installer\3fae28.msp
    + 2011-04-29 10:30 . 2011-04-29 10:30 1197056 c:\windows\Installer\3fae12.msp
    + 2011-04-14 15:11 . 2011-04-14 15:11 3898368 c:\windows\Installer\309fc4.msp
    + 2011-05-16 08:08 . 2011-05-16 08:08 1587200 c:\windows\Installer\2b398.msi
    - 2009-10-19 15:02 . 2011-04-15 01:21 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
    + 2009-10-19 15:02 . 2011-05-18 12:15 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
    - 2009-10-19 15:02 . 2011-04-15 01:21 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
    + 2009-03-30 10:22 . 2011-05-18 12:16 42829768 c:\windows\system32\MRT.exe
    + 2011-04-22 17:41 . 2011-04-22 17:41 11507712 c:\windows\Installer\3fae58.msp
    .
    -- Snapshot per reimpostare la data corrente --
    .
    ((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* i valori vuoti & legittimi/default non sono visualizzati.
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite "= "c:\programmi\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
    "NETGATERegistryCleaner "= "c:\programmi\NETGATE\Registry Cleaner\RegistryCleaner.exe" [2011-01-26 1882776]
    "Skype "= "c:\programmi\Skype\Phone\Skype.exe" [2011-04-18 15146376]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RTHDCPL "= "RTHDCPL.EXE" [2006-05-18 16207872]
    "SkyTel "= "SkyTel.EXE" [2006-05-16 2879488]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2006-01-24 7311360]
    "nwiz "= "nwiz.exe" [2006-01-24 1519616]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2006-01-24 86016]
    "NeroFilterCheck "= "c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "BluetoothAuthenticationAgent "= "bthprops.cpl" [2008-04-14 110592]
    "SunJavaUpdateSched "= "c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "PaperPort PTD "= "c:\programmi\Scansoft\PaperPort\pptd40nt.exe" [2002-05-10 45108]
    "IndexSearch "= "c:\programmi\Scansoft\PaperPort\IndexSearch.exe" [2002-05-10 36864]
    "GrooveMonitor "= "c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
    "FixCamera "= "c:\windows\FixCamera.exe" [2007-07-11 20480]
    "snpstd3 "= "c:\windows\vsnpstd3.exe" [2007-05-10 835584]
    "tsnpstd3 "= "c:\windows\tsnpstd3.exe" [2007-04-21 270336]
    "Adobe Acrobat Speed Launcher "= "c:\programmi\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-01-30 38840]
    "Acrobat Assistant 8.0 "= "c:\programmi\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]
    "Adobe ARM "= "c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "QuickTime Task "= "c:\programmi\QuickTime\qttask.exe" [2010-09-08 421888]
    "iTunesHelper "= "c:\programmi\iTunes\iTunesHelper.exe" [2010-09-24 421160]
    "avgnt "= "c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2011-01-21 281768]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE "= "c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
    .
    c:\documents and settings\Mastrogiacom\Menu Avvio\Programmi\Esecuzione automatica\
    Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
    Widget vodafone.lnk - c:\programmi\Widget vodafone.it\Widget vodafone.it.exe [2010-4-19 95232]
    .
    c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
    Windows Search.lnk - c:\programmi\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5} "= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs "=c:\windows\system32\acaptuser32.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @= "Driver "
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Programmi\\Mozilla Firefox\\firefox.exe "=
    "c:\\Programmi\\iTunes\\iTunes.exe "=
    "c:\\Programmi\\Skype\\Phone\\Skype.exe "=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP "= 3389:TCP:mad:xpsp2res.dll,-22009
    .
    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25/03/2009 19.02.28 691696]
    R2 NGRegClnSrv;NETGATE Registry Cleaner Service;c:\programmi\NETGATE\Registry Cleaner\RegistryCleanerSrv.exe [26/01/2011 16.26.42 440912]
    S1 MpKsl4615eb98;MpKsl4615eb98;\??\c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{E840DC17-E032-443A-A405-3BECC643F14D}\MpKsl4615eb98.sys --> c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{E840DC17-E032-443A-A405-3BECC643F14D}\MpKsl4615eb98.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13.16.28 130384]
    S3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.2.0;c:\windows\system32\drivers\libusb0.sys [06/07/2010 13.44.45 21504]
    S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [17/12/2009 10.48.40 18432]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13.16.28 753504]
    S4 MSSQLServerADHelper100;Servizio SQL Server Active Directory Helper;c:\programmi\Microsoft SQL Server\100\Shared\sqladhlp.exe [11/07/2008 2.28.58 47128]
    S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10/07/2008 2.49.14 242712]
    S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\programmi\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11/07/2008 2.29.04 369688]
    .
    Contenuto della cartella 'Scheduled Tasks'
    .
    2011-04-08 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\programmi\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]
    .
    .
    ------- Scansione supplementare -------
    .
    uStart Page = hxxp://www.google.it/
    IE: Append Link Target to Existing PDF - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
    TCP: {101FDF44-060D-4D30-83DF-4D0B289ACD21} = 130.192.3.21,130.192.3.24
    TCP: {51DB69B1-9045-4B51-8CBA-EAB917F96F78} = 130.192.3.21,130.192.3.24
    DPF: {4819DFDF-ABC4-488C-A323-919848C51175}
    FF - ProfilePath - c:\documents and settings\Mastrogiacom\Dati applicazioni\Mozilla\Firefox\Profiles\g8lyo8ry.default\
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-05-19 12:13
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scansione processi nascosti ...
    .
    scansione entrate autostart nascoste ...
    .
    Scansione files nascosti ...
    .
    Scansione completata con successo
    Files nascosti: 0
    .
    **************************************************************************
    .
    --------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ "•€|þ»Ã‘w*]
    "0140110900063D11C8EF10054038389C "= "C?\\WINDOWS\\system32\\FM20ENU.DLL "
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
    "0140110900063D11C8EF10054038389C "= "C?\\WINDOWS\\system32\\FM20ENU.DLL "
    "0140210900063D11C8EF10054038389C "= "C?\\WINDOWS\\system32\\FM20ENU.DLL "
    .
    --------------------- Dlls caricate dai processi in esecuzione ---------------------
    .
    - - - - - - - > 'explorer.exe'(2336)
    c:\windows\system32\WININET.dll
    c:\windows\system32\msi.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Ora fine scansione: 2011-05-19 12:15:27
    ComboFix-quarantined-files.txt 2011-05-19 10:15
    ComboFix2.txt 2011-05-13 09:36
    ComboFix3.txt 2011-05-12 13:43
    .
    Pre-Run: 19 287 056 384 byte disponibili
    Post-Run: 19 369 353 216 byte disponibili
    .
    WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug= "do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Professional" /noexecute=optin /fastdetect
    .
    Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
    - - End Of File - - 3D22F6FD028EC691B977BEDAF6E3311A
     
  17. 2011/05/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks clean.

    Any current issues?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  18. 2011/05/20
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Here is OTL.txt:


    OTL logfile created on: 20/05/2011 12.06.26 - Run 1
    OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mastrogiacom\Desktop
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

    2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
    4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
    Drive C: | 149.04 Gb Total Space | 18.17 Gb Free Space | 12.19% Space Free | Partition Type: NTFS

    Computer Name: MASTROGIACOMO | User Name: Mastrogiacomo | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2011/05/20 12.04.16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mastrogiacom\Desktop\OTL.exe
    PRC - [2011/04/27 09.25.50 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programmi\Avira\AntiVir Desktop\sched.exe
    PRC - [2011/04/04 09.30.45 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programmi\Avira\AntiVir Desktop\avguard.exe
    PRC - [2011/01/26 10.47.06 | 001,882,776 | ---- | M] (NETGATE Technologies s.r.o.) -- C:\Programmi\NETGATE\Registry Cleaner\RegistryCleaner.exe
    PRC - [2011/01/21 10.52.38 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2010/09/22 18.11.26 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Programmi\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    PRC - [2010/08/13 12.58.56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    PRC - [2010/04/01 11.16.20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Programmi\DAEMON Tools Lite\DTLite.exe
    PRC - [2010/02/18 11.43.18 | 000,248,040 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programmi\File comuni\Java\Java Update\jusched.exe
    PRC - [2010/01/14 22.11.21 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programmi\Avira\AntiVir Desktop\avshadow.exe
    PRC - [2009/09/02 12.46.24 | 000,440,912 | ---- | M] (NETGATE Technologies s.r.o.) -- C:\Programmi\NETGATE\Registry Cleaner\RegistryCleanerSrv.exe
    PRC - [2008/10/15 17.13.58 | 000,439,632 | ---- | M] (RealVNC Ltd.) -- C:\Programmi\RealVNC\VNC4\winvnc4.exe
    PRC - [2008/04/14 04.14.07 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2007/07/11 17.09.48 | 000,020,480 | ---- | M] () -- C:\WINDOWS\FixCamera.exe
    PRC - [2007/05/10 14.18.26 | 000,835,584 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe
    PRC - [2007/04/21 10.37.02 | 000,270,336 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe


    ========== Modules (SafeList) ==========

    MOD - [2011/05/20 12.04.16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mastrogiacom\Desktop\OTL.exe
    MOD - [2010/08/23 18.12.14 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - [2011/04/27 09.25.50 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programmi\Avira\AntiVir Desktop\sched.exe -- (AntiVirScheduler)
    SRV - [2011/04/04 09.30.45 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programmi\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2010/08/13 12.58.56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
    SRV - [2010/01/26 12.35.31 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2009/09/02 12.46.24 | 000,440,912 | ---- | M] (NETGATE Technologies s.r.o.) [Auto | Running] -- C:\Programmi\NETGATE\Registry Cleaner\RegistryCleanerSrv.exe -- (NGRegClnSrv)
    SRV - [2009/06/02 10.10.08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Programmi\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
    SRV - [2008/11/04 01.06.28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmi\File comuni\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
    SRV - [2008/10/15 17.13.58 | 000,439,632 | ---- | M] (RealVNC Ltd.) [Auto | Running] -- C:\Programmi\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)
    SRV - [2006/10/26 13.03.08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


    ========== Driver Services (SafeList) ==========

    DRV - [2011/04/04 09.30.45 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
    DRV - [2011/01/21 10.53.05 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
    DRV - [2010/06/17 15.28.21 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
    DRV - [2010/06/17 15.28.11 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programmi\Avira\AntiVir Desktop\avgio.sys -- (avgio)
    DRV - [2010/06/11 20.43.48 | 000,021,504 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\libusb0.sys -- (libusb0)
    DRV - [2010/04/19 20.29.20 | 000,018,432 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\netaapl.sys -- (Netaapl)
    DRV - [2009/11/24 10.38.42 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
    DRV - [2009/02/09 08.37.48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
    DRV - [2009/02/09 08.37.46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
    DRV - [2009/02/09 08.37.46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
    DRV - [2008/08/26 10.26.12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
    DRV - [2008/07/10 02.49.14 | 000,242,712 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RsFx0102.sys -- (RsFx0102)
    DRV - [2007/10/16 11.35.58 | 010,376,576 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
    DRV - [2006/05/16 11.32.58 | 004,275,712 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - [2006/04/24 11.52.28 | 000,100,736 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
    DRV - [2006/02/17 05.28.32 | 000,013,056 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
    DRV - [2006/02/17 05.28.30 | 000,034,176 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
    DRV - [2005/03/09 08.53.00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
    DRV - [2001/08/17 21.11.06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========



    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-117609710-1202660629-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
    IE - HKU\S-1-5-21-117609710-1202660629-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.3.0244
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
    FF - prefs.js..extensions.enabledItems: contact@whos.amung.us:1.80


    FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Programmi\Mozilla Firefox\components [2011/04/29 17.27.46 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Programmi\Mozilla Firefox\plugins [2011/05/16 11.00.19 | 000,000,000 | ---D | M]

    [2009/03/25 18.40.03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Mozilla\Extensions
    [2011/04/27 14.09.42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Mozilla\Firefox\Profiles\g8lyo8ry.default\extensions
    [2010/04/28 09.43.03 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Mozilla\Firefox\Profiles\g8lyo8ry.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2011/04/12 10.31.37 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Mozilla\Firefox\Profiles\g8lyo8ry.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
    [2011/02/17 10.56.38 | 000,000,000 | ---D | M] (whos.amung.us Users Online Counter) -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Mozilla\Firefox\Profiles\g8lyo8ry.default\extensions\contact@whos.amung.us
    [2011/04/27 14.09.42 | 000,000,000 | ---D | M] ( "DAEMON Tools Toolbar ") -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Mozilla\Firefox\Profiles\g8lyo8ry.default\extensions\DTToolbar@toolbarnet.com
    [2010/01/25 17.01.58 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Mozilla\Firefox\Profiles\g8lyo8ry.default\searchplugins\daemon-search.xml
    [2011/04/18 09.38.01 | 000,000,000 | ---D | M] (No name found) -- C:\Programmi\Mozilla Firefox\extensions
    File not found (No name found) --
    [2009/07/27 09.12.32 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMMI\JAVA\JRE6\LIB\DEPLOY\JQS\FF
    [2011/04/29 17.27.41 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programmi\Mozilla Firefox\components\browsercomps.dll
    [2011/04/18 13.58.43 | 000,002,252 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\bing.xml
    [2011/04/18 13.58.43 | 000,000,744 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\eBay-it.xml
    [2011/04/18 13.58.43 | 000,000,825 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\hoepli.xml
    [2011/04/18 13.58.43 | 000,001,182 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\wikipedia-it.xml
    [2011/04/18 13.58.43 | 000,000,953 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\yahoo-it.xml

    Hosts file not found
    O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
    O2 - BHO: (Guida per l'accesso a Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programmi\DAEMON Tools Toolbar\DTToolbar.dll ()
    O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKU\S-1-5-21-117609710-1202660629-839522115-1003\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programmi\DAEMON Tools Toolbar\DTToolbar.dll ()
    O3 - HKU\S-1-5-21-117609710-1202660629-839522115-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Programmi\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
    O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Programmi\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [Adobe ARM] C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [avgnt] C:\Programmi\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
    O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
    O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()
    O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
    O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
    O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()
    O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmi\File comuni\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
    O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()
    O4 - HKU\S-1-5-21-117609710-1202660629-839522115-1003..\Run: [DAEMON Tools Lite] C:\Programmi\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
    O4 - HKU\S-1-5-21-117609710-1202660629-839522115-1003..\Run: [NETGATERegistryCleaner] C:\Programmi\NETGATE\Registry Cleaner\RegistryCleaner.exe (NETGATE Technologies s.r.o.)
    O4 - Startup: C:\Documents and Settings\Mastrogiacom\Menu Avvio\Programmi\Esecuzione automatica\Widget vodafone.lnk = C:\Programmi\Widget vodafone.it\Widget vodafone.it.exe ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-117609710-1202660629-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-117609710-1202660629-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-21-117609710-1202660629-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-21-117609710-1202660629-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Append to Existing PDF - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert to Adobe PDF - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O16 - DPF: {4819DFDF-ABC4-488C-A323-919848C51175} Reg Error: Value error. (Conviva LivePass)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
    O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2_04)
    O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dispea.polito.it
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmi\File comuni\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programmi\File comuni\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20 - AppInit_DLLs: (C:\WINDOWS\system32\acaptuser32.dll) - C:\WINDOWS\system32\acaptuser32.dll (Adobe Systems Incorporated)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
    O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programmi\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/03/25 18.04.01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found

    Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
    Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
    Drivers32: VIDC.GTCC - GTCODEC.DLL File not found
    Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
    Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point (16902109354000384)

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/05/20 12.04.15 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mastrogiacom\Desktop\OTL.exe
    [2011/05/19 15.34.32 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2011/05/19 12.04.17 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2011/05/18 15.56.59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Desktop\QUADERNO AITEM
    [2011/05/17 10.02.45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Opag
    [2011/05/17 10.02.45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Onfiel
    [2011/05/16 11.54.54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Menu Avvio\Programmi\HiJackThis
    [2011/05/16 11.54.53 | 000,000,000 | ---D | C] -- C:\Programmi\Trend Micro
    [2011/05/16 10.59.26 | 000,112,056 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\acaptuser32.dll
    [2011/05/16 10.08.04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Skype
    [2011/05/12 14.55.53 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2011/05/12 14.55.53 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2011/05/12 14.55.53 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2011/05/12 14.55.53 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2011/05/12 14.55.28 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2011/05/12 14.36.39 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2011/05/12 14.34.08 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
    [2011/05/12 10.24.27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\DriverCure
    [2011/05/12 10.24.25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\ParetoLogic
    [2011/05/12 10.24.09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\ParetoLogic
    [2011/05/11 12.18.33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Biwu
    [2011/05/11 12.18.33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Awupme
    [2011/05/10 15.08.47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Desktop\Pubblicazioni
    [2011/05/09 11.26.45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Hyuzup
    [2011/05/09 11.26.45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Booqyb
    [2011/05/09 09.49.42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Impostazioni locali\Dati applicazioni\Deployment
    [2011/05/06 09.38.44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Otpiob
    [2011/05/06 09.38.44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Opc
    [2011/05/05 10.29.14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dati applicazioni\Macromedia
    [2011/05/05 10.24.13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dati applicazioni\Adobe
    [2011/05/04 16.06.35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Identities
    [2011/05/04 16.06.30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dati applicazioni\Windows Desktop Search
    [2011/05/04 16.06.30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dati applicazioni\Apple Computer
    [2011/05/04 16.05.47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dati applicazioni\Identities
    [2011/05/04 07.40.52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Adobe
    [2011/05/03 12.03.19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dati applicazioni\Macromedia
    [2011/05/03 12.03.18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dati applicazioni\Adobe
    [2011/05/03 12.03.05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dati applicazioni\Sun
    [2011/04/27 15.00.13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mastrogiacom\Desktop\PCP
    [2009/11/25 15.14.03 | 000,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
    [2009/11/25 15.14.03 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
    [2009/11/25 15.14.03 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
    [2009/11/25 15.14.03 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll
    [1 C:\Documents and Settings\Mastrogiacom\Documenti\*.tmp files -> C:\Documents and Settings\Mastrogiacom\Documenti\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2011/05/20 12.04.16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mastrogiacom\Desktop\OTL.exe
    [2011/05/20 11.42.51 | 000,043,531 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
    [2011/05/20 11.42.23 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2011/05/20 11.42.22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2011/05/19 18.00.14 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
    [2011/05/19 17.59.57 | 000,000,157 | ---- | M] () -- C:\WINDOWS\matlab.ini
    [2011/05/19 16.33.25 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Mastrogiacom\PUTTY.RND
    [2011/05/19 12.04.22 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2011/05/18 12.59.03 | 000,297,256 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2011/05/16 12.18.21 | 000,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI
    [2011/05/12 16.01.42 | 000,001,912 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
    [2011/05/10 09.23.33 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2011/05/09 09.47.37 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
    [2011/04/29 16.58.56 | 000,024,726 | ---- | M] () -- C:\Documents and Settings\Mastrogiacom\Desktop\mastrogiacomo_luca_2010.zip
    [2011/04/28 10.27.15 | 001,984,799 | ---- | M] () -- C:\Documents and Settings\Mastrogiacom\Desktop\730_2011.zip
    [2011/04/27 16.55.25 | 000,003,510 | ---- | M] () -- C:\Documents and Settings\Mastrogiacom\Desktop\distorion_correction.rar
    [1 C:\Documents and Settings\Mastrogiacom\Documenti\*.tmp files -> C:\Documents and Settings\Mastrogiacom\Documenti\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2011/05/19 12.04.22 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2011/05/19 12.04.18 | 000,261,312 | RHS- | C] () -- C:\cmldr
    [2011/05/12 14.55.53 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2011/05/12 14.55.53 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2011/05/12 14.55.53 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2011/05/12 14.55.53 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2011/05/12 14.55.53 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2011/05/12 14.27.45 | 000,001,912 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
    [2011/05/09 09.47.35 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
    [2011/04/29 16.58.56 | 000,024,726 | ---- | C] () -- C:\Documents and Settings\Mastrogiacom\Desktop\mastrogiacomo_luca_2010.zip
    [2011/04/28 10.27.15 | 001,984,799 | ---- | C] () -- C:\Documents and Settings\Mastrogiacom\Desktop\730_2011.zip
    [2011/04/27 16.55.24 | 000,003,510 | ---- | C] () -- C:\Documents and Settings\Mastrogiacom\Desktop\distorion_correction.rar
    [2010/04/27 10.06.11 | 000,066,188 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
    [2010/01/07 10.14.04 | 000,022,108 | ---- | C] () -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Valori separati da virgola (Windows).ADR
    [2009/12/17 17.05.26 | 000,290,816 | ---- | C] () -- C:\WINDOWS\System32\decdll.dll
    [2009/12/16 14.02.45 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
    [2009/11/25 15.14.12 | 000,020,480 | ---- | C] () -- C:\WINDOWS\FixCamera.exe
    [2009/11/25 15.14.08 | 000,835,584 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe
    [2009/11/25 15.14.08 | 000,270,336 | ---- | C] () -- C:\WINDOWS\tsnpstd3.exe
    [2009/11/25 15.14.08 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
    [2009/07/08 15.03.37 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2009/07/07 11.03.43 | 000,000,767 | ---- | C] () -- C:\WINDOWS\maxlink.ini
    [2009/07/06 17.25.34 | 000,102,825 | ---- | C] () -- C:\WINDOWS\hpgins14.dat
    [2009/07/06 17.25.34 | 000,000,173 | ---- | C] () -- C:\WINDOWS\hpgmdl14.dat
    [2009/07/06 17.15.00 | 000,548,864 | R--- | C] () -- C:\WINDOWS\System32\hpgt4850.dll
    [2009/06/17 17.21.31 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
    [2009/06/05 09.47.26 | 000,000,141 | ---- | C] () -- C:\Documents and Settings\Mastrogiacom\Impostazioni locali\Dati applicazioni\fusioncache.dat
    [2009/05/06 19.17.07 | 000,008,082 | ---- | C] () -- C:\WINDOWS\hplj1010.ini
    [2009/04/20 13.01.35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI
    [2009/04/20 11.12.47 | 000,000,012 | ---- | C] () -- C:\WINDOWS\bthservsdp.dat
    [2009/03/26 16.27.46 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2009/03/26 13.18.50 | 000,000,157 | ---- | C] () -- C:\WINDOWS\matlab.ini
    [2009/03/26 12.41.17 | 000,046,592 | ---- | C] () -- C:\Documents and Settings\Mastrogiacom\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/03/26 12.40.17 | 000,000,424 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2009/03/25 18.43.11 | 000,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
    [2009/03/25 18.43.11 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
    [2009/03/25 18.40.03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
    [2009/03/25 18.06.18 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2009/03/25 18.04.55 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2009/03/25 18.03.38 | 000,297,256 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2009/03/25 18.00.45 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2008/05/26 23.22.48 | 000,016,708 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
    [2008/05/26 23.22.46 | 000,021,662 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
    [2008/05/26 23.22.44 | 000,016,338 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
    [2008/05/26 22.59.42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
    [2008/05/26 22.59.40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
    [2008/04/14 14.58.40 | 002,854,912 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
    [2006/01/24 12.15.00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
    [2006/01/24 12.15.00 | 001,519,616 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
    [2006/01/24 12.15.00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
    [2006/01/24 12.15.00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
    [2006/01/24 12.15.00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
    [2006/01/24 12.15.00 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
    [2006/01/24 12.15.00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
    [2006/01/24 12.15.00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
    [2006/01/24 12.15.00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
    [2006/01/24 12.15.00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
    [2006/01/24 12.15.00 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
    [2004/08/19 14.00.00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
    [2004/08/19 14.00.00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [2004/08/19 14.00.00 | 000,644,498 | ---- | C] () -- C:\WINDOWS\System32\perfh010.dat
    [2004/08/19 14.00.00 | 000,570,494 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [2004/08/19 14.00.00 | 000,300,212 | ---- | C] () -- C:\WINDOWS\System32\perfi010.dat
    [2004/08/19 14.00.00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [2004/08/19 14.00.00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [2004/08/19 14.00.00 | 000,138,316 | ---- | C] () -- C:\WINDOWS\System32\perfc010.dat
    [2004/08/19 14.00.00 | 000,113,430 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [2004/08/19 14.00.00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [2004/08/19 14.00.00 | 000,034,004 | ---- | C] () -- C:\WINDOWS\System32\perfd010.dat
    [2004/08/19 14.00.00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [2004/08/19 14.00.00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [2004/08/19 14.00.00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
    [2004/08/19 14.00.00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
    [2004/08/19 14.00.00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
    [2002/04/11 17.33.38 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\Welsof32.dll
    [2001/07/31 11.17.12 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
    [1998/01/09 08.58.04 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Jpeg32.dll

    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2009/03/25 18.04.01 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2009/03/25 17.58.28 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2011/05/19 12.04.22 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2004/08/19 14.00.00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
    [2004/08/03 23.00.12 | 000,261,312 | RHS- | M] () -- C:\cmldr
    [2011/05/19 12.15.27 | 000,026,105 | ---- | M] () -- C:\ComboFix.txt
    [2009/03/25 18.04.01 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2011/04/14 15.49.53 | 000,000,000 | ---- | M] () -- C:\ctapi_out_gr.txt
    [2010/09/13 19.28.08 | 000,000,270 | ---- | M] () -- C:\file_list.txt
    [2009/11/25 15.38.05 | 000,230,424 | ---- | M] () -- C:\img2-003.raw
    [2009/03/25 18.04.01 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2009/03/25 18.04.01 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2004/08/19 14.00.00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2009/03/26 10.50.49 | 000,251,600 | RHS- | M] () -- C:\ntldr
    [2011/05/20 11.42.19 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
    [2011/05/18 12.57.58 | 000,042,766 | ---- | M] () -- C:\TDSSKiller.2.5.1.0_18.05.2011_12.56.52_log.txt

    < %systemroot%\Fonts\*.com >
    [2006/04/18 15.39.28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
    [2006/06/29 14.53.56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
    [2006/04/18 15.39.28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
    [2006/06/29 14.58.52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2009/03/25 18.03.34 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2008/07/06 14.06.10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    [2002/04/18 11.13.20 | 000,049,152 | ---- | M] (Zenographics, Inc.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
    [2007/04/09 13.23.54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
    [2006/10/26 19.56.12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
    [2001/05/16 09.39.02 | 000,047,616 | ---- | M] (Black Ice Software) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\ppbiPr.dll
    [2008/07/06 12.50.03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2009/03/25 18.02.43 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
    [2009/03/25 18.02.43 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
    [2009/03/25 18.02.42 | 000,438,272 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2009/03/26 11.09.14 | 000,000,123 | -HS- | M] () -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    [2009/03/25 18.09.04 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Mastrogiacom\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\Mostra Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2011/05/20 12.04.16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mastrogiacom\Desktop\OTL.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >
    [2004/02/27 18.36.18 | 000,013,023 | ---- | M] () -- C:\WINDOWS\snpstd3.src

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2011/01/19 10.24.20 | 000,002,412 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2011/05/20 11.47.04 | 000,065,536 | ---- | M] () -- C:\Documents and Settings\Mastrogiacom\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2007/06/27 15.48.40 | 000,318,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2008/04/14 04.13.37 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Programmi\Messenger\custsat.dll
    [2004/08/19 16.51.50 | 000,004,821 | ---- | M] () -- C:\Programmi\Messenger\logowin.gif
    [2004/08/19 16.51.52 | 000,007,047 | ---- | M] () -- C:\Programmi\Messenger\lvback.gif
    [2008/05/02 16.01.53 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Programmi\Messenger\msgsc.dll
    [2008/04/13 19.30.28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Programmi\Messenger\msgslang.dll
    [2008/04/14 04.14.13 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Programmi\Messenger\msmsgs.exe
    [2007/04/02 20.07.23 | 000,002,882 | ---- | M] () -- C:\Programmi\Messenger\newalert.wav
    [2007/04/02 20.07.23 | 000,006,156 | ---- | M] () -- C:\Programmi\Messenger\newemail.wav
    [2007/04/02 20.07.24 | 000,006,160 | ---- | M] () -- C:\Programmi\Messenger\online.wav
    [2004/08/19 16.51.52 | 000,004,454 | ---- | M] () -- C:\Programmi\Messenger\type.wav
    [2004/08/19 16.51.52 | 000,126,752 | ---- | M] () -- C:\Programmi\Messenger\xpmsgr.chm

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:DFC5A2B2

    < End of report >
     
  19. 2011/05/20
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    Here is Extras.txt. I understand it is in italian but I was not able to switch language.
    I post it as it is, I can run it again changing some settings but I don't know which one:

    OTL Extras logfile created on: 20/05/2011 12.06.26 - Run 1
    OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mastrogiacom\Desktop
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

    2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
    4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
    Drive C: | 149.04 Gb Total Space | 18.17 Gb Free Space | 12.19% Space Free | Partition Type: NTFS

    Computer Name: MASTROGIACOMO | User Name: Mastrogiacomo | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    .html [@ = FirefoxHTML] -- C:\Programmi\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
    .js [@ = jsfile] -- Reg Error: Key error. File not found

    [HKEY_USERS\S-1-5-21-117609710-1202660629-839522115-1003\SOFTWARE\Classes\<extension>]
    .html [@ = ChromeHTML] -- Reg Error: Key error. File not found

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    exefile [open] -- "%1" %*
    https [open] -- "C:\Programmi\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    jsfile [edit] -- Reg Error: Key error.
    jsfile [open] -- Reg Error: Key error.
    jsfile [print] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Programmi\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Programmi\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "3389:TCP" = 3389:TCP:*:Enabled:mad:xpsp2res.dll,-22009
    "139:TCP" = 139:TCP:*:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:*:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:*:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:*:Enabled:mad:xpsp2res.dll,-22002

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "3389:TCP" = 3389:TCP:*:Enabled:mad:xpsp2res.dll,-22009
    "139:TCP" = 139:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22002

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Programmi\eMule\emule.exe" = C:\Programmi\eMule\emule.exe:*:Enabled:eMule
    "C:\Programmi\Mozilla Firefox\firefox.exe" = C:\Programmi\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
    "C:\Programmi\MATLAB\R2007a\bin\win32\MATLAB.exe" = C:\Programmi\MATLAB\R2007a\bin\win32\MATLAB.exe:*:Enabled:MATLAB -- (The MathWorks Inc.)
    "C:\Programmi\RealVNC\VNC4\vncviewer.exe" = C:\Programmi\RealVNC\VNC4\vncviewer.exe:*:Enabled:Run VNC Viewer -- (RealVNC Ltd.)
    "C:\Programmi\RealVNC\VNC4\winvnc4.exe" = C:\Programmi\RealVNC\VNC4\winvnc4.exe:*:Enabled:winvnc4.exe -- (RealVNC Ltd.)
    "C:\Documents and Settings\Mastrogiacom\Desktop\CCV-1.3-win-bin\Community Core Vision.exe" = C:\Documents and Settings\Mastrogiacom\Desktop\CCV-1.3-win-bin\Community Core Vision.exe:*:Enabled:Community Core Vision
    "C:\Programmi\Java\jre6\bin\javaw.exe" = C:\Programmi\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
    "C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Esplora risorse -- (Microsoft Corporation)
    "C:\Documents and Settings\Mastrogiacom\Documenti\MATLAB\untitled1\distrib\untitled1.exe" = C:\Documents and Settings\Mastrogiacom\Documenti\MATLAB\untitled1\distrib\untitled1.exe:*:Enabled:untitled1 -- ()

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Programmi\Mozilla Firefox\firefox.exe" = C:\Programmi\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{02571A12-50D8-4D42-99CE-83D1144508C7}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools - Italiano
    "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
    "{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
    "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
    "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
    "{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
    "{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
    "{11064B68-39FA-48F5-8130-5E58383973FD}" = Microsoft SQL Server 2008 Native Client
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Strumento di caricamento di Windows Live
    "{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{246D27BE-94F5-4838-B1F9-6DD3E379E488}" = Microsoft SQL Server 2008 Database Engine Services
    "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13
    "{2B290B14-1C25-4180-99B1-354B2D5D1D1E}" = Utilità di attivazione licenze di rete AutoCAD 2009
    "{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
    "{32714140-CBC5-3FAF-BFC2-3A7376C3EECF}" = Microsoft .NET Framework 4 Client Profile ITA Language Pack
    "{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
    "{350C9410-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    "{3C93AA32-A49D-4C6A-9ADB-2EA60E367E8D}" = Microsoft SQL Server 2008 Setup Support Files (English)
    "{4344E211-F621-3870-9A08-2F56C71BA0A7}" = Microsoft .NET Framework 4 Extended ITA Language Pack
    "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
    "{48667EB3-6A7F-47B1-9C97-AFEDB4FD6B8D}" = Microsoft SQL Server 2008 Database Engine Shared
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
    "{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver
    "{5335DADB-34BA-4AE8-A519-648D78498846}" = Skypeâ„¢ 5.3
    "{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
    "{5545EEE8-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.3)
    "{55CA4086-0D2C-30E3-A7B5-C76BA737CECE}" = Microsoft .NET Framework 3.5 Language Pack SP1 - ita
    "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
    "{5A613A09-8F96-4F7E-BD71-69A89F37150D}" = hpg4850QFolder
    "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
    "{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
    "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
    "{6D7BDA00-A4DA-49F9-BAE4-7FB71FAA4737}" = Windows Live Essentials
    "{6F695BCF-9BDC-48AB-8D46-D57CFAD7A248}" = Assistente per l'accesso a Windows Live
    "{7148F0A8-6813-11D6-A77B-00B0D0142040}" = Java 2 Runtime Environment, SE v1.4.2_04
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7605109A-86F7-3F22-A35B-EDBF6FB06401}" = Microsoft Visual C# 2008 Express Edition with SP1 - ITA
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7CB59081-B692-441C-A9EF-78C27ED06879}" = Microsoft SQL Server Compact 3.5 SP1 - Italiano
    "{7E351356-81B3-4339-96FA-04A1F652CF2C}" = Dizionario Oxford-Paravia
    "{834EA459-FD2C-4336-9DFE-C4EDBF63D51A}" = Microsoft SQL Server 2008 Browser
    "{842F9881-E181-30B3-A152-008D61433274}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - ITA
    "{8658342C-43E0-43CA-B831-7E1FAB33311D}" = hpg4850
    "{86BA3130-5938-3192-BBCF-6B0A2D86FA58}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - ITA
    "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A2B151C-23FC-4A21-B6DA-263E8BF93E23}" = HP Scanjet 4800 series 7.0
    "{90120000-0010-0410-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Italian) 12
    "{90120000-0015-0410-0000-0000000FF1CE}" = Microsoft Office Access MUI (Italian) 2007
    "{90120000-0015-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0410-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Italian) 2007
    "{90120000-0016-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0410-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Italian) 2007
    "{90120000-0018-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0019-0410-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Italian) 2007
    "{90120000-0019-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0410-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Italian) 2007
    "{90120000-001A-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0410-0000-0000000FF1CE}" = Microsoft Office Word MUI (Italian) 2007
    "{90120000-001B-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
    "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
    "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90120000-002C-0410-0000-0000000FF1CE}" = Microsoft Office Proofing (Italian) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{90120000-0044-0410-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Italian) 2007
    "{90120000-0044-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-006E-0410-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Italian) 2007
    "{90120000-006E-0410-0000-0000000FF1CE}_ENTERPRISE_{0A75DA12-55CB-4DE5-8B6A-74D97847204E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0410-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Italian) 2007
    "{90120000-00A1-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00BA-0410-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Italian) 2007
    "{90120000-00BA-0410-0000-0000000FF1CE}_ENTERPRISE_{71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95140000-007F-0410-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
    "{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
    "{AC76BA86-1033-F400-7761-000000000004}_944" = Adobe Acrobat 9.4.4 - CPSID_83708
    "{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
    "{AEF2D1F3-0696-11D5-8E6A-00C04F7FA234}" = PaperPort 8.0
    "{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
    "{B423108E-F1F3-4EC0-80F5-0AC7D6ED5F1E}" = Microsoft SQL Server VSS Writer
    "{B4EC4684-1648-3A42-9417-0D5C44B6392E}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - ita
    "{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
    "{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
    "{D7BF3B76-EEF9-4868-9B2B-42ABF60B279A}" = Microsoft_VC80_CRT_x86
    "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
    "{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
    "{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
    "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
    "{E31A24A7-CF73-42B7-8FA1-26644296C9E3}" = Windows Live Mail
    "{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
    "{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = Hama Webcam AC-150
    "{EE70E5CC-B1D7-4FC0-7DC5-5460EF22FFC9}" = Widget vodafone.it
    "{EF462F41-AE1B-4C95-98B3-077562EA190F}" = Microsoft SQL Server 2008 Common Files
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
    "{F2D2B58B-B2FD-46D1-8319-DCE564079934}" = Microsoft .NET Framework 1.1 Italian Language Pack
    "{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
    "{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
    "{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
    "A86F74A8853ED6B1102811674C7B366AF1B276BB" = Pacchetto driver Windows - Hewlett-Packard Image (12/27/2006 8.0.0.0)
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
    "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
    "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
    "ConvivaProxyIE" = Conviva LivePass
    "DAEMON Tools Toolbar" = DAEMON Tools Toolbar
    "DSMT4" = MathType 4
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "Free Video Converter_is1" = Free Video Converter V 2.5
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "it.vodafone.desktopwidget.75C5D0AC8E830B80BD4FBC0B32A23F0123E8C097.1" = Widget vodafone.it
    "JDownloader" = JDownloader
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "MatlabR2007a" = MATLAB R2007a
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 Language Pack SP1 - ita" = Microsoft .NET Framework 3.5 - Language Pack SP1 (italiano)
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Client Profile ITA Language Pack" = Microsoft .NET Framework 4 Client Profile - Language Pack (ITA)
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "Microsoft .NET Framework 4 Extended ITA Language Pack" = Microsoft .NET Framework 4 Extended - Language Pack (ITA)
    "Microsoft SQL Server 10" = Microsoft SQL Server 2008
    "Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
    "Microsoft Visual C# 2008 Express Edition with SP1 - ITA" = Microsoft Visual C# 2008 Express Edition SP1 - ITA
    "Mozilla Firefox 4.0.1 (x86 it)" = Mozilla Firefox 4.0.1 (x86 it)
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
    "NETGATE Registry Cleaner_is1" = NETGATE Registry Cleaner
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "NVIDIA Drivers" = NVIDIA Drivers
    "PDF-Creator with VDM Settings_is1" = PDF-Creator with VDM Settings
    "PSPad editor_is1" = PSPad editor
    "RealVNC_is1" = VNC Free Edition 4.1.3
    "VLC media player" = VLC media player 0.9.9
    "Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    "Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinLiveSuite_Wave3" = Windows Live Essentials
    "WinRAR archiver" = WinRAR gestione archivi
    "winscp3_is1" = WinSCP 4.0.5
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
    "XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 18/05/2011 9.24.25 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\model.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 18/05/2011 9.24.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\MSDBData.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 18/05/2011 9.24.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\modellog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    Error - 18/05/2011 9.24.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\MSDBLog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    Error - 19/05/2011 4.20.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\model.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 19/05/2011 4.20.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\MSDBData.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 19/05/2011 4.20.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\modellog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    Error - 19/05/2011 4.20.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\MSDBLog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    Error - 20/05/2011 5.42.36 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\model.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 20/05/2011 5.42.36 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\modellog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    [ Application Events ]
    Error - 18/05/2011 9.24.25 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\model.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 18/05/2011 9.24.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\MSDBData.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 18/05/2011 9.24.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\modellog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    Error - 18/05/2011 9.24.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\MSDBLog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    Error - 19/05/2011 4.20.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\model.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 19/05/2011 4.20.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\MSDBData.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 19/05/2011 4.20.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\modellog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    Error - 19/05/2011 4.20.26 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\MSDBLog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    Error - 20/05/2011 5.42.36 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17204
    Description = FCB::Open failed: impossibile aprire il file e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\model.mdf
    per il numero di file 1. Errore del sistema operativo: 21(Periferica non pronta.).

    Error - 20/05/2011 5.42.36 | Computer Name = MASTROGIACOMO | Source = MSSQL$SQLEXPRESS | ID = 17207
    Description = FileMgr::StartLogFiles: Errore del sistema operativo 2(Impossibile
    trovare il file specificato.) durante la creazione o l'apertura del file 'e:\sql10_main_t\sql\mkmastr\databases\objfre\i386\modellog.ldf'.
    Individuare e correggere l'errore del sistema operativo, quindi riprovare.

    [ OSession Events ]
    Error - 31/03/2011 12.15.23 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 27038
    seconds with 1080 seconds of active time. This session ended with a crash.

    Error - 04/04/2011 3.39.29 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 524
    seconds with 120 seconds of active time. This session ended with a crash.

    Error - 07/04/2011 4.06.31 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 641
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 07/04/2011 11.27.59 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3521
    seconds with 1080 seconds of active time. This session ended with a crash.

    Error - 07/04/2011 13.17.26 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6550
    seconds with 1440 seconds of active time. This session ended with a crash.

    Error - 18/04/2011 5.59.50 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 69
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 10/05/2011 9.19.10 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 525
    seconds with 360 seconds of active time. This session ended with a crash.

    Error - 12/05/2011 5.41.55 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6826
    seconds with 240 seconds of active time. This session ended with a crash.

    Error - 17/05/2011 3.29.35 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6555.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 492
    seconds with 60 seconds of active time. This session ended with a crash.

    Error - 18/05/2011 8.57.21 | Computer Name = MASTROGIACOMO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
    seconds with 0 seconds of active time. This session ended with a crash.

    [ System Events ]
    Error - 18/05/2011 9.25.52 | Computer Name = MASTROGIACOMO | Source = Service Control Manager | ID = 7000
    Description = Il servizio Bluetooth Port Client Driver non è stato avviato per il
    seguente errore: %%2

    Error - 18/05/2011 9.25.52 | Computer Name = MASTROGIACOMO | Source = Service Control Manager | ID = 7024
    Description = Servizio SQL Server (SQLEXPRESS) terminato. Errore specifico del servizio
    1814 (0x716).

    Error - 19/05/2011 3.38.19 | Computer Name = MASTROGIACOMO | Source = Service Control Manager | ID = 7011
    Description = Timout (30000 millisecondi) durante l'attesa della risposta alla transazione
    dal servizio stisvc.

    Error - 19/05/2011 4.21.53 | Computer Name = MASTROGIACOMO | Source = Service Control Manager | ID = 7000
    Description = Il servizio Bluetooth Port Client Driver non è stato avviato per il
    seguente errore: %%2

    Error - 19/05/2011 4.21.53 | Computer Name = MASTROGIACOMO | Source = Service Control Manager | ID = 7024
    Description = Servizio SQL Server (SQLEXPRESS) terminato. Errore specifico del servizio
    1814 (0x716).

    Error - 19/05/2011 4.21.53 | Computer Name = MASTROGIACOMO | Source = Service Control Manager | ID = 7034
    Description = Interruzione imprevista del servizio NVIDIA Display Driver Service.
    Questo evento si è già verificato 1 volta(e).

    Error - 19/05/2011 6.00.30 | Computer Name = MASTROGIACOMO | Source = NETLOGON | ID = 5719
    Description = Non è disponibile alcun controller di dominio per il dominio DISPEA.
    Si è verificato il seguente errore %%1311. Acceratrsi che il computer sia connesso
    alla rete e riprovare. Se il problema persiste, contattare l'amministratore del
    dominio.

    Error - 20/05/2011 5.42.37 | Computer Name = MASTROGIACOMO | Source = Schannel | ID = 36870
    Description = Errore irreversibile durante il tentativo di accedere la chiave privata
    della credenziale server SSL. Il codice di errore restituito dal modulo di crittografia
    è 0xc0000017.

    Error - 20/05/2011 5.43.59 | Computer Name = MASTROGIACOMO | Source = Service Control Manager | ID = 7000
    Description = Il servizio Bluetooth Port Client Driver non è stato avviato per il
    seguente errore: %%2

    Error - 20/05/2011 5.43.59 | Computer Name = MASTROGIACOMO | Source = Service Control Manager | ID = 7024
    Description = Servizio SQL Server (SQLEXPRESS) terminato. Errore specifico del servizio
    1814 (0x716).


    < End of report >
     
  20. 2011/05/20
    geppoluc

    geppoluc Inactive Thread Starter

    Joined:
    2011/05/11
    Messages:
    20
    Likes Received:
    0
    An other thing. You were asking about the computer behaviour. It does not show anything particular, it seems it works fine apart from the fact that hypertextual links within the mail do not work. An error message shows saying something like "Operation has been canceled due to restrictions on the computer. Contact your system administrator ".

    Apart from that everything is ok
     
  21. 2011/05/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall NETGATE Registry Cleaner.
    Registry cleaners/optimizers are not recommended for several reasons:

    • Registry cleaners are extremely powerful applications that can damage the registry by using aggressive cleaning routines and cause your computer to become unbootable.

      The Windows registry is a central repository (database) for storing configuration data, user settings and machine-dependent settings, and options for the operating system. It contains information and settings for all hardware, software, users, and preferences. Whenever a user makes changes to settings, file associations, system policies, or installed software, the changes are reflected and stored in this repository. The registry is a crucial component because it is where Windows "remembers" all this information, how it works together, how Windows boots the system and what files it uses when it does. The registry is also a vulnerable subsystem, in that relatively small changes done incorrectly can render the system inoperable. For a more detailed explanation, read Understanding The Registry.
    • Not all registry cleaners are created equal. There are a number of them available but they do not all work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad entry ". One cleaner may find entries on your system that will not cause problems when removed, another may not find the same entries, and still another may want to remove entries required for a program to work.
    • Not all registry cleaners create a backup of the registry before making changes. If the changes prevent the system from booting up, then there is no backup available to restore it in order to regain functionality. A backup of the registry is essential BEFORE making any changes to the registry.
    • Improperly removing registry entries can hamper malware disinfection and make the removal process more difficult if your computer becomes infected. For example, removing malware related registry entries before the infection is properly identified can contribute to system instability and even make the malware undetectable to removal tools.
    • The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in "unpredictable results ".
    Unless you have a particular problem that requires a registry edit to correct it, I would suggest you leave the registry alone. Using registry cleaning tools unnecessarily or incorrectly could lead to disastrous effects on your operating system such as preventing it from ever starting again. For routine use, the benefits to your computer are negligible while the potential risks are great.


    =====================================================

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    ====================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      O16 - DPF: {4819DFDF-ABC4-488C-A323-919848C51175} Reg Error: Value error. (Conviva LivePass)
      [1 C:\Documents and Settings\Mastrogiacom\Documenti\*.tmp files -> C:\Documents and Settings\Mastrogiacom\Documenti\*.tmp -> ]
      @Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:DFC5A2B2
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ====================================================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • IMPORTANT! UN-check Remove found threats
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.