Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Stop C0000135 Error after turn off when pc load windows


  • This topic is locked This topic is locked
11 replies to this topic

#1 iliadawah

iliadawah

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:09:20 AM

Posted 13 October 2013 - 10:57 AM

Problems: Windows don't run and appear a blue screen "Stop C0000135 Error" bla bla bla

i read this topic and i follow guide -> http://www.bleepingcomputer.com/forums/t/425808/stop-c0000135-error-after-windows-7-sp1-x64-update/

sorry for my simple and bad english :thumbdown:

 

Thank you for helping me. Here is the text file:

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by SYSTEM on MININT-52FA5VT on 13-10-2013 17:20:02
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-11] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-13] (Synaptics Incorporated)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-06-20] (Microsoft Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [415680 2012-02-05] (Autodesk, Inc.)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-15] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-03-16] (EasyBits Software AS)
HKLM-x32\...\Run: [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-09-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-04-30] (Apple Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.)
HKU\Gianlu\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\Gianlu\...\Run: [Spotify Web Helper] - C:\Users\Gianlu\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-10-03] (Spotify Ltd)
HKU\Gianlu\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-20] (Skype Technologies S.A.)
HKU\Gianlu\...\Run: [Spotify] - C:\Users\Gianlu\AppData\Roaming\Spotify\spotify.exe [4736000 2013-10-03] (Spotify Ltd)
HKU\Gianlu\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-09-04] (Samsung)
HKU\Gianlu\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKU\Gianlu\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung)

==================== Services (Whitelisted) =================

S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-06-20] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-06-20] (Microsoft Corporation)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-13] (Microsoft Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [759192 2013-09-02] (Tunngle.net GmbH)
S4 Akamai; C:/Program Files (x86)/Common Files/Akamai/netsession_win_4f7fccd.dll [x]

==================== Drivers (Whitelisted) ====================

S1 CSN5PDTS82x64; C:\Windows\System32\Drivers\CSN5PDTS82x64.sys [34840 2010-05-20] (Colasoft Co., Ltd.)
S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-26] (DT Soft Ltd)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation)
S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation)
S3 ss_bserd; C:\Windows\System32\DRIVERS\ss_bserd.sys [128000 2009-09-18] (MCCI Corporation)
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-15] (Tunngle.net)
S1 CSN5PDTS82; System32\Drivers\CSN5PDTS82.sys [x]
S3 X6va009; \??\C:\Windows\SysWOW64\Drivers\X6va009 [x]
S3 X6va010; \??\C:\Windows\SysWOW64\Drivers\X6va010 [x]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-13 17:19 - 2013-10-13 17:19 - 00000000 ____D C:\FRST
2013-10-12 06:30 - 2013-10-12 06:30 - 00000000 ____D C:\Users\Gianlu\Downloads\Final Fantasy 9 ITA by vivalaraza
2013-10-11 17:05 - 2013-10-11 17:05 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\Dropbox
2013-10-11 17:04 - 2013-10-11 17:04 - 35289176 _____ (Dropbox, Inc.) C:\Users\Gianlu\Downloads\Dropbox 2.4.2.exe
2013-10-01 14:39 - 2013-10-01 14:39 - 00000000 _____ C:\Windows\SysWOW64\sho35D3.tmp
2013-10-01 13:03 - 2013-10-13 16:51 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Update.AIO.1.to.10-FTS
2013-10-01 13:03 - 2013-10-13 16:51 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Update.12-FTS
2013-10-01 13:03 - 2013-10-13 16:51 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Update.11-FTS
2013-10-01 13:03 - 2013-10-13 16:51 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Update.11.HOTFIX-FTS
2013-10-01 12:50 - 2013-10-01 12:50 - 00296304 _____ C:\Users\Gianlu\Downloads\PAYDAY.2.LAN.Fix-RVTFiX.rar
2013-10-01 11:20 - 2013-10-01 11:20 - 00001938 _____ C:\Users\Gianlu\Downloads\render settings DauG.txt
2013-10-01 11:08 - 2013-10-02 11:22 - 00000000 ____D C:\Users\Gianlu\AppData\Local\PAYDAY 2
2013-10-01 10:56 - 2013-10-01 10:56 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-01 10:56 - 2013-10-01 10:56 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-10-01 10:55 - 2013-10-01 10:55 - 00001647 _____ C:\Users\Gianlu\Desktop\Play PAYDAY 2.lnk
2013-10-01 10:34 - 2013-10-01 10:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-01 06:01 - 2013-10-01 06:01 - 00000000 ____H C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2013-10-01 05:21 - 2013-10-01 05:21 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-01 05:07 - 2013-10-01 05:07 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-10-01 05:07 - 2013-10-01 05:07 - 00000000 ____D C:\Users\Gianlu\Documents\samsung
2013-10-01 05:07 - 2013-10-01 05:07 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\Samsung
2013-10-01 05:07 - 2013-10-01 05:07 - 00000000 ____D C:\Users\Gianlu\AppData\Local\Samsung
2013-10-01 05:05 - 2013-07-18 04:33 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll
2013-10-01 05:05 - 2013-07-18 04:32 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll
2013-10-01 05:04 - 2013-10-01 05:06 - 00000000 ____D C:\ProgramData\Samsung
2013-10-01 05:04 - 2013-10-01 05:06 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-10-01 04:57 - 2013-10-01 04:58 - 70111336 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Gianlu\Downloads\KiesSetup.exe
2013-09-30 05:06 - 2013-09-30 05:06 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\OpenOffice
2013-09-23 11:45 - 2013-09-23 11:45 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-23 11:43 - 2013-09-23 11:43 - 00000000 ____D C:\Users\Gianlu\Desktop\OpenOffice 4.0.0 (it) Installation Files
2013-09-23 11:41 - 2013-09-23 11:43 - 138823014 _____ C:\Users\Gianlu\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_it.exe
2013-09-23 04:27 - 2013-10-13 16:51 - 00000000 ____D C:\Users\Gianlu\Downloads\Guns 'n' Roses - Greatest Hits [Mp3 ~ 320Kbs][Rock City][Colombo-BT.i2p]
2013-09-22 01:58 - 2013-09-22 01:58 - 00012800 ___SH C:\Users\Gianlu\Downloads\Thumbs.db
2013-09-18 07:55 - 2013-09-18 07:55 - 00258775 _____ C:\Users\Gianlu\Downloads\(2695 non letti) - mar.longo - Yahoo Mail.htm
2013-09-18 07:55 - 2013-09-18 07:55 - 00000000 ____D C:\Users\Gianlu\Downloads\(2695 non letti) - mar.longo - Yahoo Mail_files
2013-09-17 05:02 - 2013-10-13 16:51 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Steamworks.Fix.Proper.V3-RVTFiX
2013-09-17 04:57 - 2013-10-13 16:51 - 00000000 ____D C:\Users\Gianlu\Downloads\PayDay 2 PC full game ^^nosTEAM^^
2013-09-15 04:45 - 2013-10-03 11:39 - 00000000 ____D C:\ProgramData\Tunngle
2013-09-15 04:45 - 2013-09-15 04:45 - 00000000 ____D C:\Users\Public\Documents\Tunngle
2013-09-15 04:43 - 2013-09-15 04:44 - 04068392 _____ (Tunngle.net GmbH                                            ) C:\Users\Gianlu\Downloads\Tunngle_Setup_v4.5.1.3.exe
2013-09-14 10:49 - 2013-09-14 10:49 - 00000000 ____D C:\Users\Gianlu\AppData\Local\FLT
2013-09-14 10:42 - 2013-09-14 10:42 - 00002204 _____ C:\Users\Public\Desktop\XCOM Enemy Unknown.lnk
2013-09-14 10:24 - 2013-09-14 10:24 - 00000000 ____D C:\Program Files (x86)\XCOM Enemy Unknown
2013-09-14 01:45 - 2013-09-14 01:45 - 00905728 _____ C:\Users\Gianlu\Downloads\EqualifySetup.msi
2013-09-14 01:45 - 2013-09-14 01:45 - 00000000 ____D C:\Program Files (x86)\Spotify

==================== One Month Modified Files and Folders =======

2013-10-13 17:19 - 2013-10-13 17:19 - 00000000 ____D C:\FRST
2013-10-13 16:52 - 2012-05-26 10:29 - 00000000 ____D C:\users\Gianlu
2013-10-13 16:51 - 2013-10-01 13:03 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Update.AIO.1.to.10-FTS
2013-10-13 16:51 - 2013-10-01 13:03 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Update.12-FTS
2013-10-13 16:51 - 2013-10-01 13:03 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Update.11-FTS
2013-10-13 16:51 - 2013-10-01 13:03 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Update.11.HOTFIX-FTS
2013-10-13 16:51 - 2013-09-23 04:27 - 00000000 ____D C:\Users\Gianlu\Downloads\Guns 'n' Roses - Greatest Hits [Mp3 ~ 320Kbs][Rock City][Colombo-BT.i2p]
2013-10-13 16:51 - 2013-09-17 05:02 - 00000000 ____D C:\Users\Gianlu\Downloads\PAYDAY.2.Steamworks.Fix.Proper.V3-RVTFiX
2013-10-13 16:51 - 2013-09-17 04:57 - 00000000 ____D C:\Users\Gianlu\Downloads\PayDay 2 PC full game ^^nosTEAM^^
2013-10-13 16:51 - 2013-09-09 04:51 - 00000000 ____D C:\Users\Gianlu\Downloads\XCOM_Enemy_Unknown-FLT
2013-10-13 16:51 - 2013-08-19 08:09 - 00000000 ____D C:\Users\Gianlu\Documents\Minecraft
2013-10-13 16:51 - 2013-03-19 04:22 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\Spotify
2013-10-13 16:51 - 2013-03-13 18:00 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-13 16:51 - 2013-01-18 12:54 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\Tunngle
2013-10-13 16:51 - 2012-07-19 03:30 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\uTorrent
2013-10-13 16:51 - 2012-05-31 11:33 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\Hamachi
2013-10-13 16:51 - 2012-05-26 11:41 - 00000000 ____D C:\ProgramData\PMB Files
2013-10-13 16:51 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-10-13 16:51 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\AppCompat
2013-10-13 16:50 - 2013-03-13 18:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-13 16:50 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-10-13 16:47 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2013-10-13 16:43 - 2012-05-26 10:41 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\Skype
2013-10-12 06:36 - 2012-05-26 11:41 - 00000000 ____D C:\Users\Gianlu\AppData\Local\PMB Files
2013-10-12 06:30 - 2013-10-12 06:30 - 00000000 ____D C:\Users\Gianlu\Downloads\Final Fantasy 9 ITA by vivalaraza
2013-10-11 17:05 - 2013-10-11 17:05 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\Dropbox
2013-10-11 17:04 - 2013-10-11 17:04 - 35289176 _____ (Dropbox, Inc.) C:\Users\Gianlu\Downloads\Dropbox 2.4.2.exe
2013-10-09 06:13 - 2013-08-14 19:19 - 00000000 ____D C:\Windows\System32\MRT
2013-10-09 06:07 - 2011-09-17 11:07 - 01756000 _____ C:\Windows\WindowsUpdate.log
2013-10-09 05:10 - 2012-05-26 10:48 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 05:10 - 2012-05-26 10:48 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 05:10 - 2012-05-26 10:48 - 00003916 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 05:10 - 2012-05-26 10:48 - 00000978 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-09 04:58 - 2012-10-10 11:25 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\TS3Client
2013-10-09 03:19 - 2009-07-13 20:45 - 00032064 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-09 03:19 - 2009-07-13 20:45 - 00032064 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-09 03:12 - 2012-11-17 08:40 - 00050983 _____ C:\Windows\setupact.log
2013-10-09 03:12 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-08 12:05 - 2012-05-26 10:36 - 00003954 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{86BA0543-E562-42F9-8D90-CF594F146E09}
2013-10-07 12:34 - 2012-05-31 12:20 - 00000000 ____D C:\Users\Gianlu\AppData\Local\CrashDumps
2013-10-07 10:13 - 2013-03-19 04:22 - 00000000 ____D C:\Users\Gianlu\AppData\Local\Spotify
2013-10-03 11:39 - 2013-09-15 04:45 - 00000000 ____D C:\ProgramData\Tunngle
2013-10-02 11:22 - 2013-10-01 11:08 - 00000000 ____D C:\Users\Gianlu\AppData\Local\PAYDAY 2
2013-10-02 03:50 - 2012-05-26 10:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-01 14:39 - 2013-10-01 14:39 - 00000000 _____ C:\Windows\SysWOW64\sho35D3.tmp
2013-10-01 12:50 - 2013-10-01 12:50 - 00296304 _____ C:\Users\Gianlu\Downloads\PAYDAY.2.LAN.Fix-RVTFiX.rar
2013-10-01 12:48 - 2012-11-07 13:56 - 00000000 ____D C:\Program Files (x86)\Steam
2013-10-01 11:20 - 2013-10-01 11:20 - 00001938 _____ C:\Users\Gianlu\Downloads\render settings DauG.txt
2013-10-01 11:05 - 2012-10-10 11:25 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2013-10-01 10:56 - 2013-10-01 10:56 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-01 10:56 - 2013-10-01 10:56 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-10-01 10:55 - 2013-10-01 10:55 - 00001647 _____ C:\Users\Gianlu\Desktop\Play PAYDAY 2.lnk
2013-10-01 10:55 - 2013-03-26 12:31 - 00000000 ____D C:\Games
2013-10-01 10:51 - 2013-10-01 10:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-01 10:51 - 2012-05-26 10:47 - 00000000 ____D C:\Users\Gianlu\AppData\Local\Mozilla
2013-10-01 06:01 - 2013-10-01 06:01 - 00000000 ____H C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2013-10-01 05:21 - 2013-10-01 05:21 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-01 05:07 - 2013-10-01 05:07 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-10-01 05:07 - 2013-10-01 05:07 - 00000000 ____D C:\Users\Gianlu\Documents\samsung
2013-10-01 05:07 - 2013-10-01 05:07 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\Samsung
2013-10-01 05:07 - 2013-10-01 05:07 - 00000000 ____D C:\Users\Gianlu\AppData\Local\Samsung
2013-10-01 05:06 - 2013-10-01 05:04 - 00000000 ____D C:\ProgramData\Samsung
2013-10-01 05:06 - 2013-10-01 05:04 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-10-01 05:05 - 2011-06-23 05:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-01 05:01 - 2012-08-16 10:45 - 00000000 ____D C:\Users\Gianlu\AppData\Local\Downloaded Installations
2013-10-01 04:58 - 2013-10-01 04:57 - 70111336 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Gianlu\Downloads\KiesSetup.exe
2013-10-01 03:33 - 2012-06-03 17:37 - 00000000 ___RD C:\Users\Gianlu\Desktop\Gianlu
2013-10-01 03:31 - 2013-05-08 04:12 - 00039950 _____ C:\Windows\DPINST.LOG
2013-10-01 03:30 - 2012-07-04 15:04 - 00002026 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2013-09-30 05:06 - 2013-09-30 05:06 - 00000000 ____D C:\Users\Gianlu\AppData\Roaming\OpenOffice
2013-09-25 10:18 - 2013-07-12 11:42 - 00000000 ____D C:\Users\Gianlu\Downloads\Rob.Zombie-Venomous.Rat.Regeneration.Vendor
2013-09-23 15:17 - 2012-05-26 10:35 - 00096424 _____ C:\Users\Gianlu\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-23 15:15 - 2009-07-13 20:45 - 00370056 _____ C:\Windows\System32\FNTCACHE.DAT
2013-09-23 11:45 - 2013-09-23 11:45 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-23 11:43 - 2013-09-23 11:43 - 00000000 ____D C:\Users\Gianlu\Desktop\OpenOffice 4.0.0 (it) Installation Files
2013-09-23 11:43 - 2013-09-23 11:41 - 138823014 _____ C:\Users\Gianlu\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_it.exe
2013-09-23 03:14 - 2012-05-26 10:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-09-23 03:14 - 2012-05-26 10:41 - 00000000 ____D C:\ProgramData\Skype
2013-09-22 02:01 - 2012-08-15 09:16 - 00000000 ____D C:\Users\Gianlu\Downloads\fun.-Some Nights (2012) 320Kbit(mp3) DMT
2013-09-22 01:58 - 2013-09-22 01:58 - 00012800 ___SH C:\Users\Gianlu\Downloads\Thumbs.db
2013-09-18 12:15 - 2012-12-17 13:14 - 00003192 _____ C:\Windows\System32\Tasks\HPCeeScheduleForGianlu
2013-09-18 12:15 - 2012-12-17 13:14 - 00000336 _____ C:\Windows\Tasks\HPCeeScheduleForGianlu.job
2013-09-18 07:55 - 2013-09-18 07:55 - 00258775 _____ C:\Users\Gianlu\Downloads\(2695 non letti) - mar.longo - Yahoo Mail.htm
2013-09-18 07:55 - 2013-09-18 07:55 - 00000000 ____D C:\Users\Gianlu\Downloads\(2695 non letti) - mar.longo - Yahoo Mail_files
2013-09-15 04:45 - 2013-09-15 04:45 - 00000000 ____D C:\Users\Public\Documents\Tunngle
2013-09-15 04:45 - 2013-01-18 12:54 - 00000991 _____ C:\Users\Public\Desktop\Tunngle beta.lnk
2013-09-15 04:45 - 2013-01-18 12:54 - 00000000 ____D C:\Program Files (x86)\Tunngle
2013-09-15 04:44 - 2013-09-15 04:43 - 04068392 _____ (Tunngle.net GmbH                                            ) C:\Users\Gianlu\Downloads\Tunngle_Setup_v4.5.1.3.exe
2013-09-14 10:49 - 2013-09-14 10:49 - 00000000 ____D C:\Users\Gianlu\AppData\Local\FLT
2013-09-14 10:49 - 2012-11-13 09:27 - 00000000 ____D C:\Users\Gianlu\Documents\My Games
2013-09-14 10:43 - 2012-12-26 01:27 - 00053613 _____ C:\Windows\DirectX.log
2013-09-14 10:42 - 2013-09-14 10:42 - 00002204 _____ C:\Users\Public\Desktop\XCOM Enemy Unknown.lnk
2013-09-14 10:24 - 2013-09-14 10:24 - 00000000 ____D C:\Program Files (x86)\XCOM Enemy Unknown
2013-09-14 01:45 - 2013-09-14 01:45 - 00905728 _____ C:\Users\Gianlu\Downloads\EqualifySetup.msi
2013-09-14 01:45 - 2013-09-14 01:45 - 00000000 ____D C:\Program Files (x86)\Spotify
2013-09-13 04:00 - 2012-08-17 06:15 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk

Some content of TEMP:
====================
C:\Users\Gianlu\AppData\Local\Temp\APNStub.exe
C:\Users\Gianlu\AppData\Local\Temp\DTLite4461-0327.exe
C:\Users\Gianlu\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Gianlu\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Gianlu\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Gianlu\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Gianlu\AppData\Local\Temp\SkypeSetup.exe


==================== Known DLLs (Whitelisted) ================

C:\Windows\System32\LPK.dll IS MISSING <==== ATTENTION!
C:\Windows\SysWOW64\LPK.dll IS MISSING <==== ATTENTION!

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

4
Restore point made on: 2013-10-03 10:23:18
Restore point made on: 2013-10-06 10:51:15
Restore point made on: 2013-10-08 05:25:30
Restore point made on: 2013-10-09 06:07:36

==================== Memory info ===========================

Percentage of memory in use: 14%
Total physical RAM: 6091.86 MB
Available physical RAM: 5222.26 MB
Total Pagefile: 6090.01 MB
Available Pagefile: 5223.93 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:450.97 GB) (Free:135.3 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (RECOVERY) (Fixed) (Total:14.5 GB) (Free:1.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
Drive h: (KINGSTON) (Removable) (Total:14.63 GB) (Free:8.05 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 34087946)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=451 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=14 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 15 GB) (Disk ID: C3072E18)
Partition 1: (Not Active) - (Size=15 GB) - (Type=0C)


LastRegBack: 2013-10-11 02:01

==================== End Of Log ============================

 



BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:20 AM

Posted 13 October 2013 - 12:26 PM

Hello iliadawah

I would like to welcome you to the Malware Removal section of the forum.

Around here they call me Gringo and I will be glad to help you with your malware problems.

Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the "Follow This Topic" Button, make sure that the "Receive notification" box is checked and that it is set to "Instantly" - This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

Ok lets see if we can find a replacement for the infected file

Boot back into the recovery Environment and run FRST like you did before

Type the following in the edit box after "Search:".

LPK.dll

It then should look like:

Search: LPK.dll

Click Search button and post the log (Search.txt) it makes to your reply.

Gringo

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 iliadawah

iliadawah
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:09:20 AM

Posted 13 October 2013 - 01:11 PM

I read all accurately, thanks. :)

 

Here you are the "search.txt" :

 

Farbar Recovery Scan Tool (x64) Version: 02-10-2013
Ran by SYSTEM at 2013-10-13 20:00:07
Running from H:\
Boot Mode: Recovery

================== Search: "lpk.dll" ===================

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_1281c5a8bee46a0f\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22153_none_12ab04c4bec5c79d\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.21664_none_12a15568beccd507\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.21636_none_12c3c5c0beb2b3e2\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18032_none_12360787a598d69a\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17991_none_11f44f93a5ca31a7\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17563_none_1216b853a5b01be6\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17537_none_123b293fa5942d6f\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17514_none_124dc839a586a988\lpk.dll
[2009-07-13 15:25] - [2009-07-13 17:11] - 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_082d1b568a83a814\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22153_none_08565a728a6505a2\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.21664_none_084cab168a6c130c\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.21636_none_086f1b6e8a51f1e7\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18032_none_07e15d357138149f\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17991_none_079fa54171696fac\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17563_none_07c20e01714f59eb\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17537_none_07e67eed71336b74\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17514_none_07f91de77125e78d\lpk.dll
[2009-07-13 15:38] - [2009-07-13 17:41] - 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

====== End Of Search ======



#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:20 AM

Posted 13 October 2013 - 04:24 PM


Hello iliadawah



Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flash drive as fixlist.txt

 
Replace: C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_082d1b568a83a814\lpk.dll C:\Windows\System32\LPK.dll
Replace: C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_1281c5a8bee46a0f\lpk.dll C:\Windows\SysWOW64\LPK.dll

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.

Run FRST again like we did before but this time press the Fix button just once and wait.
The tool will make a log on the flash drive (Fixlog.txt) please post it to your reply.

Also boot the computer into normal mode and let me know how things are looking.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 iliadawah

iliadawah
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:09:20 AM

Posted 13 October 2013 - 05:44 PM

Wow...fantastic! now it's all ok! what are the problem? can i prevents it?!

thanks a lot!! this is fixlog and wait a "gift" :thumbup2:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2013
Ran by SYSTEM at 2013-10-14 00:36:35 Run:2
Running from H:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
Replace: C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_082d1b568a83a814\lpk.dll C:\Windows\System32\LPK.dll
Replace: C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_1281c5a8bee46a0f\lpk.dll C:\Windows\SysWOW64\LPK.dll
*****************

Could not find C:\Windows\System32\LPK.dll.
C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_082d1b568a83a814\lpk.dll copied successfully to C:\Windows\System32\LPK.dll
Could not find C:\Windows\SysWOW64\LPK.dll.
C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_1281c5a8bee46a0f\lpk.dll copied successfully to C:\Windows\SysWOW64\LPK.dll

==== End of Fixlog ====



#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:20 AM

Posted 13 October 2013 - 05:48 PM



Hello iliadawah

These are the programs I would like you to run next, if you have any problems with one of these just skip it and move on to the next one.

-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
-Junkware-Removal-Tool-

Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
When they are complete let me have the two reports and let me know how things are running.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 iliadawah

iliadawah
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:09:20 AM

Posted 13 October 2013 - 06:10 PM

Hi Gringo,

here you are adwc log:
 
# AdwCleaner v3.007 - Report created 14/10/2013 at 00:54:19
# Updated 09/10/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Gianlu - GIANLU-HP
# Running from : C:\Users\Gianlu\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Ask
File Deleted : C:\END
File Deleted : C:\Users\Gianlu\AppData\Roaming\Mozilla\Firefox\Profiles\7gzcpgsf.default\searchplugins\Askcom.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Value Deleted : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1]
Key Deleted : HKLM\Software\systweak

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16506


-\\ Mozilla Firefox v24.0 (it)

[ File : C:\Users\Gianlu\AppData\Roaming\Mozilla\Firefox\Profiles\7gzcpgsf.default\prefs.js ]

Line Deleted : user_pref("browser.search.order.1", "Ask.com");

*************************

AdwCleaner[R0].txt - [4682 octets] - [14/10/2013 00:52:46]
AdwCleaner[S0].txt - [4322 octets] - [14/10/2013 00:54:19]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4382 octets] ##########
 
 
And this is Junk Log:
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.4 (10.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by Gianlu on 14/10/2013 at  0:59:47,77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{617D50A8-7B47-4246-9B26-5B5B50CE5369}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D387E947-2B31-4600-8CFE-68B56CECA248}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{D387E947-2B31-4600-8CFE-68B56CECA248}



~~~ Files

Successfully deleted: [File] C:\Windows\syswow64\sho35D3.tmp



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Gianlu\appdata\local\{44C5EA9B-631E-4805-AB25-A953AD6D6D54}
Successfully deleted: [Empty Folder] C:\Users\Gianlu\appdata\local\{8287ED70-065D-4630-9A02-10BCC2CBA4C2}
Successfully deleted: [Empty Folder] C:\Users\Gianlu\appdata\local\{B948A445-BD08-4647-AEFE-AFD09EB24A37}



~~~ FireFox

Emptied folder: C:\Users\Gianlu\AppData\Roaming\mozilla\firefox\profiles\7gzcpgsf.default\minidumps [423 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14/10/2013 at  1:06:16,45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


again...Thanks!!

Edit:
Now windows done 21 updates...in Italy is all more slow, but i update windows every time is available. I hope this don't waste all your work.

Edited by iliadawah, 13 October 2013 - 06:43 PM.


#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:20 AM

Posted 13 October 2013 - 11:02 PM


Hello iliadawah,

That is perfect at least we know it is working!



I Would like you to do the following.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"
  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 iliadawah

iliadawah
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:09:20 AM

Posted 14 October 2013 - 02:09 AM

Works all fine, except the game "league of legends", i start game but i only can see the logo and after process crash without notice, it's strange because in 3 years nevertimes it happened,  is it happen by chance?!  (i search "r3dlog" and it appear in league of legends's folder)

This is combofix log:

ComboFix 13-10-13.02 - Gianlu 14/10/2013   8:38.1.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.39.1040.18.6092.3969 [GMT 2:00]
Eseguito da: c:\users\Gianlu\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((   Altre eliminazioni   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\IsUn0410.exe
c:\windows\SysWow64\logs
c:\windows\SysWow64\logs\Game - R3d Logs\2013-06-20T20-36-43_r3dlog.txt
.
.
(((((((((((((((((((((((((   Files Creati Da 2013-09-14 al 2013-10-14  )))))))))))))))))))))))))))))))))))
.
.
2013-10-14 06:47 . 2013-10-14 06:47    --------    d-----w-    c:\windows\system32\config\systemprofile\AppData\Local\temp
2013-10-14 06:47 . 2013-10-14 06:47    --------    d-----w-    c:\users\Default\AppData\Local\temp
2013-10-14 01:19 . 2013-10-14 01:19    --------    d-----w-    C:\FRST
2013-10-13 23:20 . 2013-09-05 05:32    9694160    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E1147795-C0BD-4E64-AB80-E0173943D29C}\mpengine.dll
2013-10-13 23:10 . 2013-10-13 23:10    17813896    ----a-w-    c:\windows\SysWow64\FlashPlayerInstaller.exe
2013-10-13 23:00 . 2013-07-04 12:50    633856    ----a-w-    c:\windows\system32\comctl32.dll
2013-10-13 23:00 . 2013-07-04 11:50    530432    ----a-w-    c:\windows\SysWow64\comctl32.dll
2013-10-13 22:59 . 2013-10-13 22:59    --------    d-----w-    c:\windows\ERUNT
2013-10-13 22:54 . 2013-06-06 05:50    41472    ----a-w-    c:\windows\system32\lpk.dll
2013-10-13 22:54 . 2013-06-06 05:49    14336    ----a-w-    c:\windows\system32\dciman32.dll
2013-10-13 22:54 . 2013-06-06 03:30    368128    ----a-w-    c:\windows\system32\atmfd.dll
2013-10-13 22:54 . 2013-06-06 03:01    295424    ----a-w-    c:\windows\SysWow64\atmfd.dll
2013-10-13 22:54 . 2013-06-06 05:49    100864    ----a-w-    c:\windows\system32\fontsub.dll
2013-10-13 22:54 . 2013-06-06 05:47    46080    ----a-w-    c:\windows\system32\atmlib.dll
2013-10-13 22:54 . 2013-06-06 04:57    25600    ----a-w-    c:\windows\SysWow64\lpk.dll
2013-10-13 22:54 . 2013-06-06 04:51    70656    ----a-w-    c:\windows\SysWow64\fontsub.dll
2013-10-13 22:54 . 2013-06-06 04:50    10240    ----a-w-    c:\windows\SysWow64\dciman32.dll
2013-10-13 22:51 . 2013-09-08 02:30    1903552    ----a-w-    c:\windows\system32\drivers\tcpip.sys
2013-10-13 22:51 . 2013-09-14 01:10    497152    ----a-w-    c:\windows\system32\drivers\afd.sys
2013-10-13 22:51 . 2013-09-08 02:27    327168    ----a-w-    c:\windows\system32\mswsock.dll
2013-10-13 22:51 . 2013-09-08 02:03    231424    ----a-w-    c:\windows\SysWow64\mswsock.dll
2013-10-13 22:51 . 2013-08-28 01:21    3155968    ----a-w-    c:\windows\system32\win32k.sys
2013-10-13 22:48 . 2013-07-20 10:33    102608    ----a-w-    c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-10-13 22:48 . 2013-07-20 10:33    124112    ----a-w-    c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-13 22:48 . 2013-08-01 12:09    983488    ----a-w-    c:\windows\system32\drivers\dxgkrnl.sys
2013-10-13 22:47 . 2013-08-28 01:12    461312    ----a-w-    c:\windows\system32\scavengeui.dll
2013-10-13 22:37 . 2013-09-05 05:32    9694160    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-10-12 01:05 . 2013-10-12 01:05    --------    d-----w-    c:\users\Gianlu\AppData\Roaming\Dropbox
2013-10-01 19:08 . 2013-10-02 19:22    --------    d-----w-    c:\users\Gianlu\AppData\Local\PAYDAY 2
2013-10-01 18:56 . 2013-10-01 18:56    --------    d-----w-    c:\program files (x86)\NVIDIA Corporation
2013-10-01 18:56 . 2013-10-01 18:56    --------    d-----w-    c:\program files (x86)\AGEIA Technologies
2013-10-01 13:07 . 2013-10-01 13:07    --------    d-----w-    c:\users\Gianlu\AppData\Local\Samsung
2013-10-01 13:07 . 2013-10-01 13:07    --------    d-----w-    c:\users\Gianlu\AppData\Roaming\Samsung
2013-10-01 13:05 . 2013-07-18 12:33    4659712    ----a-w-    c:\windows\SysWow64\Redemption.dll
2013-10-01 13:05 . 2013-07-18 12:32    821824    ----a-w-    c:\windows\SysWow64\dgderapi.dll
2013-10-01 13:04 . 2013-10-01 13:06    --------    d-----w-    c:\program files (x86)\Samsung
2013-10-01 13:04 . 2013-10-01 13:06    --------    d-----w-    c:\programdata\Samsung
2013-09-30 13:06 . 2013-09-30 13:06    --------    d-----w-    c:\users\Gianlu\AppData\Roaming\OpenOffice
2013-09-23 19:45 . 2013-09-23 19:45    --------    d-----w-    c:\program files (x86)\OpenOffice 4
2013-09-15 12:45 . 2013-10-03 19:39    --------    d-----w-    c:\programdata\Tunngle
2013-09-14 18:49 . 2013-09-14 18:49    --------    d-----w-    c:\users\Gianlu\AppData\Local\FLT
2013-09-14 18:24 . 2013-09-14 18:24    --------    d-----w-    c:\program files (x86)\XCOM Enemy Unknown
2013-09-14 09:45 . 2013-09-14 09:45    --------    d-----w-    c:\program files (x86)\Spotify
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-13 23:35 . 2012-05-29 13:35    80541720    ----a-w-    c:\windows\system32\MRT.exe
2013-10-13 23:10 . 2012-05-26 18:48    71048    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-13 23:10 . 2012-05-26 18:48    692616    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-06 22:11 . 2013-09-06 22:13    965008    ------w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{20575A2B-6C17-4BAC-AAE8-8A07C9AF6F84}\gapaengine.dll
2013-08-29 19:11 . 2013-08-29 19:11    108968    ----a-w-    c:\windows\system32\WindowsAccessBridge-64.dll
2013-08-29 19:11 . 2013-02-21 00:28    312232    ----a-w-    c:\windows\system32\javaws.exe
2013-08-29 19:11 . 2013-02-21 00:28    1093032    ----a-w-    c:\windows\system32\npDeployJava1.dll
2013-08-29 19:11 . 2011-06-23 13:56    189352    ----a-w-    c:\windows\system32\javaw.exe
2013-08-29 19:11 . 2011-06-23 13:56    188840    ----a-w-    c:\windows\system32\java.exe
2013-08-29 19:11 . 2011-06-23 13:56    972712    ----a-w-    c:\windows\system32\deployJava1.dll
2013-08-29 01:48 . 2013-10-13 22:50    44032    ----a-w-    c:\windows\apppatch\acwow64.dll
2013-08-23 01:06 . 2012-06-12 18:41    941720    ------w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-08-20 05:02 . 2013-08-20 05:02    708168    ----a-w-    c:\windows\system32\WinUSBCoInstaller.dll
2013-08-20 05:02 . 2013-08-20 05:02    1490656    ----a-w-    c:\windows\system32\WdfCoInstaller01007.dll
2013-08-20 05:02 . 2013-08-20 05:02    204568    ----a-w-    c:\windows\system32\drivers\ssudmdm.sys
2013-08-20 05:02 . 2013-08-20 05:02    103576    ----a-w-    c:\windows\system32\drivers\ssudbus.sys
2013-08-05 02:25 . 2013-09-12 11:21    155584    ----a-w-    c:\windows\system32\drivers\ataport.sys
2013-08-02 02:14 . 2013-09-12 11:21    215040    ----a-w-    c:\windows\system32\winsrv.dll
2013-08-02 02:13 . 2013-09-12 11:21    424448    ----a-w-    c:\windows\system32\KernelBase.dll
2013-08-02 02:13 . 2013-09-12 11:21    1161216    ----a-w-    c:\windows\system32\kernel32.dll
2013-08-02 02:12 . 2013-09-12 11:21    43520    ----a-w-    c:\windows\system32\csrsrv.dll
2013-08-02 02:12 . 2013-09-12 11:21    6144    ---ha-w-    c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    4608    ---ha-w-    c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    6656    ----a-w-    c:\windows\system32\apisetschema.dll
2013-08-02 02:12 . 2013-09-12 11:21    4608    ---ha-w-    c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    5120    ---ha-w-    c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-08-02 01:50 . 2013-09-12 11:21    274944    ----a-w-    c:\windows\SysWow64\KernelBase.dll
2013-08-02 01:48 . 2013-09-12 11:21    5120    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    4608    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    6656    ----a-w-    c:\windows\SysWow64\apisetschema.dll
2013-08-02 01:48 . 2013-09-12 11:21    4096    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
2013-08-02 01:09 . 2013-09-12 11:21    338432    ----a-w-    c:\windows\system32\conhost.exe
2013-08-02 00:59 . 2013-09-12 11:21    112640    ----a-w-    c:\windows\system32\smss.exe
2013-08-02 00:43 . 2013-09-12 11:21    4608    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 11:21    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 11:21    6144    ---ha-w-    c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 11:21    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-07-26 02:24 . 2013-09-12 11:21    14172672    ----a-w-    c:\windows\system32\shell32.dll
2013-07-26 02:24 . 2013-09-12 11:21    197120    ----a-w-    c:\windows\system32\shdocvw.dll
2013-07-25 09:25 . 2013-08-15 01:46    1888768    ----a-w-    c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-15 01:46    1620992    ----a-w-    c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-15 01:46    2048    ----a-w-    c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-15 01:46    2048    ----a-w-    c:\windows\SysWow64\tzres.dll
2013-07-18 12:32 . 2013-07-18 12:32    90112    ----a-w-    c:\windows\MAMCityDownload.ocx
2013-07-18 12:32 . 2013-07-18 12:32    330240    ----a-w-    c:\windows\MASetupCaller.dll
2013-07-18 12:32 . 2013-07-18 12:32    30568    ----a-w-    c:\windows\MusiccityDownload.exe
2013-07-18 12:32 . 2013-07-18 12:32    974848    ----a-w-    c:\windows\SysWow64\cis-2.4.dll
2013-07-18 12:32 . 2013-07-18 12:32    81920    ----a-w-    c:\windows\SysWow64\issacapi_bs-2.3.dll
2013-07-18 12:32 . 2013-07-18 12:32    65536    ----a-w-    c:\windows\SysWow64\issacapi_pe-2.3.dll
2013-07-18 12:32 . 2013-07-18 12:32    57344    ----a-w-    c:\windows\SysWow64\MTXSYNCICON.dll
2013-07-18 12:32 . 2013-07-18 12:32    57344    ----a-w-    c:\windows\SysWow64\MK_Lyric.dll
2013-07-18 12:32 . 2013-07-18 12:32    57344    ----a-w-    c:\windows\SysWow64\issacapi_se-2.3.dll
2013-07-18 12:32 . 2013-07-18 12:32    569344    ----a-w-    c:\windows\SysWow64\muzdecode.ax
2013-07-18 12:32 . 2013-07-18 12:32    491520    ----a-w-    c:\windows\SysWow64\muzapp.dll
2013-07-18 12:32 . 2013-07-18 12:32    49152    ----a-w-    c:\windows\SysWow64\MaJGUILib.dll
.
.
(((((((((((((((((((((((((((((((((((((   Punti Reg Caricati   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"Spotify Web Helper"="c:\users\Gianlu\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-10-13 1140736]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-10-02 20472992]
"Spotify"="c:\users\Gianlu\AppData\Roaming\Spotify\spotify.exe" [2013-10-13 4752384]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-09-04 1564528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-01-13 283160]
"HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-02-15 94264]
"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-11-09 586296]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2013-09-03 40312]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2011-03-16 61112]
"HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-01-27 318520]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-30 343168]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2013-09-04 311152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 CSN5PDTS82;CSN5PDTS82 NDIS Protocol Driver;c:\windows\system32\Drivers\CSN5PDTS82.sys;c:\windows\SYSNATIVE\Drivers\CSN5PDTS82.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bmdm.sys [x]
R3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\DRIVERS\ss_bserd.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bserd.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 X6va009;X6va009;c:\windows\SysWOW64\Drivers\X6va009;c:\windows\SysWOW64\Drivers\X6va009 [x]
R3 X6va010;X6va010;c:\windows\SysWOW64\Drivers\X6va010;c:\windows\SysWOW64\Drivers\X6va010 [x]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
R4 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 CSN5PDTS82x64;CSN5PDTS82x64 NDIS Protocol Driver;c:\windows\system32\Drivers\CSN5PDTS82x64.sys;c:\windows\SYSNATIVE\Drivers\CSN5PDTS82x64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.exe [x]
S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe;c:\program files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe;c:\windows\SYSNATIVE\ezSharedSvcHost.exe [x]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 hpCMSrv;HP Connection Manager 4.0 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [x]
S3 IntcDAud;Audio schermo Intel®;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys;c:\windows\SYSNATIVE\drivers\ScreamingBAudio64.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai    REG_MULTI_SZ       Akamai
.
Contenuto della cartella 'Scheduled Tasks'
.
2013-10-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-26 23:10]
.
2013-09-18 c:\windows\Tasks\HPCeeScheduleForGianlu.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13 20:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-03-11 1128448]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 1356240]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-09 416024]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
.
------- Scansione supplementare -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
FF - ProfilePath - c:\users\Gianlu\AppData\Roaming\Mozilla\Firefox\Profiles\7gzcpgsf.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Wow6432Node-HKCU-Run-KiesAirMessage - c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-{E92D47A1-D27D-430A-8368-0BAFD956507D} - c:\program files (x86)\InstallShield Installation Information\{E92D47A1-D27D-430A-8368-0BAFD956507D}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_4f7fccd.dll"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_4f7fccd.dll"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va009]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va009"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va010]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va010"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8,
   89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
   1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
   aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,
   d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:d1,54,41,64,3a,d0,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fe,54,19,bd,59,b8,6c,42,95,78,17,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fe,54,19,bd,59,b8,6c,42,95,78,17,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2013-10-14  08:50:21
ComboFix-quarantined-files.txt  2013-10-14 06:50
.
Pre-Run: 142.737.334.272 byte disponibili
Post-Run: 143.193.915.392 byte disponibili
.
- - End Of File - - 17C4A2E00D15422B2767599595F668B9
 


Edited by iliadawah, 14 October 2013 - 02:17 AM.


#10 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:20 AM

Posted 14 October 2013 - 08:17 PM


Hello iliadawah

Try reinstalling the game, The virus itself did not target the game but anything could have caused it to stop working from the virus or our tools and even it could be just by chance that it happened now.

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Please start by opening Notepad and copy/paste the text in the box into the window:

ClearJavaCache::


 
Save it to your desktop as CFScript.txt

Referring to the picture above, drag CFScript.txt into ComboFix.exe
CFScriptB-4.gif
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"
  • In your next post I need the following
    • report from Combofix
    • let me know of any problems you may have had
    • How is the computer doing now after running the script?
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#11 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:20 AM

Posted 22 October 2013 - 08:13 PM



Hello

48 Hour bump

It has been more than 48 hours since my last post.
  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#12 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:20 AM

Posted 25 October 2013 - 12:27 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users