Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help me,please


  • This topic is locked This topic is locked
8 replies to this topic

#1 Striker195

Striker195

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:48 PM

Posted 12 June 2011 - 12:43 PM

Hello guys,i've got that virus updateKB250S5X82R4H0N0 i tried many antiviruses and no one delete it. So what I do? Can I use ComboFix? Thanks guys, bye!

BC AdBot (Login to Remove)

 


#2 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:03:48 PM

Posted 20 June 2011 - 11:29 AM

Hello and welcome to the forums!

My secret agent name on the forums is SweetTech (you can call me ST for short), it's a pleasure to meet you. :)

I am very sorry for the delay in responding, but as you can see we are at the moment being flooded with logs which, when paired with the never-ending shortage of helpers, resulted in the delayed responding to your thread.

I would be glad to take a look at your log and help you with solving any malware problems.

If you have since resolved the issues you were originally experiencing, or have received help elsewhere, please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forums.
  • Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.

____________________________________________________

Rootkit UnHooker (RkU)
Please download Rootkit Unhooker from one of the following links and save it to your desktop.
Link 1 (.exe file)
Link 2 (zipped file)
Link 3 (.rar file)In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can downlaod, install and use the free 7-zip utility.

  • Double-click on RKUnhookerLE.exe to start the program.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth Code, and uncheck the rest.
  • Click OK.
  • Wait until it's finished and then go to File > Save Report.
  • Save the report to your Desktop.
  • Copy and paste the contents of the report into your next reply.
-- Note: You may get this warning...just ignore it, click OK and continue: "Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?".



NEXT:


Running OTL

We need to create a FULL OTL Report
  • Please download OTL from here:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Change the "Extra Registry" option to "SafeList"
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extras.txt <-- Will be minimized

NEXT:


Please provide an update on how things are running in your next reply.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.


#3 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:03:48 PM

Posted 22 June 2011 - 11:44 AM

Hi!

It's been several days since I last posted instructions for you to complete. Do you still require assistance in getting your computer cleaned up?

Please Note: Unless notified in advance, threads with no response in 3 days get closed.

If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave & if there is no contact for that amount of time I will have to assume you have abandoned your topic.


Thanks,
SweetTech.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.


#4 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:03:48 PM

Posted 23 June 2011 - 03:58 PM

Due to lack of feedback this thread will now be closed. If you still require assistance, and would like to have your thread re-opened, please feel free to send me a Private Message (PM) being sure to include a link to your topic, and I'd be happy to re-open it.


Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.


#5 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:03:48 PM

Posted 24 June 2011 - 09:38 AM

This topic has been re-opened at the request of the person who originally posted.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.


#6 Striker195

Striker195
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:48 PM

Posted 25 June 2011 - 05:22 AM

Hi ST I did only OTL scan cause RKU didn't work..Attached File  OTL.Txt   111.13KB   2 downloadsAttached File  Extras.Txt   51.18KB   1 downloads



OTL logfile created on: 25/06/2011 12:16:36 - Run 2
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Utente\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

3,96 Gb Total Physical Memory | 2,53 Gb Available Physical Memory | 63,90% Memory free
7,92 Gb Paging File | 6,02 Gb Available in Paging File | 76,08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 926,33 Gb Total Space | 820,94 Gb Free Space | 88,62% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 931,38 Gb Free Space | 99,99% Space Free | Partition Type: NTFS

Computer Name: UTENTE-PC | User Name: Utente | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/24 11:02:35 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Utente\Desktop\OTL.exe
PRC - [2011/06/15 01:47:58 | 000,404,568 | ---- | M] (LG Electronics) -- C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
PRC - [2011/06/08 18:05:22 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011/06/01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011/06/01 14:10:00 | 000,821,080 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011/06/01 14:09:58 | 004,385,112 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
PRC - [2011/05/29 09:11:28 | 000,449,584 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/05/28 14:46:56 | 000,761,232 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\AutoSweep.exe
PRC - [2011/05/26 11:42:36 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\DNA\btdna.exe
PRC - [2011/04/05 16:40:44 | 000,517,864 | ---- | M] () -- C:\Program Files (x86)\puush\puush.exe
PRC - [2011/02/17 06:21:58 | 002,190,688 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\avgtray.exe
PRC - [2011/01/20 17:20:34 | 000,426,840 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Game Booster\gbtray.exe
PRC - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe


========== Modules (SafeList) ==========

MOD - [2011/06/24 11:02:35 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Utente\Desktop\OTL.exe
MOD - [2010/11/12 16:22:38 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/05/11 12:21:26 | 000,415,616 | R--- | M] (cFos Software GmbH) [Auto | Running] -- C:\Program Files\cFosSpeed\spd.exe -- (cFosSpeedS)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/08/26 03:57:14 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011/06/16 10:47:50 | 003,435,096 | ---- | M] () [Auto | Running] -- c:\program files (x86)\common files\akamai\netsession_win_e877e12.dll -- (Akamai)
SRV - [2011/06/08 18:05:22 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011/06/01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011/06/01 14:10:00 | 000,821,080 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
SRV - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/05/28 14:46:56 | 000,353,168 | ---- | M] (IObit) [Disabled | Stopped] -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe -- (AdvancedSystemCareService)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/11/11 00:02:10 | 004,134,480 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWow64\GameMon.des -- (npggsvc)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/05/29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/05/11 12:21:30 | 001,261,440 | ---- | M] (cFos Software GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\cfosspeed6.sys -- (cFosSpeed) cFosSpeed for faster Internet connections (NDIS 6)
DRV:64bit: - [2011/04/27 10:59:58 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/04/27 10:59:58 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/22 08:12:46 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV:64bit: - [2011/02/10 07:53:58 | 000,376,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2010/12/08 04:12:36 | 000,308,304 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2010/11/09 15:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2010/09/23 01:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/09/03 14:59:26 | 000,349,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/08/26 05:37:26 | 007,767,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/08/26 03:20:56 | 000,279,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/07/15 14:47:42 | 000,116,240 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2009/09/17 13:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel®
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 03:40:11 | 000,840,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\blackbox.dll -- (BlackBox)
DRV:64bit: - [2009/06/10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/12 15:53:12 | 000,020,480 | ---- | M] (Danish Wireless Design A/S) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FlashUSB_x64.sys -- (FlashUSB)
DRV:64bit: - [2008/07/24 12:04:34 | 000,115,328 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2011/06/24 11:22:27 | 000,024,448 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWow64\drivers\rkhdrv40.sys -- (rkhdrv40)
DRV - [2011/06/24 11:01:39 | 000,034,560 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWow64\drivers\Normandy.sys -- (Normandy)
DRV - [2011/06/24 11:00:27 | 000,035,712 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWow64\drivers\BlackBox.sys -- (BlackBox)
DRV - [2011/04/27 19:17:28 | 000,020,336 | ---- | M] () [File_System | On_Demand | Running] -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys -- (FileMonitor)
DRV - [2011/03/23 00:58:10 | 000,021,328 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys -- (UrlFilter)
DRV - [2011/03/23 00:58:06 | 000,033,184 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys -- (RegFilter)
DRV - [2009/05/12 15:53:12 | 000,020,480 | ---- | M] (Danish Wireless Design A/S) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\FlashUsb_x64.sys -- (FlashUSB)
DRV - [2005/01/02 05:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://nmd.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://nmd.msn.com


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2011736281-2734640664-761541749-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nmd.msn.com
IE - HKU\S-1-5-21-2011736281-2734640664-761541749-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
IE - HKU\S-1-5-21-2011736281-2734640664-761541749-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://it.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-2011736281-2734640664-761541749-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = it-IT
IE - HKU\S-1-5-21-2011736281-2734640664-761541749-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 14 EE 88 B2 77 E6 CB 01 [binary data]
IE - HKU\S-1-5-21-2011736281-2734640664-761541749-1000\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-2011736281-2734640664-761541749-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2011/04/27 10:42:04 | 000,000,000 | ---D | M]

[2011/06/13 10:01:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011/02/23 19:23:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/28 20:50:05 | 000,002,191 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml

O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [cFosSpeed] C:\Programmi\cFosSpeed\cfosspeed.exe (cFos Software GmbH)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2011736281-2734640664-761541749-1000..\Run: [BitTorrent DNA] C:\Program Files (x86)\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-21-2011736281-2734640664-761541749-1000..\Run: [puush] C:\Program Files (x86)\puush\puush.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.53.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\WB: DllName - Reg Error: Key error. - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{382da53c-9789-11e0-81cf-6c626d8c92f0}\Shell - "" = AutoRun
O33 - MountPoints2\{382da53c-9789-11e0-81cf-6c626d8c92f0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{382da53e-9789-11e0-81cf-6c626d8c92f0}\Shell - "" = AutoRun
O33 - MountPoints2\{382da53e-9789-11e0-81cf-6c626d8c92f0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{382da548-9789-11e0-81cf-6c626d8c92f0}\Shell - "" = AutoRun
O33 - MountPoints2\{382da548-9789-11e0-81cf-6c626d8c92f0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{382da54a-9789-11e0-81cf-6c626d8c92f0}\Shell - "" = AutoRun
O33 - MountPoints2\{382da54a-9789-11e0-81cf-6c626d8c92f0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{4f3f0c2a-9729-11e0-9e4e-6c626d8c92f0}\Shell - "" = AutoRun
O33 - MountPoints2\{4f3f0c2a-9729-11e0-9e4e-6c626d8c92f0}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{4f3f0c2e-9729-11e0-9e4e-6c626d8c92f0}\Shell - "" = AutoRun
O33 - MountPoints2\{4f3f0c2e-9729-11e0-9e4e-6c626d8c92f0}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/24 23:08:28 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Stardock
[2011/06/24 23:08:27 | 000,042,672 | ---- | C] (Stardock.Net, Inc) -- C:\Windows\SysWow64\wbsys.dll
[2011/06/24 23:08:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Stardock
[2011/06/24 22:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2011/06/24 22:11:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/06/24 18:47:13 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/06/24 18:47:13 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/06/24 18:47:13 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/06/24 18:47:12 | 002,303,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011/06/24 18:47:12 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
[2011/06/24 18:47:12 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/06/24 18:47:12 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/06/24 18:47:12 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/06/24 18:46:22 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2011/06/24 15:44:20 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\NVIDIA
[2011/06/24 15:41:01 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NVIDIA Demos
[2011/06/24 15:40:47 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_43.dll
[2011/06/24 15:40:47 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll
[2011/06/24 15:40:46 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_43.dll
[2011/06/24 15:40:46 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll
[2011/06/24 15:38:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2011/06/24 15:11:24 | 000,684,032 | ---- | C] (3Planesoft) -- C:\Windows\SysWow64\3Planesoft_Screensaver_Manager.scr
[2011/06/24 15:11:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\3Planesoft Screensaver Manager
[2011/06/24 15:11:24 | 000,000,000 | ---D | C] -- C:\ProgramData\3Planesoft
[2011/06/24 15:11:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3Planesoft
[2011/06/24 15:11:11 | 000,587,776 | ---- | C] (3Planesoft) -- C:\Windows\SysWow64\Sun_Village_NV_3D_Screensaver.scr
[2011/06/24 15:11:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sun Village NV 3D Screensaver
[2011/06/24 15:03:57 | 001,720,668 | ---- | C] (Macromedia, Inc.) -- C:\Windows\nv25.exe.exe
[2011/06/24 15:03:57 | 000,184,400 | ---- | C] (MacSourcery) -- C:\Windows\nv25.exe.scr
[2011/06/24 15:03:57 | 000,040,960 | ---- | C] (MacSourcery) -- C:\Windows\nv25.exe.dll
[2011/06/24 15:03:57 | 000,018,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\nv25.exe.dat
[2011/06/24 11:02:34 | 000,579,072 | ---- | C] (OldTimer Tools) -- C:\Users\Utente\Desktop\OTL.exe
[2011/06/24 11:01:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rootkit Unhooker LE
[2011/06/18 22:18:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MegaLink
[2011/06/18 22:18:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MegaLink
[2011/06/15 21:06:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alice MOBILE E169
[2011/06/15 21:06:11 | 000,691,712 | ---- | C] (DiBcom SA) -- C:\Windows\SysNative\drivers\mod7700.sys
[2011/06/15 21:06:11 | 000,133,632 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ewusbnet.sys
[2011/06/15 21:06:11 | 000,115,328 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ewusbmdm.sys
[2011/06/15 21:06:11 | 000,029,696 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\SysNative\drivers\ewdcsc.sys
[2011/06/15 21:05:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Alice MOBILE E169
[2011/06/15 10:40:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3
[2011/06/13 14:14:32 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_41.dll
[2011/06/13 14:14:32 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_41.dll
[2011/06/13 14:14:31 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_41.dll
[2011/06/13 14:14:31 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll
[2011/06/13 14:14:30 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_4.dll
[2011/06/13 14:14:30 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll
[2011/06/13 14:14:30 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll
[2011/06/13 14:14:30 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_4.dll
[2011/06/13 14:14:30 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_3.dll
[2011/06/13 14:14:29 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_40.dll
[2011/06/13 14:14:29 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll
[2011/06/13 14:14:29 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_40.dll
[2011/06/13 14:14:29 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll
[2011/06/13 14:14:29 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_40.dll
[2011/06/13 14:14:29 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll
[2011/06/13 14:14:29 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_6.dll
[2011/06/13 14:14:29 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll
[2011/06/13 14:14:28 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_3.dll
[2011/06/13 14:14:28 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll
[2011/06/13 14:14:28 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_2.dll
[2011/06/13 14:14:28 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll
[2011/06/13 14:14:28 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll
[2011/06/13 14:14:28 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_3.dll
[2011/06/13 14:14:28 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_2.dll
[2011/06/13 14:14:28 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_1.dll
[2011/06/13 14:14:28 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll
[2011/06/13 14:14:28 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll
[2011/06/13 14:14:28 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_5.dll
[2011/06/13 14:14:28 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll
[2011/06/13 14:14:27 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_39.dll
[2011/06/13 14:14:27 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll
[2011/06/13 14:14:27 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_39.dll
[2011/06/13 14:14:27 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll
[2011/06/13 14:14:27 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_39.dll
[2011/06/13 14:14:27 | 000,511,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_1.dll
[2011/06/13 14:14:27 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll
[2011/06/13 14:14:27 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll
[2011/06/13 14:14:27 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll
[2011/06/13 14:14:27 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_2.dll
[2011/06/13 14:14:27 | 000,068,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_0.dll
[2011/06/13 14:14:27 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll
[2011/06/13 14:14:25 | 001,941,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_38.dll
[2011/06/13 14:14:25 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_38.dll
[2011/06/13 14:14:25 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_38.dll
[2011/06/13 14:14:25 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_38.dll
[2011/06/13 14:14:25 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll
[2011/06/13 14:14:25 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_1.dll
[2011/06/13 14:14:25 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_4.dll
[2011/06/13 14:14:25 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_4.dll
[2011/06/13 14:14:24 | 004,991,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_38.dll
[2011/06/13 14:14:24 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_38.dll
[2011/06/13 14:14:24 | 000,489,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_0.dll
[2011/06/13 14:14:24 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_0.dll
[2011/06/13 14:14:24 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_0.dll
[2011/06/13 14:14:24 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_0.dll
[2011/06/13 14:14:23 | 001,860,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_37.dll
[2011/06/13 14:14:23 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_37.dll
[2011/06/13 14:14:23 | 000,529,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_37.dll
[2011/06/13 14:14:23 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_37.dll
[2011/06/13 14:14:23 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_3.dll
[2011/06/13 14:14:23 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_3.dll
[2011/06/13 14:14:22 | 005,081,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_36.dll
[2011/06/13 14:14:22 | 004,910,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_37.dll
[2011/06/13 14:14:22 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_37.dll
[2011/06/13 14:14:22 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_36.dll
[2011/06/13 14:14:22 | 002,006,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_36.dll
[2011/06/13 14:14:22 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_36.dll
[2011/06/13 14:14:22 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_36.dll
[2011/06/13 14:14:22 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_36.dll
[2011/06/13 14:14:22 | 000,411,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_10.dll
[2011/06/13 14:14:22 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_10.dll
[2011/06/13 14:14:21 | 005,073,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_35.dll
[2011/06/13 14:14:21 | 004,496,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_34.dll
[2011/06/13 14:14:21 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll
[2011/06/13 14:14:21 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll
[2011/06/13 14:14:21 | 001,985,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_35.dll
[2011/06/13 14:14:21 | 001,401,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_34.dll
[2011/06/13 14:14:21 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_35.dll
[2011/06/13 14:14:21 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_34.dll
[2011/06/13 14:14:21 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_35.dll
[2011/06/13 14:14:21 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_34.dll
[2011/06/13 14:14:21 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_35.dll
[2011/06/13 14:14:21 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_34.dll
[2011/06/13 14:14:21 | 000,411,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_9.dll
[2011/06/13 14:14:21 | 000,409,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_8.dll
[2011/06/13 14:14:21 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_9.dll
[2011/06/13 14:14:21 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_8.dll
[2011/06/13 14:14:21 | 000,021,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_2.dll
[2011/06/13 14:14:21 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_2.dll
[2011/06/13 14:14:20 | 004,494,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_33.dll
[2011/06/13 14:14:20 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_33.dll
[2011/06/13 14:14:20 | 001,400,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_33.dll
[2011/06/13 14:14:20 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_33.dll
[2011/06/13 14:14:20 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_33.dll
[2011/06/13 14:14:20 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_33.dll
[2011/06/13 14:14:20 | 000,403,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_7.dll
[2011/06/13 14:14:20 | 000,393,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_6.dll
[2011/06/13 14:14:20 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_7.dll
[2011/06/13 14:14:20 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_6.dll
[2011/06/13 14:14:20 | 000,107,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_3.dll
[2011/06/13 14:14:20 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_3.dll
[2011/06/13 14:14:19 | 000,469,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10.dll
[2011/06/13 14:14:19 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10.dll
[2011/06/13 14:14:19 | 000,390,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_5.dll
[2011/06/13 14:14:19 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_5.dll
[2011/06/13 14:14:18 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_31.dll
[2011/06/13 14:14:18 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll
[2011/06/13 14:14:18 | 000,364,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_4.dll
[2011/06/13 14:14:18 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_4.dll
[2011/06/13 14:14:18 | 000,017,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_1.dll
[2011/06/13 14:14:18 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_1.dll
[2011/06/13 14:14:15 | 000,363,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_3.dll
[2011/06/13 14:14:15 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_3.dll
[2011/06/13 14:14:14 | 000,354,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_2.dll
[2011/06/13 14:14:14 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_2.dll
[2011/06/13 14:14:14 | 000,083,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_2.dll
[2011/06/13 14:14:14 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_2.dll
[2011/06/13 14:14:13 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_1.dll
[2011/06/13 14:14:13 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll
[2011/06/13 14:14:12 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_1.dll
[2011/06/13 14:14:12 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll
[2011/06/13 14:13:59 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_30.dll
[2011/06/13 14:13:59 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll
[2011/06/13 14:13:58 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_29.dll
[2011/06/13 14:13:58 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_29.dll
[2011/06/13 14:13:58 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_0.dll
[2011/06/13 14:13:58 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll
[2011/06/13 14:13:58 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_0.dll
[2011/06/13 14:13:58 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll
[2011/06/13 13:46:49 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crystal Aion
[2011/06/13 13:46:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crystal Aion
[2011/06/13 12:58:30 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\Microsoft
[2011/06/12 19:29:59 | 004,120,119 | R--- | C] (Swearware) -- C:\Users\Utente\Desktop\ComboFix.exe
[2011/06/12 17:36:25 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\puush
[2011/06/12 17:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush
[2011/06/12 17:36:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\puush
[2011/06/12 12:28:52 | 000,000,000 | ---D | C] -- C:\Users\Utente\Desktop\World of Warcraft
[2011/06/12 12:06:04 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCsoft
[2011/06/12 11:57:05 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Local\assembly
[2011/06/12 11:56:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCsoft
[2011/06/12 11:56:25 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\InstallShield
[2011/06/11 23:24:22 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gamez Aion
[2011/06/11 23:24:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gamez Aion
[2011/06/11 23:24:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NCsoft
[2011/06/09 17:27:43 | 000,021,992 | ---- | C] (CPUID) -- C:\Windows\SysNative\drivers\cpuz135_x64.sys
[2011/06/09 17:27:43 | 000,000,000 | ---D | C] -- C:\Programmi\CPUID
[2011/06/09 17:27:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2011/06/08 18:07:24 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Local\PunkBuster
[2011/06/08 18:05:51 | 000,000,000 | ---D | C] -- C:\Users\Utente\Documents\Battlefield Play4Free
[2011/06/08 18:05:21 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EA Games
[2011/06/08 17:04:34 | 000,067,072 | ---- | C] (Anark Corporation) -- C:\Windows\SysWow64\AKCPanel.cpl
[2011/06/08 17:04:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Anark
[2011/06/08 14:18:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/06/07 20:01:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cFosSpeed Traffic Shaping
[2011/06/07 20:01:44 | 001,261,440 | ---- | C] (cFos Software GmbH) -- C:\Windows\SysNative\drivers\cfosspeed6.sys
[2011/06/07 20:01:44 | 000,000,000 | ---D | C] -- C:\Programmi\cFosSpeed
[2011/06/05 18:03:04 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011/06/05 17:58:13 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\alaplaya
[2011/06/04 19:15:03 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StepMania
[2011/06/04 19:15:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StepMania
[2011/06/04 19:14:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\StepMania
[2011/06/03 15:09:48 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\vlc
[2011/06/03 14:43:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/06/03 14:43:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2011/06/02 16:32:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3
[2011/06/02 16:32:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AutoIt3
[2011/05/30 17:46:52 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011/05/28 18:55:16 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011/05/28 18:52:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2011/05/28 18:52:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011/05/28 18:51:46 | 000,000,000 | ---D | C] -- C:\Programmi\Common Files\ATI Technologies
[2011/05/28 18:51:37 | 000,116,240 | ---- | C] (ATI Technologies, Inc.) -- C:\Windows\SysNative\drivers\AtihdW76.sys
[2011/05/28 18:51:22 | 000,450,560 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\ATIDEMGX.dll
[2011/05/28 18:51:22 | 000,057,344 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst.dll
[2011/05/28 18:36:22 | 000,000,000 | ---D | C] -- C:\Programmi\ATI Technologies
[2011/05/26 13:28:13 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\NPLUTO Corporation
[2011/05/26 13:14:57 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drift City (EU_ENG)
[2011/05/26 13:14:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DriftCity

========== Files - Modified Within 30 Days ==========

[2011/06/25 11:51:59 | 000,013,456 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/25 11:51:59 | 000,013,456 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/25 11:49:07 | 001,541,382 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/25 11:49:07 | 000,698,332 | ---- | M] () -- C:\Windows\SysNative\perfh010.dat
[2011/06/25 11:49:07 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/06/25 11:49:07 | 000,127,558 | ---- | M] () -- C:\Windows\SysNative\perfc010.dat
[2011/06/25 11:49:07 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/06/25 11:45:19 | 000,002,413 | ---- | M] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2011/06/25 11:44:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/25 11:44:23 | 3189,071,872 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/24 23:19:58 | 000,275,264 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/24 23:01:14 | 034,430,312 | ---- | M] () -- C:\Users\Utente\Desktop\WindowBlinds7_public.exe
[2011/06/24 22:42:20 | 000,001,180 | ---- | M] () -- C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2011/06/24 20:54:24 | 000,234,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2011/06/24 20:54:24 | 000,234,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/06/24 18:47:13 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/06/24 18:47:13 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/06/24 18:47:13 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/06/24 18:47:13 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/06/24 18:47:12 | 002,303,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011/06/24 18:47:12 | 001,797,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
[2011/06/24 18:47:12 | 000,818,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/06/24 18:47:12 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/06/24 18:46:22 | 000,861,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2011/06/24 18:05:53 | 000,001,250 | ---- | M] () -- C:\Users\Public\Desktop\Quick Care.lnk
[2011/06/24 18:05:53 | 000,001,228 | ---- | M] () -- C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/06/24 15:41:01 | 000,002,517 | ---- | M] () -- C:\Users\Utente\Desktop\Endless City.lnk
[2011/06/24 15:41:01 | 000,002,501 | ---- | M] () -- C:\Users\Utente\Desktop\Endless City Configuration.lnk
[2011/06/24 15:11:24 | 000,001,080 | ---- | M] () -- C:\Users\Utente\Desktop\3Planesoft Screensaver Manager.lnk
[2011/06/24 15:11:23 | 000,001,160 | ---- | M] () -- C:\Users\Utente\Desktop\Sun Village NV 3D Screensaver.lnk
[2011/06/24 15:03:57 | 001,720,668 | ---- | M] (Macromedia, Inc.) -- C:\Windows\nv25.exe.exe
[2011/06/24 15:03:57 | 000,184,400 | ---- | M] (MacSourcery) -- C:\Windows\nv25.exe.scr
[2011/06/24 15:03:57 | 000,040,960 | ---- | M] (MacSourcery) -- C:\Windows\nv25.exe.dll
[2011/06/24 15:03:57 | 000,018,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\nv25.exe.dat
[2011/06/24 11:22:27 | 000,024,448 | ---- | M] () -- C:\Windows\SysWow64\drivers\rkhdrv40.sys
[2011/06/24 11:02:35 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Utente\Desktop\OTL.exe
[2011/06/24 11:01:39 | 000,034,560 | ---- | M] () -- C:\Windows\SysWow64\drivers\Normandy.sys
[2011/06/24 11:00:27 | 000,035,712 | ---- | M] () -- C:\Windows\SysWow64\drivers\BlackBox.sys
[2011/06/22 11:41:47 | 004,692,877 | ---- | M] () -- C:\Users\Utente\Desktop\Sunshine project S4 League.mp3
[2011/06/21 12:07:54 | 000,001,978 | ---- | M] () -- C:\Users\Utente\Desktop\GamezAion Launcher.lnk
[2011/06/18 22:18:58 | 000,000,950 | ---- | M] () -- C:\Users\Public\Desktop\MegaLink.lnk
[2011/06/15 21:06:19 | 000,001,122 | ---- | M] () -- C:\Users\Public\Desktop\Alice MOBILE E169.lnk
[2011/06/15 10:40:30 | 000,001,189 | ---- | M] () -- C:\Users\Public\Desktop\Switch to Gaming Mode 3.lnk
[2011/06/15 10:40:30 | 000,001,177 | ---- | M] () -- C:\Users\Public\Desktop\Game Booster 3.lnk
[2011/06/13 13:46:49 | 000,001,112 | ---- | M] () -- C:\Users\Utente\Desktop\Crystal Aion Launcher.lnk
[2011/06/13 11:25:00 | 018,017,153 | ---- | M] () -- C:\Users\Utente\Desktop\bin32.rar
[2011/06/13 09:24:12 | 1275,455,315 | ---- | M] () -- C:\Users\Utente\Desktop\Aion_Main_0.0.0.0To2.1.0.12.ncpatch
[2011/06/12 19:31:09 | 004,120,119 | R--- | M] (Swearware) -- C:\Users\Utente\Desktop\ComboFix.exe
[2011/06/12 12:06:04 | 000,002,109 | ---- | M] () -- C:\Users\Utente\Desktop\Aion.lnk
[2011/06/12 11:56:55 | 000,002,035 | ---- | M] () -- C:\Users\Public\Desktop\NCsoft Launcher.lnk
[2011/06/09 17:27:43 | 000,000,876 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2011/06/08 18:05:22 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/06/08 17:04:34 | 000,072,774 | ---- | M] (Jordan Russell) -- C:\Windows\unins000.exe
[2011/06/08 17:04:34 | 000,001,080 | ---- | M] () -- C:\Windows\unins000.dat
[2011/06/08 14:32:10 | 006,078,809 | -H-- | M] () -- C:\Users\Utente\AppData\Roaming\Utentelog.dat
[2011/06/08 14:06:28 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/03 14:43:46 | 000,001,073 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/05/29 21:15:13 | 000,459,184 | ---- | M] () -- C:\Users\Utente\AppData\Local\Tempsuck3.png
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/05/26 21:51:41 | 000,633,247 | ---- | M] () -- C:\Users\Utente\AppData\Local\TempTheGUI.png
[2011/05/26 13:14:57 | 000,001,903 | ---- | M] () -- C:\Users\Utente\Desktop\Drift City (EU_ENG).lnk

========== Files Created - No Company Name ==========

[2011/06/24 23:08:29 | 000,053,904 | ---- | C] () -- C:\Windows\SysNative\wbload.dll
[2011/06/24 22:58:27 | 034,430,312 | ---- | C] () -- C:\Users\Utente\Desktop\WindowBlinds7_public.exe
[2011/06/24 22:42:20 | 000,001,180 | ---- | C] () -- C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2011/06/24 15:41:01 | 000,002,517 | ---- | C] () -- C:\Users\Utente\Desktop\Endless City.lnk
[2011/06/24 15:41:01 | 000,002,501 | ---- | C] () -- C:\Users\Utente\Desktop\Endless City Configuration.lnk
[2011/06/24 15:11:24 | 000,001,080 | ---- | C] () -- C:\Users\Utente\Desktop\3Planesoft Screensaver Manager.lnk
[2011/06/24 15:11:23 | 000,001,160 | ---- | C] () -- C:\Users\Utente\Desktop\Sun Village NV 3D Screensaver.lnk
[2011/06/24 11:22:27 | 000,024,448 | ---- | C] () -- C:\Windows\SysWow64\drivers\rkhdrv40.sys
[2011/06/24 10:57:29 | 000,034,560 | ---- | C] () -- C:\Windows\SysWow64\drivers\Normandy.sys
[2011/06/24 10:56:00 | 000,035,712 | ---- | C] () -- C:\Windows\SysWow64\drivers\BlackBox.sys
[2011/06/22 11:40:59 | 004,692,877 | ---- | C] () -- C:\Users\Utente\Desktop\Sunshine project S4 League.mp3
[2011/06/18 22:18:58 | 000,000,950 | ---- | C] () -- C:\Users\Public\Desktop\MegaLink.lnk
[2011/06/15 21:06:19 | 000,001,122 | ---- | C] () -- C:\Users\Public\Desktop\Alice MOBILE E169.lnk
[2011/06/15 10:40:30 | 000,001,189 | ---- | C] () -- C:\Users\Public\Desktop\Switch to Gaming Mode 3.lnk
[2011/06/15 10:40:30 | 000,001,177 | ---- | C] () -- C:\Users\Public\Desktop\Game Booster 3.lnk
[2011/06/13 13:46:49 | 000,001,112 | ---- | C] () -- C:\Users\Utente\Desktop\Crystal Aion Launcher.lnk
[2011/06/13 11:24:06 | 018,017,153 | ---- | C] () -- C:\Users\Utente\Desktop\bin32.rar
[2011/06/12 11:59:35 | 000,002,109 | ---- | C] () -- C:\Users\Utente\Desktop\Aion.lnk
[2011/06/12 11:56:55 | 000,002,035 | ---- | C] () -- C:\Users\Public\Desktop\NCsoft Launcher.lnk
[2011/06/11 23:24:22 | 000,001,978 | ---- | C] () -- C:\Users\Utente\Desktop\GamezAion Launcher.lnk
[2011/06/09 17:27:43 | 000,000,876 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2011/06/08 18:08:08 | 000,234,768 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2011/06/08 18:05:23 | 000,234,768 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/06/08 18:05:22 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/06/08 17:04:34 | 000,001,080 | ---- | C] () -- C:\Windows\unins000.dat
[2011/06/03 14:43:46 | 000,001,073 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/05/29 21:15:02 | 000,459,184 | ---- | C] () -- C:\Users\Utente\AppData\Local\Tempsuck3.png
[2011/05/28 18:51:22 | 000,076,216 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2011/05/28 18:51:22 | 000,021,866 | ---- | C] () -- C:\Windows\atiogl.xml
[2011/05/26 21:49:33 | 000,633,247 | ---- | C] () -- C:\Users\Utente\AppData\Local\TempTheGUI.png
[2011/05/26 13:14:57 | 000,001,903 | ---- | C] () -- C:\Users\Utente\Desktop\Drift City (EU_ENG).lnk
[2011/05/23 17:52:26 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2011/05/23 17:52:26 | 000,002,413 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2011/04/11 13:53:35 | 000,007,605 | ---- | C] () -- C:\Users\Utente\AppData\Local\Resmon.ResmonCfg
[2011/02/26 12:19:12 | 000,281,578 | ---- | C] () -- C:\Windows\SysWow64\wbers.dat.dmp
[2011/02/17 19:53:09 | 000,704,732 | ---- | C] () -- C:\Users\Utente\AppData\Roaming\test3.exe
[2011/02/06 13:33:54 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011/01/18 01:45:46 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/01/18 01:12:42 | 000,002,857 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009/07/14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/07/08 17:48:50 | 006,078,809 | -H-- | C] () -- C:\Users\Utente\AppData\Roaming\Utentelog.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:F63A059B

< End of report >





OTL Extras logfile created on: 25/06/2011 12:16:36 - Run 2
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Utente\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

3,96 Gb Total Physical Memory | 2,53 Gb Available Physical Memory | 63,90% Memory free
7,92 Gb Paging File | 6,02 Gb Available in Paging File | 76,08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 926,33 Gb Total Space | 820,94 Gb Free Space | 88,62% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 931,38 Gb Free Space | 99,99% Space Free | Partition Type: NTFS

Computer Name: UTENTE-PC | User Name: Utente | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{169C77B7-69C9-4648-9DD0-72B152AF269F}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{25B473DB-CC8D-384A-ACE7-7CFB119B7E03}" = Microsoft .NET Framework 4 Client Profile ITA Language Pack
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{5DDF6B75-2369-4D52-9867-10EFD8878185}" = AVG 2011
"{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources
"{67048E0C-29A5-534C-FF67-83C4BF948D48}" = AMD Drag and Drop Transcoding
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}" = AVG 2011
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A0008F2A-0E82-09A2-5A24-DFB31DCB3690}" = ATI Catalyst Install Manager
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{D87047B9-BBC5-9941-00B4-719B9E56CACC}" = ATI AVIVO64 Codecs
"{D9B52C63-4209-7129-BF10-FA5DCD38579E}" = ccc-utility64
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"81AE60DDD229A248055515E311406D86F7E4012A" = Pacchetto driver Windows - Infineon Technologies (FlashUSB) USB (04/16/2009 1.0.0.6)
"Adobe Flash Player ActiveX 64" = Adobe Flash Player 10 ActiveX 64-bit
"AVG" = AVG 2011
"cFosSpeed" = cFosSpeed v6.60
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.57.1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile ITA Language Pack" = Microsoft .NET Framework 4 Client Profile - Language Pack (ITA)
"Process_Hacker2_is1" = Process Hacker 2.14

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{04634A14-619B-4F53-88B3-2A48FB3A99C6}" = TwelveSky2
"{06092909-8851-C581-F990-7195076FDAEF}" = CCC Help Czech
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CA04779-346C-30FD-EB9B-8EEA2CE094B3}" = CCC Help Thai
"{1B3B5C60-70B8-F022-5497-03FD2772586C}" = CCC Help Greek
"{1C160168-BF5B-72FE-BAFA-6DD5F737404C}" = CCC Help Chinese Standard
"{1ED3EBF6-A130-4B3B-B01A-C29B067798B3}" = CCC Help Finnish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 24
"{278AD90C-D27D-AA89-58DF-AD13852D51CA}" = CCC Help Spanish
"{2CDBFF1A-6433-E94D-CA25-831FDB9775E9}" = CCC Help Italian
"{2EF94C49-4D4F-2137-26C2-4E52E36E54DF}" = Catalyst Control Center InstallProxy
"{31DED885-1124-0E58-97FB-73E4EF692E8D}" = CCC Help Hungarian
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33B670D7-8A06-DA5B-0341-5630D1E12007}" = ccc-core-static
"{38D65ABC-A00B-6E13-2EF3-826CFC8CFC14}" = CCC Help French
"{3B4325A0-43CD-10D1-64F6-BD2F90DCB756}" = Catalyst Control Center Graphics Previews Vista
"{3D0C22FA-96D7-4789-BC5B-991A5A99BFFA}" = Windows Live Messenger
"{3F8B39A4-B7CE-B036-941C-A8DB57676B04}" = CCC Help Norwegian
"{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack
"{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4ACF9BBA-E137-7309-7BF9-567ADAB6B4E6}" = CCC Help Turkish
"{51AD839D-CE11-B9E3-227D-03BC89F227C8}" = CCC Help Danish
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{5774B4C1-8579-D5D9-8D38-A0CE32B6736C}" = CCC Help German
"{5D19BB0D-9B04-5B85-9295-4E11BCB1C2C3}" = CCC Help Polish
"{5E7A8F05-013C-44FD-B450-5434CA581098}_is1" = MicroVolts
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher
"{60341104-FC8E-EF26-12CB-93B17DF55976}" = CCC Help Japanese
"{62161867-51F1-9FB8-0E6E-FE49D89CBB71}" = CCC Help Dutch
"{65589581-920C-CAE1-58C2-2149D3AA3F39}" = HydraVision
"{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A7E9B60-4698-F505-CAD3-05F8AB22FB61}" = CCC Help Russian
"{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common
"{75794DD1-5D69-4E33-A141-C3D4B0724C71}" = Catalyst Control Center Graphics Previews Common
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7CE47764-9A8F-380D-FB9E-FCFC37B9F727}" = CCC Help Korean
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}" = REACTOR
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{9ED77550-AF66-2B7E-97E1-34B3BFDEAC6D}" = CCC Help Swedish
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1040-7B44-AA0000000001}" = Adobe Reader X - Italiano
"{BBB7F293-12A9-821C-9409-013CD8E824EC}" = Application Profiles
"{C3592426-531E-4110-911D-BFECE2CE284B}" = puush
"{C3592426-531E-4110-911D-BFECE2CE284C}" = osu!
"{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections
"{C7DAD22D-29D4-438F-B986-03B9ED582EA4}" = Messenger Companion
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}" = WinZip 15.0
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1E502E2-C006-49DB-9C0C-F2196E51826F}_is1" = Rootkit Unhooker LE 3.8 SR 2
"{E8454B5F-4122-864C-002D-31F878D2CBF4}" = CCC Help English
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E6252F-8DC2-B508-D412-1C427CDB3448}" = CCC Help Portuguese
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FCB6F9DC-A0FF-621E-DE53-877E63864DD1}" = CCC Help Chinese Traditional
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE4466A3-76B3-A9F4-9B22-150D6F8B4647}" = Catalyst Control Center Localization All
"{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker
"3Planesoft Screensaver Manager_is1" = 3Planesoft Screensaver Manager 1.4
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"Akamai" = Akamai NetSession Interface
"Alice MOBILE E169" = Alice MOBILE E169
"AnarkClient" = Anark Client 1.0
"AutoItv3" = AutoIt v3.3.6.1
"Cheat Engine 6.0_is1" = Cheat Engine 6.0
"DriftCity_EU_eng" = Drift City (EU_ENG)
"Endless City" = NVIDIA Endless City demo
"FantasyTennis" = FantasyTennis
"Flazheus Manager Beta" = Flazheus Manager Beta 1.0
"Fraps" = Fraps (remove only)
"Game Booster 3_is1" = Game Booster
"Game Booster_is1" = Game Booster
"Infineon USB driver_is1" = Infineon USB driver 1.0.0.6
"IObit Malware Fighter_is1" = IObit Malware Fighter
"JDownloader" = JDownloader
"KitsuSaga" = KitsuSaga
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware versione 1.51.0.1200
"MegaLink_is1" = MegaLink 2.14
"NVIDIA Screen Saver_is1" = NVIDIA Screen Saver 1.2
"PunkBusterSvc" = PunkBuster Services
"StepMania" = StepMania (remove only)
"Sun Village NV 3D Screensaver_is1" = Sun Village NV 3D Screensaver 1.1
"TeamViewer 6" = TeamViewer 6
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.9
"WavePad" = WavePad Sound Editor
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 (32-bit)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2011736281-2734640664-761541749-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free (Utente)
"BitTorrent DNA" = DNA
"NCsoft-Aion" = Aion
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinImage" = WinImage

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 13/06/2011 07:20:22 | Computer Name = Utente-PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: aion.bin, versione:
2111.1201.408.4039, timestamp: 0x4d9ec3e6 Nome del modulo che ha generato l'errore:
CrySystem.dll, versione: 2111.1201.408.4039, timestamp: 0x4d9ebc28 Codice eccezione:
0xc0000005 Offset errore 0x0001274c ID processo che ha generato l'errore: 0x4f0 Ora
di avvio dell'applicazione che ha generato l'errore: 0x01cc29bbdb11a505 Percorso
dell'applicazione che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\aion.bin
Percorso
del modulo che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\CrySystem.dll
ID
segnalazione: 20892f5c-95af-11e0-8644-6c626d8c92f0

Error - 13/06/2011 07:24:01 | Computer Name = Utente-PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: aion.bin, versione:
2111.1201.408.4039, timestamp: 0x4d9ec3e6 Nome del modulo che ha generato l'errore:
CrySystem.dll, versione: 2111.1201.408.4039, timestamp: 0x4d9ebc28 Codice eccezione:
0xc0000005 Offset errore 0x0001274c ID processo che ha generato l'errore: 0xb98 Ora
di avvio dell'applicazione che ha generato l'errore: 0x01cc29bc601c6a2d Percorso
dell'applicazione che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\aion.bin
Percorso
del modulo che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\CrySystem.dll
ID
segnalazione: a3111244-95af-11e0-8644-6c626d8c92f0

Error - 13/06/2011 07:30:50 | Computer Name = Utente-PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: aion.bin, versione:
2111.1201.408.4039, timestamp: 0x4d9ec3e6 Nome del modulo che ha generato l'errore:
CrySystem.dll, versione: 2111.1201.408.4039, timestamp: 0x4d9ebc28 Codice eccezione:
0xc0000005 Offset errore 0x0001274c ID processo che ha generato l'errore: 0xb90 Ora
di avvio dell'applicazione che ha generato l'errore: 0x01cc29bd530cd69b Percorso
dell'applicazione che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\aion.bin
Percorso
del modulo che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\CrySystem.dll
ID
segnalazione: 96907076-95b0-11e0-8644-6c626d8c92f0

Error - 13/06/2011 07:44:00 | Computer Name = Utente-PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: aion.bin, versione:
2111.1201.408.4039, timestamp: 0x4d9ec3e6 Nome del modulo che ha generato l'errore:
CrySystem.dll, versione: 2111.1201.408.4039, timestamp: 0x4d9ebc28 Codice eccezione:
0xc0000005 Offset errore 0x0001274c ID processo che ha generato l'errore: 0xd8c Ora
di avvio dell'applicazione che ha generato l'errore: 0x01cc29bf29f96084 Percorso
dell'applicazione che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\aion.bin
Percorso
del modulo che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\CrySystem.dll
ID
segnalazione: 6d3fd224-95b2-11e0-8644-6c626d8c92f0

Error - 13/06/2011 07:44:22 | Computer Name = Utente-PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: aion.bin, versione:
2111.1201.408.4039, timestamp: 0x4d9ec3e6 Nome del modulo che ha generato l'errore:
CrySystem.dll, versione: 2111.1201.408.4039, timestamp: 0x4d9ebc28 Codice eccezione:
0xc0000005 Offset errore 0x0001274c ID processo che ha generato l'errore: 0x13c4 Ora
di avvio dell'applicazione che ha generato l'errore: 0x01cc29bf37c0552c Percorso
dell'applicazione che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\aion.bin
Percorso
del modulo che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\CrySystem.dll
ID
segnalazione: 7ad9bb88-95b2-11e0-8644-6c626d8c92f0

Error - 13/06/2011 08:00:11 | Computer Name = Utente-PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: aion.bin, versione:
2511.302.520.4206, timestamp: 0x4dd5b9c1 Nome del modulo che ha generato l'errore:
CrySystem.dll, versione: 2511.302.520.4206, timestamp: 0x4dd5b59e Codice eccezione:
0xc0000005 Offset errore 0x0001328c ID processo che ha generato l'errore: 0xaf8 Ora
di avvio dell'applicazione che ha generato l'errore: 0x01cc29c15c6989f8 Percorso
dell'applicazione che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\aion.bin
Percorso
del modulo che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\CrySystem.dll
ID
segnalazione: b042aa30-95b4-11e0-8644-6c626d8c92f0

Error - 14/06/2011 10:55:25 | Computer Name = Utente-PC | Source = SideBySide | ID = 16842785
Description = Generazione del contesto di attivazione non riuscita per "C:\Program
Files (x86)\NCsoft\Aion\bin32\MFC80.DLL". Impossibile trovare l'assembly dipendente
Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0".
Utilizzare
sxstrace.exe per ottenere una diagnosi dettagliata.

Error - 14/06/2011 10:55:25 | Computer Name = Utente-PC | Source = SideBySide | ID = 16842785
Description = Generazione del contesto di attivazione non riuscita per "C:\Program
Files (x86)\NCsoft\Aion\bin32\MFC80.DLL". Impossibile trovare l'assembly dipendente
Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0".
Utilizzare
sxstrace.exe per ottenere una diagnosi dettagliata.

Error - 14/06/2011 10:55:27 | Computer Name = Utente-PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: aion.bin, versione:
2511.302.520.4206, timestamp: 0x4dd5b9c1 Nome del modulo che ha generato l'errore:
Game.dll, versione: 2511.302.520.4206, timestamp: 0x4dd5c44c Codice eccezione: 0xc0000005
Offset
errore 0x00174300 ID processo che ha generato l'errore: 0xbe8 Ora di avvio dell'applicazione
che ha generato l'errore: 0x01cc2a94a3080d30 Percorso dell'applicazione che ha generato
l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\aion.bin Percorso del modulo
che ha generato l'errore: C:\Program Files (x86)\NCsoft\Aion\bin32\Game.dll ID segnalazione:
5693860b-9696-11e0-bc75-6c626d8c92f0

Error - 15/06/2011 15:49:59 | Computer Name = Utente-PC | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: svchost.exe_RasMan,
versione: 6.1.7600.16385, timestamp: 0x4a5bc3c1 Nome del modulo che ha generato
l'errore: msvcrt.dll, versione: 7.0.7600.16385, timestamp: 0x4a5bdfbe Codice eccezione:
0xc0000005 Offset errore 0x00000000000016cb ID processo che ha generato l'errore:
0x170 Ora di avvio dell'applicazione che ha generato l'errore: 0x01cc2b3619777146
Percorso
dell'applicazione che ha generato l'errore: C:\Windows\system32\svchost.exe Percorso
del modulo che ha generato l'errore: C:\Windows\system32\msvcrt.dll ID segnalazione:
a63c3289-9788-11e0-9e4e-6c626d8c92f0

[ System Events ]
Error - 24/06/2011 17:20:54 | Computer Name = Utente-PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Provider Gruppo Home dipende dal servizio Host provider
di individuazione funzioni che non è stato avviato per il seguente errore: %%1058

Error - 25/06/2011 04:52:24 | Computer Name = Utente-PC | Source = volmgr | ID = 262190
Description = Impossibile inizializzare i dettagli arresto anomalo del sistema.

Error - 25/06/2011 04:52:30 | Computer Name = Utente-PC | Source = volmgr | ID = 262190
Description = Impossibile inizializzare i dettagli arresto anomalo del sistema.

Error - 25/06/2011 04:53:08 | Computer Name = Utente-PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Provider Gruppo Home dipende dal servizio Host provider
di individuazione funzioni che non è stato avviato per il seguente errore: %%1058

Error - 25/06/2011 05:00:54 | Computer Name = Utente-PC | Source = Service Control Manager | ID = 7034
Description = Arresto imprevista del servizio IMF Service. Questo evento si è già
verificato 1 volta(e).

Error - 25/06/2011 05:00:58 | Computer Name = Utente-PC | Source = Service Control Manager | ID = 7034
Description = Arresto imprevista del servizio MBAMService. Questo evento si è già
verificato 1 volta(e).

Error - 25/06/2011 05:06:43 | Computer Name = Utente-PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Provider Gruppo Home dipende dal servizio Host provider
di individuazione funzioni che non è stato avviato per il seguente errore: %%1058

Error - 25/06/2011 05:44:18 | Computer Name = Utente-PC | Source = volmgr | ID = 262190
Description = Impossibile inizializzare i dettagli arresto anomalo del sistema.

Error - 25/06/2011 05:44:25 | Computer Name = Utente-PC | Source = volmgr | ID = 262190
Description = Impossibile inizializzare i dettagli arresto anomalo del sistema.

Error - 25/06/2011 05:44:57 | Computer Name = Utente-PC | Source = Service Control Manager | ID = 7001
Description = Il servizio Provider Gruppo Home dipende dal servizio Host provider
di individuazione funzioni che non è stato avviato per il seguente errore: %%1058


< End of report >

Edited by SweetTech, 25 June 2011 - 10:27 AM.
expanded logs.--ST


#7 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:03:48 PM

Posted 25 June 2011 - 10:33 AM

Hi!

Please see the following from my intro speech:

Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.

It makes it easier to work with the logs if they are poted in the body of the text.

----------

Do you recognize this file?

C:\Users\Utente\AppData\Roaming\test3.exe




OTL Fix

We need to run an OTL Fix
  • Please reopen Posted Image on your desktop.
  • Copy and Paste the following code into the Posted Image textbox.
    :Services
    :OTL
    IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    IE - HKU\S-1-5-21-2011736281-2734640664-761541749-1000\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    [2011/02/23 19:23:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    [2011/03/28 20:50:05 | 000,002,191 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
    O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
    O20:64bit: - Winlogon\Notify\WB: DllName - Reg Error: Key error. - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O33 - MountPoints2\{382da53c-9789-11e0-81cf-6c626d8c92f0}\Shell - "" = AutoRun
    O33 - MountPoints2\{382da53c-9789-11e0-81cf-6c626d8c92f0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{382da53e-9789-11e0-81cf-6c626d8c92f0}\Shell - "" = AutoRun
    O33 - MountPoints2\{382da53e-9789-11e0-81cf-6c626d8c92f0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{382da548-9789-11e0-81cf-6c626d8c92f0}\Shell - "" = AutoRun
    O33 - MountPoints2\{382da548-9789-11e0-81cf-6c626d8c92f0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{382da54a-9789-11e0-81cf-6c626d8c92f0}\Shell - "" = AutoRun
    O33 - MountPoints2\{382da54a-9789-11e0-81cf-6c626d8c92f0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{4f3f0c2a-9729-11e0-9e4e-6c626d8c92f0}\Shell - "" = AutoRun
    O33 - MountPoints2\{4f3f0c2a-9729-11e0-9e4e-6c626d8c92f0}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{4f3f0c2e-9729-11e0-9e4e-6c626d8c92f0}\Shell - "" = AutoRun
    O33 - MountPoints2\{4f3f0c2e-9729-11e0-9e4e-6c626d8c92f0}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    [2011/06/24 11:22:27 | 000,024,448 | ---- | M] () -- C:\Windows\SysWow64\drivers\rkhdrv40.sys
    [2011/06/24 11:00:27 | 000,035,712 | ---- | M] () -- C:\Windows\SysWow64\drivers\BlackBox.sys
    @Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:F63A059B
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
    
  • Push Posted Image
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click the OK button.
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:


Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Make sure that the option "Remove found threats" is Unchecked
  • When the Computer scan settings display shows, click the Advanced option, the place a check next to the following (if it is not already checked):
    • Enable Anti-Stealth technology
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


NEXT:



What outstanding issues are you currently experiencing with your computer?

Edited by SweetTech, 25 June 2011 - 10:34 AM.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.


#8 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:03:48 PM

Posted 28 June 2011 - 09:06 AM

Are you still with me?

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.


#9 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:03:48 PM

Posted 29 June 2011 - 10:24 AM

Due to lack of feedback this thread will now be closed. If you still require assistance, and would like to have your thread re-opened, please feel free to send me a Private Message (PM) being sure to include a link to your topic, and I'd be happy to re-open it.


Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users