[code] OTScanIt2 logfile created on: 25/02/2009 9.50.04 - Run 1 OTScanIt2 by OldTimer - Version 1.0.8.0 Folder = C:\Documents and Settings\Administrator\Desktop\OTScanIt2 Windows 2000 Professional Edition Service Pack 4 (Version = 5.0.2195) - Type = NTWorkstation Internet Explorer (Version = 6.0.2800.1106) Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy 511,42 Mb Total Physical Memory | 281,09 Mb Available Physical Memory | 54,96% Memory free 1,21 Gb Paging File | 1,03 Gb Available in Paging File | 84,89% Paging File free Paging file location(s): G:\pagefile.sys 766 768; %SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Programmi Drive C: | 9,50 Gb Total Space | 3,03 Gb Free Space | 31,87% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded Drive G: | 149,04 Gb Total Space | 79,21 Gb Free Space | 53,15% Space Free | Partition Type: NTFS H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PC-MIGLIORI Current User Name: Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days [Processes - Safe List] bgsvcgen.exe -> %SystemRoot%\system32\bgsvcgen.exe -> [2005/04/30 16.02.26 | 00,086,016 | ---- | M] (B.H.A Corporation) btstac~1.exe -> %ProgramFiles%\WIDCOMM\Software Bluetooth\BTStackServer.exe -> [2005/09/16 14.01.06 | 01,396,820 | ---- | M] (Broadcom Corporation.) bttray.exe -> %ProgramFiles%\WIDCOMM\Software Bluetooth\BTTray.exe -> [2005/09/16 14.02.14 | 00,610,365 | ---- | M] (Broadcom Corporation.) btwdins.exe -> %ProgramFiles%\WIDCOMM\Software Bluetooth\bin\btwdins.exe -> [2005/09/16 13.56.06 | 00,266,295 | ---- | M] (Broadcom Corporation.) drvlsnr.exe -> %ProgramFiles%\Analog Devices\SoundMAX\DrvLsnr.exe -> [2003/05/08 12.34.32 | 00,069,632 | ---- | M] (adi) explorer.exe -> %SystemRoot%\Explorer.EXE -> [2003/06/19 12.05.04 | 00,243,984 | ---- | M] (Microsoft Corporation) hidserv.exe -> %SystemRoot%\system32\hidserv.exe -> [2003/06/19 11.05.04 | 00,019,728 | ---- | M] (Microsoft Corporation) jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/02/13 17.42.03 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) jusched.exe -> %ProgramFiles%\Java\jre6\bin\jusched.exe -> [2009/02/13 17.42.03 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) kodakccs.exe -> %SystemRoot%\system32\drivers\KodakCCS.exe -> [2005/03/30 16.46.56 | 00,411,920 | ---- | M] (Eastman Kodak Company) nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2003/07/28 14.19.00 | 00,077,824 | ---- | M] (NVIDIA Corporation) oodag.exe -> %SystemRoot%\system32\oodag.exe -> [2008/09/04 06.02.24 | 01,295,616 | ---- | M] (O&O Software GmbH) otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/02/19 11.15.40 | 00,489,984 | ---- | M] (OldTimer Tools) regsvc.exe -> %SystemRoot%\system32\regsvc.exe -> [2003/06/19 12.05.04 | 00,068,368 | ---- | M] (Microsoft Corporation) smagent.exe -> %ProgramFiles%\Analog Devices\SoundMAX\SMAgent.exe -> [2002/09/20 16.50.10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) stisvc.exe -> %SystemRoot%\system32\stisvc.exe -> [2003/06/19 12.05.04 | 00,062,224 | ---- | M] (Microsoft Corporation) t3srv.exe -> %ProgramFiles%\FLIR Systems\Device Drivers\T3Srv.exe -> [2007/02/01 03.01.34 | 00,140,896 | R--- | M] (FLIR Systems) t3srv.exe -> %ProgramFiles%\FLIR Systems\ThermaCAM QuickView 2\T3Srv.exe -> [2006/06/08 11.58.22 | 00,140,896 | ---- | M] (FLIR Systems) winmgmt.exe -> %SystemRoot%\System32\WBEM\WinMgmt.exe -> [2003/06/19 12.05.04 | 00,196,706 | ---- | M] (Microsoft Corporation) [Win32 Services - Safe List] (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2005/09/23 06.28.32 | 00,029,896 | ---- | M] (Microsoft Corporation) (AVP) Kaspersky Anti-Virus [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe -> [2009/02/19 12.13.09 | 00,206,088 | ---- | M] (Kaspersky Lab) (bgsvcgen) B's Recorder GOLD Library General Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\bgsvcgen.exe -> [2005/04/30 16.02.26 | 00,086,016 | ---- | M] (B.H.A Corporation) (btwdins) Bluetooth Service [Win32_Own | Auto | Running] -> %ProgramFiles%\WIDCOMM\Software Bluetooth\bin\btwdins.exe -> [2005/09/16 13.56.06 | 00,266,295 | ---- | M] (Broadcom Corporation.) (CameraMonitor) FLIR Camera Monitor [Win32_Own | Auto | Running] -> %ProgramFiles%\FLIR Systems\ThermaCAM QuickView 2\T3Srv.exe -> [2006/06/08 11.58.22 | 00,140,896 | ---- | M] (FLIR Systems) (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2005/09/23 06.28.56 | 00,066,240 | ---- | M] (Microsoft Corporation) (dmadmin) Servizio amministrativo di Gestione disco logico [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\dmadmin.exe -> [2003/06/19 12.05.04 | 00,147,728 | ---- | M] (VERITAS Software Corp.) (Fax) Servizio Microsoft Fax [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\system32\faxsvc.exe -> [2003/06/19 12.05.04 | 00,096,016 | ---- | M] (Microsoft Corporation) (FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2008/07/29 08.37.35 | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) (HidServ) HID Input Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\hidserv.exe -> [2003/06/19 11.05.04 | 00,019,728 | ---- | M] (Microsoft Corporation) (hpqcxs08) hpqcxs08 [Win32_Shared | On_Demand | Stopped] -> %ProgramFiles%\hp\Digital Imaging\bin\hpqcxs08.dll -> [2008/01/29 10.32.44 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) (JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/02/13 17.42.03 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) (KodakCCS) Kodak Camera Connection Software [Win32_Own | Auto | Running] -> %SystemRoot%\system32\drivers\KodakCCS.exe -> [2005/03/30 16.46.56 | 00,411,920 | ---- | M] (Eastman Kodak Company) (Net Driver HPZ12) Net Driver HPZ12 [Win32_Own | Auto | Running] -> %SystemRoot%\system32\HPZinw12.dll -> [2006/11/08 15.35.36 | 00,043,520 | ---- | M] (Hewlett-Packard) (NVSvc) NVIDIA Driver Helper Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2003/07/28 14.19.00 | 00,077,824 | ---- | M] (NVIDIA Corporation) (O&O Defrag) O&O Defrag [Win32_Own | Auto | Running] -> %SystemRoot%\system32\oodag.exe -> [2008/09/04 06.02.24 | 01,295,616 | ---- | M] (O&O Software GmbH) (Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Auto | Running] -> %SystemRoot%\system32\HPZipm12.dll -> [2006/11/08 15.35.38 | 00,053,248 | ---- | M] (Hewlett-Packard) (RemoteRegistry) Servizio Registro di sistema remoto [Win32_Own | Auto | Running] -> %SystemRoot%\system32\regsvc.exe -> [2003/06/19 12.05.04 | 00,068,368 | ---- | M] (Microsoft Corporation) (SolidWorks Licensing Service) SolidWorks Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\SolidWorks Shared\Service\SolidWorksLicensing.exe -> [2007/06/27 09.42.10 | 00,079,360 | ---- | M] (SolidWorks) (SoundMAX Agent Service (default)) SoundMAX Agent Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Analog Devices\SoundMAX\SMAgent.exe -> [2002/09/20 16.50.10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) (StiSvc) Still Image Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\stisvc.exe -> [2003/06/19 12.05.04 | 00,062,224 | ---- | M] (Microsoft Corporation) (T3Srv) FLIR Systems Camera Monitor [Win32_Own | Auto | Running] -> %ProgramFiles%\FLIR Systems\Device Drivers\T3Srv.exe -> [2007/02/01 03.01.34 | 00,140,896 | R--- | M] (FLIR Systems) (UtilMan) Utility Manager [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\UtilMan.exe -> [2003/06/19 12.05.04 | 00,022,800 | ---- | M] (Microsoft Corporation) (WinMgmt) Strumentazione gestione Windows [Win32_Own | Auto | Running] -> %SystemRoot%\System32\WBEM\WinMgmt.exe -> [2003/06/19 12.05.04 | 00,196,706 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (aeaudio) aeaudio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\aeaudio.sys -> [2003/03/13 18.34.48 | 00,100,224 | ---- | M] (Andrea Electronics Corporation) (BT2KNDFL) Driver del server di accesso alla rete LAN Bluetooth - Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\bt2kndfl.sys -> [2005/09/16 13.36.58 | 00,003,879 | ---- | M] (Broadcom Corporation.) (btaudio) Periferica audio Bluetooth [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\btaudio.sys -> [2005/09/16 13.45.00 | 00,428,269 | ---- | M] (Broadcom Corporation.) (BTDriver) Driver di comunicazioni virtuali Bluetooth [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\btport.sys -> [2005/09/16 13.40.26 | 00,030,363 | ---- | M] (Broadcom Corporation.) (BTKRNL) Enumeratore bus Bluetooth [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\btkrnl.sys -> [2005/09/16 13.42.30 | 00,853,258 | ---- | M] (Broadcom Corporation.) (BTWDNDIS) Bluetooth LAN Access Server [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\btwdndis.sys -> [2005/09/16 13.36.56 | 00,148,360 | ---- | M] (Broadcom Corporation.) (btwhid) btwhid [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\btwhid.sys -> [2004/01/20 17.30.36 | 00,043,299 | ---- | M] (WIDCOMM, Inc.) (btwmodem) Modem Bluetooth [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\btwmodem.sys -> [2005/09/16 13.40.20 | 00,030,221 | ---- | M] (Broadcom Corporation.) (BTWUSB) WIDCOMM USB Bluetooth Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\btwusb.sys -> [2005/09/16 13.39.52 | 00,064,344 | ---- | M] (Broadcom Corporation.) (Cdr4_2K) Cdr4_2K [Kernel | System | Running] -> %SystemRoot%\System32\drivers\cdr4_2k.sys -> [2005/11/03 03.00.00 | 00,002,432 | ---- | M] (Sonic Solutions) (Cdralw2k) Cdralw2k [Kernel | System | Running] -> %SystemRoot%\System32\drivers\cdralw2k.sys -> [2005/11/03 03.00.00 | 00,002,560 | ---- | M] (Sonic Solutions) (DcCam) Kodak Camera Proxy [Kernel | System | Running] -> %SystemRoot%\system32\DRIVERS\DcCam.sys -> [2005/06/16 14.41.02 | 00,037,150 | ---- | M] (Eastman Kodak Company) (DcFpoint) DcFpoint [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\DcFpoint.sys -> [2005/03/31 07.47.42 | 00,061,564 | ---- | M] (Eastman Kodak Company) (DCFS2K) Kodak DCFS2K Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\dcfs2k.sys -> [2005/03/31 07.47.48 | 00,038,673 | ---- | M] (Eastman Kodak Company) (DcLps) Legacy Polling Service [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\DcLps.sys -> [2005/03/31 07.47.50 | 00,008,022 | ---- | M] (Eastman Kodak Company) (DcPTP) DcPTP [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\DcPTP.sys -> [2005/03/31 07.47.56 | 00,070,262 | ---- | M] (Eastman Kodak Company) (Diskperf) Diskperf [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\diskperf.sys -> [2003/06/19 12.05.04 | 00,007,728 | ---- | M] (Microsoft Corporation) (dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\dmboot.sys -> [2003/06/19 12.05.04 | 00,369,104 | ---- | M] (VERITAS Software Corp.) (dmio) Driver Gestione disco logico [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\dmio.sys -> [2003/06/19 12.05.04 | 00,137,936 | ---- | M] (VERITAS Software Corp.) (dmload) dmload [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\dmload.sys -> [2003/06/19 12.05.04 | 00,007,312 | ---- | M] (VERITAS Software Corp.) (dtscsi) dtscsi [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\dtscsi.sys -> [2007/03/09 16.18.16 | 00,223,128 | ---- | M] () (E100B) Intel(R) PRO Network Connection Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\e100bnt5.sys -> [2007/03/14 09.33.16 | 00,154,760 | ---- | M] (Intel Corporation) (EFS) EFS [File_System | Disabled | Running] -> %SystemRoot%\System32\drivers\efs.sys -> [2003/06/19 12.05.04 | 00,027,440 | ---- | M] (Microsoft Corporation) (eugss) EUTRON SmartKey GSS2 Driver [File_System | Auto | Running] -> %SystemRoot%\system32\Drivers\eugss2k.sys -> [2007/05/09 15.00.42 | 00,063,336 | ---- | M] (Eutronsec) (eusk2par) EUTRON SmartKey Parallel Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\Drivers\eusk2par.sys -> [2006/12/13 11.10.20 | 00,030,656 | ---- | M] (Eutron) (Eutron-Emu) Eutron-Emu [Kernel | Auto | Stopped] -> %SystemRoot%\System32\drivers\Eutron-Emu.SYS -> [2006/08/19 08.29.16 | 00,009,216 | ---- | M] () (Exportit) Exportit [Kernel | System | Stopped] -> %SystemRoot%\system32\DRIVERS\exportit.sys -> [2005/03/31 08.00.08 | 00,152,081 | ---- | M] (Eastman Kodak Company) (FLIRUSBRNDIS) FLIR Camera USB Network Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\usb8023k.sys -> [2006/05/05 09.20.34 | 00,013,824 | ---- | M] (Microsoft Corporation) (hwdatacard) Huawei DataCard USB Modem and USB Serial [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\ewusbmdm.sys -> [2006/12/04 11.36.34 | 00,088,960 | ---- | M] (Huawei Technologies Co., Ltd.) (kl1) kl1 [Kernel | Boot | Stopped] -> %SystemRoot%\system32\drivers\kl1.sys -> [2008/07/21 17.34.36 | 00,121,872 | ---- | M] (Kaspersky Lab) (klbg) Kaspersky Lab Boot Guard Driver [File_System | Boot | Running] -> %SystemRoot%\system32\drivers\klbg.sys -> [2009/02/19 15.55.55 | 00,033,808 | ---- | M] (Kaspersky Lab) (KLIF) Kaspersky Lab Driver [File_System | System | Running] -> %SystemRoot%\system32\DRIVERS\klif.sys -> [2009/02/19 15.55.55 | 00,230,032 | ---- | M] (Kaspersky Lab) (klim5) Kaspersky Anti-Virus NDIS Filter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\klim5.sys -> [2008/04/30 17.06.48 | 00,024,592 | ---- | M] (Kaspersky Lab) (motccgp) Motorola USB Composite Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\motccgp.sys -> [2007/06/20 14.57.24 | 00,017,920 | ---- | M] (Motorola) (motccgpfl) MotCcgpFlService [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\motccgpfl.sys -> [2007/01/23 20.03.44 | 00,007,680 | ---- | M] (Motorola) (MotDev) Motorola Inc. USB Device [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\motodrv.sys -> [2007/09/07 13.42.18 | 00,042,112 | ---- | M] (Motorola Inc) (motmodem) Motorola USB CDC ACM Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\motmodem.sys -> [2007/06/20 14.57.46 | 00,023,680 | ---- | M] (Motorola) (MPE) BDA MPE Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\MPE.sys -> [2004/07/09 02.58.10 | 00,015,104 | ---- | M] (Microsoft Corporation) (NetDetect) NetDetect [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\netdtect.sys -> [1999/12/23 01.00.00 | 00,009,680 | ---- | M] (Microsoft Corporation) (nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\nv4_mini.sys -> [2003/07/28 14.19.00 | 01,341,339 | ---- | M] (NVIDIA Corporation) (nv4) nv4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\nv4.sys -> [1999/10/27 23.23.38 | 00,345,040 | ---- | M] (NVIDIA Corporation) (Parallel) Driver di classe parallela [Kernel | On_Demand | Running] -> %SystemRoot%\System32\DRIVERS\parallel.sys -> [2003/06/19 12.05.04 | 00,060,304 | ---- | M] (Microsoft Corporation) (pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pfc.sys -> [2007/08/10 15.44.08 | 00,010,368 | ---- | M] (Padus, Inc.) (Ptilink) Driver Direct Parallel Link [Kernel | On_Demand | Running] -> %SystemRoot%\System32\DRIVERS\ptilink.sys -> [2003/06/19 12.05.04 | 00,017,680 | ---- | M] (Parallel Technologies, Inc.) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\PxHelp20.sys -> [2006/08/25 04.47.00 | 00,036,528 | ---- | M] (Sonic Solutions) (RCA) Accesso Raw Channel rete streaming Microsoft [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\RCA.sys -> [1999/12/23 01.00.00 | 00,021,712 | ---- | M] (Microsoft Corporation) (rtl8139) Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\DRIVERS\RTL8139.SYS -> [1999/09/25 02.17.18 | 00,018,704 | ---- | M] (Realtek Semiconductor Corporation ) (skeyusb) SmartKey USB [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\skeyusb.sys -> [2006/03/10 15.35.30 | 00,043,968 | ---- | M] (Eutron) (smwdm) smwdm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\smwdm.sys -> [2003/05/27 17.05.42 | 00,578,304 | ---- | M] (Analog Devices, Inc.) (sptd) sptd [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\sptd.sys -> [2007/03/09 16.13.53 | 00,643,072 | ---- | M] () (StillCam) Driver per fotocamera digitale seriale [Kernel | On_Demand | Running] -> %SystemRoot%\System32\DRIVERS\serscan.sys -> [1999/12/22 22.11.10 | 00,006,832 | ---- | M] (Microsoft Corporation) (TSP) TSP [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\klif.sys -> [2009/02/19 15.55.55 | 00,230,032 | ---- | M] (Kaspersky Lab) (UALFDrv2) UALFDrv2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\UALFDrv2.sys -> [2006/09/12 10.02.10 | 00,046,309 | ---- | M] (Sonix) (uhcd) Driver host controller Universal USB Microsoft [Kernel | On_Demand | Running] -> %SystemRoot%\System32\DRIVERS\uhcd.sys -> [2003/06/19 12.05.04 | 00,032,848 | ---- | M] (Microsoft Corporation) (usbaudio) Driver audio USB (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usbaudio.sys -> [1999/10/12 23.57.12 | 00,068,912 | ---- | M] (Microsoft Corporation) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.google.com/ie -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINNT\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.it/ -> HKEY_CURRENT_USER\: SearchURL\\"" -> http://www.google.com/search?q=%s -> HKEY_CURRENT_USER\: SearchURL\\"provider" -> gogl -> HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> HKEY_CURRENT_USER\: "ProxyOverride" -> -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\.DEFAULT\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\] > -> -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\: Main\\"Local Page" -> C:\WINNT\system32\blank.htm -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\: Main\\"Start Page" -> http://www.google.it/ -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\: SearchURL\\"" -> http://www.google.com/search?q=%s -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\: SearchURL\\"provider" -> gogl -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\: "ProxyEnable" -> 0 -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\: "ProxyOverride" -> -> < FireFox Settings [Default Profile] > -> C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\FireFox\Profiles\yyauvfjj.default\prefs.js -> browser.startup.homepage -> "http://it.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:it:official" -> browser.startup.homepage_override.mstone -> "rv:1.9.0.6" -> extensions.enabledItems -> {405e2f6c-b9b8-4515-a69c-e375d7156c86}:0.1.3 -> extensions.enabledItems -> {FDD1DC87-8568-42cc-9A49-CD4919E9A33A}:1.5.0 -> extensions.enabledItems -> [removed]:3.1 -> extensions.enabledItems -> {E7BE9E35-D5BA-4d0f-91B0-D7A879995D62}:2.4 -> extensions.enabledItems -> {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20081203 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12 -> extensions.enabledItems -> [removed]:1.0 -> extensions.enabledItems -> {37E4D8EA-8BDA-4831-8EA1-89053939A250}:2.1.0.1 -> extensions.enabledItems -> {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.6.11 -> extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6 -> < HOSTS File > (27 bytes and 1 lines) -> C:\WINNT\System32\drivers\etc\Hosts -> 127.0.0.1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [Adobe PDF Link Helper] -> [2008/06/11 22.33.16 | 00,075,128 | ---- | M] (Adobe Systems Incorporated) {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [HKLM] -> %ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll [IEVkbdBHO Class] -> [2008/11/11 19.59.58 | 00,062,728 | ---- | M] (Kaspersky Lab) {DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009/02/13 17.42.02 | 00,035,840 | ---- | M] (Sun Microsystems, Inc.) {E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009/02/13 17.42.05 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{8E718888-423F-11D2-876E-00A0C9082467}" [HKLM] -> %SystemRoot%\system32\msdxm.ocx [@msdxmLC.dll,-1@1033,&Radio] -> [2005/06/03 15.26.10 | 00,850,192 | ---- | M] (Microsoft Corporation) < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found ShellBrowser\\"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" [HKLM] -> G:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> File not found WebBrowser\\"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" [HKLM] -> G:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\] > -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found ShellBrowser\\"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" [HKLM] -> G:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> File not found WebBrowser\\"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" [HKLM] -> G:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> File not found < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "AVP" -> %ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe ["C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"] -> [2009/02/19 12.13.09 | 00,206,088 | ---- | M] (Kaspersky Lab) "DrvLsnr" -> %ProgramFiles%\Analog Devices\SoundMAX\DrvLsnr.exe [C:\Programmi\Analog Devices\SoundMAX\DrvLsnr.exe] -> [2003/05/08 12.34.32 | 00,069,632 | ---- | M] (adi) "NvCplDaemon" -> %SystemRoot%\system32\NvCpl.DLL [RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup] -> [2003/07/28 14.19.00 | 04,841,472 | ---- | M] (NVIDIA Corporation) "nwiz" -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /install] -> [2003/07/28 14.19.00 | 00,323,584 | ---- | M] (NVIDIA Corporation) "SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Programmi\Java\jre6\bin\jusched.exe"] -> [2009/02/13 17.42.03 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) "Synchronization Manager" -> %SystemRoot%\system32\mobsync.exe [mobsync.exe /logon] -> [2003/06/19 12.05.04 | 00,111,376 | ---- | M] (Microsoft Corporation) < RunOnce [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "^SetupICWDesktop" -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe [C:\Programmi\Internet Explorer\Connection Wizard\icwconn1.exe /desktop] -> [2003/06/19 12.05.04 | 00,188,176 | ---- | M] (Microsoft Corporation) < All Users Startup Folder > -> C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica -> %AllUsersProfile%\Menu Avvio\Programmi\Esecuzione automatica\BTTray.lnk -> %ProgramFiles%\WIDCOMM\Software Bluetooth\BTTray.exe -> [2005/09/16 14.02.14 | 00,610,365 | ---- | M] (Broadcom Corporation.) < Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer -> < Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer -> < Software Policy Settings [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500] > -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\SOFTWARE\Policies\Microsoft\Internet Explorer -> < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [323] -> File not found \\"NoDriveAutoRun" -> [67108863] -> File not found \\"NoDrives" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"DisableRegistryTools" -> [0] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [323] -> File not found \\"CDRAutoRun" -> [0] -> File not found \\"NoDriveAutoRun" -> [67108863] -> File not found \\"NoDrives" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [323] -> File not found \\"NoDriveAutoRun" -> [67108863] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500] > -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [323] -> File not found \\"CDRAutoRun" -> [0] -> File not found \\"NoDriveAutoRun" -> [67108863] -> File not found \\"NoDrives" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500] > -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> Invia a &Bluetooth -> %ProgramFiles%\IBM\Bluetooth Software\btsendto_ie_ctx.htm [C:\Programmi\IBM\Bluetooth Software\btsendto_ie_ctx.htm] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\] > -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\Software\Microsoft\Internet Explorer\MenuExt\ -> Invia a &Bluetooth -> %ProgramFiles%\IBM\Bluetooth Software\btsendto_ie_ctx.htm [C:\Programmi\IBM\Bluetooth Software\btsendto_ie_ctx.htm] -> File not found < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}:{85E0B171-04FA-11D1-B7DA-00A0C90348D6} [HKLM] -> %ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll [Button: Statistiche sulla protezione del traffico Web] -> [2008/11/11 20.00.38 | 00,222,472 | ---- | M] (Kaspersky Lab) {CCA281CA-C863-46ef-9331-5C8D4460577F}:C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm [HKLM] -> %ProgramFiles%\WIDCOMM\Software Bluetooth\btsendto_ie.htm [Button: @btrez.dll,-4015] -> [2003/05/29 12.53.08 | 00,002,681 | ---- | M] () {CCA281CA-C863-46ef-9331-5C8D4460577F}:C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm [HKLM] -> %ProgramFiles%\WIDCOMM\Software Bluetooth\btsendto_ie.htm [Menu: @btrez.dll,-12650] -> [2003/05/29 12.53.08 | 00,002,681 | ---- | M] () < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 18.26.26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}" [HKLM] -> %ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll [Statistiche sulla protezione del traffico Web] -> [2008/11/11 20.00.38 | 00,222,472 | ---- | M] (Kaspersky Lab) CmdMapping\\"{36ECAF82-3300-8F84-092E-AFF36D6C7040}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{7F9DB11C-E358-4ca6-A83D-ACC663939424}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{c95fe080-8f5d-11d2-a20b-00aa003c157a}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{CCA281CA-C863-46ef-9331-5C8D4460577F}" [HKLM] -> [@btrez.dll,-4015] -> File not found CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] -> [Reg Error: Key error.] -> File not found < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\] > -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 18.26.26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}" [HKLM] -> %ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll [Statistiche sulla protezione del traffico Web] -> [2008/11/11 20.00.38 | 00,222,472 | ---- | M] (Kaspersky Lab) CmdMapping\\"{36ECAF82-3300-8F84-092E-AFF36D6C7040}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{7F9DB11C-E358-4ca6-A83D-ACC663939424}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{c95fe080-8f5d-11d2-a20b-00aa003c157a}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{CCA281CA-C863-46ef-9331-5C8D4460577F}" [HKLM] -> [@btrez.dll,-4015] -> File not found CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] -> [Reg Error: Key error.] -> File not found < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Galleria ActiveX Microsoft -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5371 domain(s) found. -> 48 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5393 domain(s) found. -> 49 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5393 domain(s) found. -> 49 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 78 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\] > -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5393 domain(s) found. -> 49 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\] > -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-1844237615-1960408961-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {13149882-F480-4F6B-8C6A-0764F75B99ED} [HKLM] -> http://plug-in.reallusion.com/CrazyTalk4.cab [CrazyTalk4 Control] -> {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} [HKLM] -> http://www.eset.eu/buxus/docs/OnlineScanner.cab [OnlineScanner Control] -> {5D6F45B3-9043-443D-A792-115447494D24} [HKLM] -> http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab [UnoCtrl Class] -> {664088B0-6AF3-4514-AF9D-A0DC3A3DF24A} [HKLM] -> http://support.f-secure.com/ols3beta/fscax.cab [F-Secure Online Scanner 3.3] -> {74DBCB52-F298-4110-951D-AD2FF67BC8AB} [HKLM] -> http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab [NVIDIA Smart Scan] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab [Java Plug-in 1.6.0_12] -> {C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab [MessengerStatsClient Class] -> {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab [Java Plug-in 1.6.0_12] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab [Java Plug-in 1.6.0_12] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab [Shockwave Flash Object] -> DirectAnimation Java Classes [HKLM] -> file://C:\WINNT\Java\classes\dajava.cab [Reg Error: Key error.] -> Microsoft XML Parser for Java [HKLM] -> file://C:\WINNT\Java\classes\xmldso.cab [Reg Error: Key error.] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {46AA183D-08D8-4F06-99CC-5F02635E7636} -> 151.99.125.1 (Intel(R) PRO/100 VM Network Connection) -> {6A057E3E-8776-4024-ADA7-C819DCF8D46E} -> (FLIR Camera Network Device) -> {6B016F18-323B-4428-A7D4-7223D11EC5A1} -> () -> {A465B9A8-102C-4A12-B7C6-713A65835D05} -> (Scheda 10/100 SMC EZ (SMC1211TX)) -> {BD59E7EB-5B4B-4F0C-BEF4-FB717698BA24} -> (FLIR Camera Network Device) -> {E5E72B87-5298-4953-BD78-BAD92DCB4C6F} -> 151.99.125.1 (Scheda Fast Ethernet PCI Realtek RTL8139-based) -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> Explorer.exe -> %SystemRoot%\Explorer.exe -> [2003/06/19 12.05.04 | 00,243,984 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> klogon -> %SystemRoot%\system32\klogon.dll -> [2008/11/11 20.00.04 | 00,218,376 | ---- | M] (Kaspersky Lab) wzcnotif -> %SystemRoot%\system32\wzcdlg.dll -> [2003/06/19 12.05.04 | 00,053,008 | ---- | M] (Microsoft Corporation) < SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad -> "{7007ACCF-3202-11D1-AAD2-00805FC1270E}" [HKLM] -> %SystemRoot%\system32\NETSHELL.dll [Network.ConnectionTray] -> [2003/06/19 12.05.04 | 00,481,040 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> Driver del CD-ROM -> "ImagePath" -> %SystemRoot%\System32\DRIVERS\cdrom.sys [System32\DRIVERS\cdrom.sys] -> [2003/06/19 12.05.04 | 00,027,984 | ---- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2007/01/05 11.27.33 | 00,000,000 | -H-- | M] () C:\autorun.inf [] -> %SystemDrive%\autorun.inf [ NTFS ] -> [2009/01/28 14.23.24 | 00,000,000 | RHSD | M] G:\autorun.inf [] -> G:\autorun.inf [ NTFS ] -> [2009/01/28 14.23.24 | 00,000,000 | RHSD | M] [Files/Folders - Created Within 30 Days] 4 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/02/25 09.47.57 | 00,000,000 | ---D | C] OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/02/25 09.46.24 | 00,661,370 | ---- | C] () Perflib_Perfdata_274.dat -> %SystemRoot%\System32\Perflib_Perfdata_274.dat -> [2009/02/25 08.56.37 | 00,016,384 | ---- | C] () temp -> %SystemRoot%\temp -> [2009/02/24 16.37.40 | 00,000,000 | ---D | C] PSEXESVC.EXE -> %SystemRoot%\PSEXESVC.EXE -> [2009/02/24 16.11.18 | 00,053,248 | ---- | C] (Sysinternals) export.bat -> %UserProfile%\Desktop\export.bat -> [2009/02/24 15.18.15 | 00,000,096 | ---- | C] () OTListIt2.exe -> %UserProfile%\Desktop\OTListIt2.exe -> [2009/02/23 17.13.21 | 00,494,080 | ---- | C] (OldTimer Tools) ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [2009/02/23 16.13.42 | 02,924,943 | R--- | C] () Immagine.jpg -> %UserProfile%\Desktop\Immagine.jpg -> [2009/02/20 14.33.40 | 00,057,568 | ---- | C] () Flash_Disinfector.exe -> %UserProfile%\Desktop\Flash_Disinfector.exe -> [2009/02/20 10.12.46 | 00,132,597 | ---- | C] () ntuser.pol -> %UserProfile%\ntuser.pol -> [2009/02/19 17.59.18 | 00,000,458 | RHS- | C] () winacisa.sys -> %SystemRoot%\System32\dllcache\winacisa.sys -> [2009/02/19 17.43.03 | 00,771,824 | ---- | C] (Rockwell) w840nd.sys -> %SystemRoot%\System32\dllcache\w840nd.sys -> [2009/02/19 17.43.03 | 00,019,728 | ---- | C] (Winbond Electronics Corporation) twotrack.sys -> %SystemRoot%\System32\dllcache\twotrack.sys -> [2009/02/19 17.43.02 | 00,007,568 | ---- | C] (Microsoft Corporation) tsbmce.sys -> %SystemRoot%\System32\dllcache\tsbmce.sys -> [2009/02/19 17.39.42 | 00,017,712 | ---- | C] (Toshiba Corp.) stlnprop.dll -> %SystemRoot%\System32\dllcache\stlnprop.dll -> [2009/02/19 17.39.41 | 00,176,400 | ---- | C] (Stallion Technologies) spxports.dll -> %SystemRoot%\System32\dllcache\spxports.dll -> [2009/02/19 17.39.40 | 00,421,648 | ---- | C] (Specialix International Ltd.) stlnata.sys -> %SystemRoot%\System32\dllcache\stlnata.sys -> [2009/02/19 17.39.40 | 00,281,456 | ---- | C] (Stallion Technologies) skfpwin.sys -> %SystemRoot%\System32\dllcache\skfpwin.sys -> [2009/02/19 17.39.39 | 00,104,656 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) stkmc.sys -> %SystemRoot%\System32\dllcache\stkmc.sys -> [2009/02/19 17.39.37 | 00,010,288 | ---- | C] (Microsoft Corporation) sma032.dll -> %SystemRoot%\System32\dllcache\sma032.dll -> [2009/02/19 17.39.36 | 00,028,432 | ---- | C] (Microsoft Corporation) sm9132.dll -> %SystemRoot%\System32\dllcache\sm9132.dll -> [2009/02/19 17.38.14 | 00,025,872 | ---- | C] (Microsoft Corporation) sm9032.dll -> %SystemRoot%\System32\dllcache\sm9032.dll -> [2009/02/19 17.38.14 | 00,023,824 | ---- | C] (Microsoft Corporation) sm8c32.dll -> %SystemRoot%\System32\dllcache\sm8c32.dll -> [2009/02/19 17.38.13 | 00,025,872 | ---- | C] (Microsoft Corporation) sm8d32.dll -> %SystemRoot%\System32\dllcache\sm8d32.dll -> [2009/02/19 17.38.13 | 00,023,824 | ---- | C] (Microsoft Corporation) sm8a32.dll -> %SystemRoot%\System32\dllcache\sm8a32.dll -> [2009/02/19 17.38.13 | 00,023,824 | ---- | C] (Microsoft Corporation) sm8132.dll -> %SystemRoot%\System32\dllcache\sm8132.dll -> [2009/02/19 17.38.12 | 00,032,528 | ---- | C] (Microsoft Corporation) sm8732.dll -> %SystemRoot%\System32\dllcache\sm8732.dll -> [2009/02/19 17.38.12 | 00,032,016 | ---- | C] (Microsoft Corporation) sm8932.dll -> %SystemRoot%\System32\dllcache\sm8932.dll -> [2009/02/19 17.38.12 | 00,023,824 | ---- | C] (Microsoft Corporation) sm5932.dll -> %SystemRoot%\System32\dllcache\sm5932.dll -> [2009/02/19 17.38.11 | 00,024,848 | ---- | C] (Microsoft Corporation) rtl8029.sys -> %SystemRoot%\System32\dllcache\rtl8029.sys -> [2009/02/19 17.38.11 | 00,018,704 | ---- | C] (REALTEK Semiconductor Corp.) rnbo3531.sys -> %SystemRoot%\System32\dllcache\rnbo3531.sys -> [2009/02/19 17.38.11 | 00,013,968 | ---- | C] (Rainbow Technologies Inc.) otceth5.sys -> %SystemRoot%\System32\dllcache\otceth5.sys -> [2009/02/19 17.37.58 | 00,044,464 | ---- | C] () pca200e.sys -> %SystemRoot%\System32\dllcache\pca200e.sys -> [2009/02/19 17.37.58 | 00,030,064 | ---- | C] (FORE Systems, Inc.) netflx3.sys -> %SystemRoot%\System32\dllcache\netflx3.sys -> [2009/02/19 17.37.57 | 00,092,080 | ---- | C] (Compaq Computer Corporation) ngrpci.sys -> %SystemRoot%\System32\dllcache\ngrpci.sys -> [2009/02/19 17.37.57 | 00,030,992 | ---- | C] (NETGEAR Corporation.) msmgr32.dll -> %SystemRoot%\System32\dllcache\msmgr32.dll -> [2009/02/19 17.37.55 | 00,026,384 | ---- | C] (Microsoft Corporation) msriffwv.sys -> %SystemRoot%\System32\dllcache\msriffwv.sys -> [2009/02/19 17.37.55 | 00,012,208 | ---- | C] (Microsoft Corporation) mssti.dll -> %SystemRoot%\System32\dllcache\mssti.dll -> [2009/02/19 17.37.55 | 00,008,464 | ---- | C] (Microsoft Corporation) msf12sp.dll -> %SystemRoot%\System32\dllcache\msf12sp.dll -> [2009/02/19 17.37.54 | 00,007,440 | ---- | C] (Microsoft Corporation) msf12cx.dll -> %SystemRoot%\System32\dllcache\msf12cx.dll -> [2009/02/19 17.37.54 | 00,007,440 | ---- | C] (Microsoft Corporation) msfsio.sys -> %SystemRoot%\System32\dllcache\msfsio.sys -> [2009/02/19 17.37.54 | 00,005,776 | ---- | C] (Microsoft Corporation) msf08sp.dll -> %SystemRoot%\System32\dllcache\msf08sp.dll -> [2009/02/19 17.37.53 | 00,007,440 | ---- | C] (Microsoft Corporation) msf06sp.dll -> %SystemRoot%\System32\dllcache\msf06sp.dll -> [2009/02/19 17.37.53 | 00,007,440 | ---- | C] (Microsoft Corporation) msf06cz.dll -> %SystemRoot%\System32\dllcache\msf06cz.dll -> [2009/02/19 17.37.53 | 00,007,440 | ---- | C] (Microsoft Corporation) msf06cx.dll -> %SystemRoot%\System32\dllcache\msf06cx.dll -> [2009/02/19 17.37.52 | 00,007,440 | ---- | C] (Microsoft Corporation) miscan32.dll -> %SystemRoot%\System32\dllcache\miscan32.dll -> [2009/02/19 17.37.49 | 00,023,824 | ---- | C] (Microsoft Corporation) modemcsa.sys -> %SystemRoot%\System32\dllcache\modemcsa.sys -> [2009/02/19 17.37.49 | 00,016,144 | ---- | C] (Microsoft Corporation) mfs12sp.dll -> %SystemRoot%\System32\dllcache\mfs12sp.dll -> [2009/02/19 17.37.49 | 00,007,440 | ---- | C] (Microsoft Corporation) mphase32.dll -> %SystemRoot%\System32\dllcache\mphase32.dll -> [2009/02/19 17.37.49 | 00,006,928 | ---- | C] (Microsoft Corporation) mfs12cx.dll -> %SystemRoot%\System32\dllcache\mfs12cx.dll -> [2009/02/19 17.37.48 | 00,007,440 | ---- | C] (Microsoft Corporation) mfs08sp.dll -> %SystemRoot%\System32\dllcache\mfs08sp.dll -> [2009/02/19 17.37.48 | 00,007,440 | ---- | C] (Microsoft Corporation) mfs06sp.dll -> %SystemRoot%\System32\dllcache\mfs06sp.dll -> [2009/02/19 17.37.48 | 00,007,440 | ---- | C] (Microsoft Corporation) mfs06cz.dll -> %SystemRoot%\System32\dllcache\mfs06cz.dll -> [2009/02/19 17.37.47 | 00,007,440 | ---- | C] (Microsoft Corporation) mfs06cx.dll -> %SystemRoot%\System32\dllcache\mfs06cx.dll -> [2009/02/19 17.37.47 | 00,007,440 | ---- | C] (Microsoft Corporation) mf3.dll -> %SystemRoot%\System32\dllcache\mf3.dll -> [2009/02/19 17.37.47 | 00,007,440 | ---- | C] (Microsoft Corporation) lwusbhid.sys -> %SystemRoot%\System32\dllcache\lwusbhid.sys -> [2009/02/19 17.37.46 | 00,019,408 | ---- | C] (Logitech, Inc.) lwadihid.sys -> %SystemRoot%\System32\dllcache\lwadihid.sys -> [2009/02/19 17.37.46 | 00,018,576 | ---- | C] (Logitech, Inc.) lgpusb.dll -> %SystemRoot%\System32\dllcache\lgpusb.dll -> [2009/02/19 17.37.45 | 00,091,408 | ---- | C] (Microsoft Corporation) lgmntr.dll -> %SystemRoot%\System32\dllcache\lgmntr.dll -> [2009/02/19 17.37.45 | 00,036,624 | ---- | C] (Microsoft Corporation) lginstsc.dll -> %SystemRoot%\System32\dllcache\lginstsc.dll -> [2009/02/19 17.37.45 | 00,032,528 | ---- | C] (Microsoft Corporation) lgdeskew.dll -> %SystemRoot%\System32\dllcache\lgdeskew.dll -> [2009/02/19 17.37.44 | 00,010,000 | ---- | C] (Microsoft Corporation) lit220p.sys -> %SystemRoot%\System32\dllcache\lit220p.sys -> [2009/02/19 17.37.43 | 00,016,144 | ---- | C] (Litronic Industries) jt1nd5.sys -> %SystemRoot%\System32\dllcache\jt1nd5.sys -> [2009/02/19 17.37.42 | 00,035,856 | ---- | C] (Level One Communications) jupi32.dll -> %SystemRoot%\System32\dllcache\jupi32.dll -> [2009/02/19 17.37.42 | 00,017,168 | ---- | C] (Microsoft Corporation) is4x.dll -> %SystemRoot%\System32\dllcache\is4x.dll -> [2009/02/19 17.37.37 | 00,007,440 | ---- | C] (Microsoft Corporation) is450.dll -> %SystemRoot%\System32\dllcache\is450.dll -> [2009/02/19 17.37.37 | 00,007,440 | ---- | C] (Microsoft Corporation) is410.dll -> %SystemRoot%\System32\dllcache\is410.dll -> [2009/02/19 17.37.37 | 00,007,440 | ---- | C] (Microsoft Corporation) is01.dll -> %SystemRoot%\System32\dllcache\is01.dll -> [2009/02/19 17.37.36 | 00,007,440 | ---- | C] (Microsoft Corporation) hr132.dll -> %SystemRoot%\System32\dllcache\hr132.dll -> [2009/02/19 17.37.34 | 00,017,680 | ---- | C] (Microsoft Corporation) forehe.sys -> %SystemRoot%\System32\dllcache\forehe.sys -> [2009/02/19 17.37.02 | 00,032,528 | ---- | C] (FORE Systems, Inc.) ecnb.sys -> %SystemRoot%\System32\dllcache\ecnb.sys -> [2009/02/19 17.37.01 | 00,039,072 | ---- | C] (Eicon Technology Corporation) ecpagex.dll -> %SystemRoot%\System32\dllcache\ecpagex.dll -> [2009/02/19 17.37.01 | 00,033,792 | ---- | C] (Eicon Technology Corporation) eclandd.sys -> %SystemRoot%\System32\dllcache\eclandd.sys -> [2009/02/19 17.37.01 | 00,023,664 | ---- | C] (Eicon Technology Corporation) ecwandd.sys -> %SystemRoot%\System32\dllcache\ecwandd.sys -> [2009/02/19 17.37.01 | 00,017,856 | ---- | C] (Eicon Technology Corporation) essm2e.sys -> %SystemRoot%\System32\dllcache\essm2e.sys -> [2009/02/19 17.37.00 | 00,156,496 | ---- | C] (Microsoft Corporation) ecsnadd.sys -> %SystemRoot%\System32\dllcache\ecsnadd.sys -> [2009/02/19 17.36.59 | 00,008,960 | ---- | C] (Eicon Technology Corporation) ecvbus.sys -> %SystemRoot%\System32\dllcache\ecvbus.sys -> [2009/02/19 17.36.59 | 00,007,648 | ---- | C] (Eicon Technology Corporation) ecpinst.dll -> %SystemRoot%\System32\dllcache\ecpinst.dll -> [2009/02/19 17.36.58 | 00,021,680 | ---- | C] (Eicon Technology Corporation) ecdtrace.sys -> %SystemRoot%\System32\dllcache\ecdtrace.sys -> [2009/02/19 17.36.58 | 00,007,744 | ---- | C] (Eicon Technology Corporation) eccommdd.sys -> %SystemRoot%\System32\dllcache\eccommdd.sys -> [2009/02/19 17.36.57 | 00,100,656 | ---- | C] (Eicon Technology Corporation) dot4scan.sys -> %SystemRoot%\System32\dllcache\dot4scan.sys -> [2009/02/19 17.36.56 | 00,008,752 | ---- | C] (Microsoft Corporation) dot4prt.sys -> %SystemRoot%\System32\dllcache\dot4prt.sys -> [2009/02/19 17.36.55 | 00,012,688 | ---- | C] (Microsoft Corporation) dot4.sys -> %SystemRoot%\System32\dllcache\dot4.sys -> [2009/02/19 17.36.53 | 00,044,208 | ---- | C] (Microsoft Corporation) dspimg32.dll -> %SystemRoot%\System32\dllcache\dspimg32.dll -> [2009/02/19 17.36.45 | 00,013,072 | ---- | C] (Microsoft Corporation) dr3020.dll -> %SystemRoot%\System32\dllcache\dr3020.dll -> [2009/02/19 17.36.44 | 00,007,440 | ---- | C] (Microsoft Corporation) dlh5xnd5.sys -> %SystemRoot%\System32\dllcache\dlh5xnd5.sys -> [2009/02/19 17.36.43 | 00,023,216 | ---- | C] (D-Link Corporation) cb325.sys -> %SystemRoot%\System32\dllcache\cb325.sys -> [2009/02/19 17.36.39 | 00,039,680 | ---- | C] (Silicom Ltd.) brzwlan.sys -> %SystemRoot%\System32\dllcache\brzwlan.sys -> [2009/02/19 17.36.39 | 00,031,888 | ---- | C] (BreezeCOM) atibt829.sys -> %SystemRoot%\System32\dllcache\atibt829.sys -> [2009/02/19 17.36.38 | 00,042,192 | ---- | C] () atitvsnd.sys -> %SystemRoot%\System32\dllcache\atitvsnd.sys -> [2009/02/19 17.36.38 | 00,016,976 | ---- | C] () amb8002.sys -> %SystemRoot%\System32\dllcache\amb8002.sys -> [2009/02/19 17.36.37 | 00,017,168 | ---- | C] (AmbiCom, Inc.) af450.dll -> %SystemRoot%\System32\dllcache\af450.dll -> [2009/02/19 17.36.37 | 00,007,440 | ---- | C] (Microsoft Corporation) acq32.dll -> %SystemRoot%\System32\dllcache\acq32.dll -> [2009/02/19 17.36.28 | 00,092,432 | ---- | C] (Microsoft Corporation) 8514a.dll -> %SystemRoot%\System32\dllcache\8514a.dll -> [2009/02/19 17.36.28 | 00,038,320 | ---- | C] (Microsoft Corporation) 4mmdat.sys -> %SystemRoot%\System32\dllcache\4mmdat.sys -> [2009/02/19 17.36.27 | 00,010,928 | ---- | C] (Microsoft Corporation) 3cpciadi.sys -> %SystemRoot%\System32\dllcache\3cpciadi.sys -> [2009/02/19 17.36.25 | 00,801,072 | ---- | C] (U.S. Robotics, Inc.) 3cisati.sys -> %SystemRoot%\System32\dllcache\3cisati.sys -> [2009/02/19 17.36.24 | 00,774,928 | ---- | C] (U.S. Robotics, Inc.) 3cisaadi.sys -> %SystemRoot%\System32\dllcache\3cisaadi.sys -> [2009/02/19 17.36.23 | 00,792,176 | ---- | C] (U.S. Robotics, Inc.) 3cwmcru.sys -> %SystemRoot%\System32\dllcache\3cwmcru.sys -> [2009/02/19 17.36.22 | 00,763,024 | ---- | C] (3Com, Inc.) 15_16wdm.sys -> %SystemRoot%\System32\dllcache\15_16wdm.sys -> [2009/02/19 17.36.22 | 00,022,992 | ---- | C] (Microsoft Corporation) 1394bus.sys -> %SystemRoot%\System32\dllcache\1394bus.sys -> [2009/02/19 17.36.01 | 00,040,752 | ---- | C] (Microsoft Corporation) klin.dat -> %SystemRoot%\System32\drivers\klin.dat -> [2009/02/19 11.41.30 | 00,101,287 | ---- | C] () klick.dat -> %SystemRoot%\System32\drivers\klick.dat -> [2009/02/19 11.41.30 | 00,089,601 | ---- | C] () fsaua.data -> %SystemDrive%\fsaua.data -> [2009/02/19 09.15.56 | 00,000,000 | ---D | C] athena_speech_export.dat -> %UserProfile%\Desktop\athena_speech_export.dat -> [2009/02/16 15.40.50 | 00,025,037 | ---- | C] () ONLINESCANNER.html -> %UserProfile%\Desktop\ONLINESCANNER.html -> [2009/02/16 14.43.44 | 00,026,560 | ---- | C] () OTMoveIt3.exe -> %UserProfile%\Desktop\OTMoveIt3.exe -> [2009/02/13 10.21.39 | 00,348,160 | ---- | C] (OldTimer Tools) imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009/02/13 09.24.26 | 00,001,410 | ---- | C] () SWXCACLS.exe -> %SystemRoot%\SWXCACLS.exe -> [2009/02/12 17.37.52 | 00,212,480 | ---- | C] (SteelWerX) SWREG.exe -> %SystemRoot%\SWREG.exe -> [2009/02/12 17.37.52 | 00,161,792 | ---- | C] (SteelWerX) SWSC.exe -> %SystemRoot%\SWSC.exe -> [2009/02/12 17.37.52 | 00,136,704 | ---- | C] (SteelWerX) sed.exe -> %SystemRoot%\sed.exe -> [2009/02/12 17.37.52 | 00,098,816 | ---- | C] () fdsv.exe -> %SystemRoot%\fdsv.exe -> [2009/02/12 17.37.52 | 00,089,504 | ---- | C] (Smallfrogs Studio) grep.exe -> %SystemRoot%\grep.exe -> [2009/02/12 17.37.52 | 00,080,412 | ---- | C] () zip.exe -> %SystemRoot%\zip.exe -> [2009/02/12 17.37.52 | 00,068,096 | ---- | C] () VFIND.exe -> %SystemRoot%\VFIND.exe -> [2009/02/12 17.37.52 | 00,049,152 | ---- | C] () NIRCMD.exe -> %SystemRoot%\NIRCMD.exe -> [2009/02/12 17.37.52 | 00,029,696 | ---- | C] (NirSoft) Qoobox -> %SystemDrive%\Qoobox -> [2009/02/12 17.37.44 | 00,000,000 | ---D | C] Lop SD -> %SystemDrive%\Lop SD -> [2009/02/10 16.39.03 | 00,000,000 | ---D | C] Schema elettrico.zip -> %UserProfile%\Desktop\Schema elettrico.zip -> [2009/02/04 17.09.36 | 00,083,730 | ---- | C] () pc.xls -> G:\Documenti\pc.xls -> [2009/02/04 11.04.46 | 00,013,824 | ---- | C] () EsetOnlineScanner -> %ProgramFiles%\EsetOnlineScanner -> [2009/02/02 16.33.45 | 00,000,000 | ---D | C] _OTMoveIt -> %SystemDrive%\_OTMoveIt -> [2009/02/02 16.21.01 | 00,000,000 | ---D | C] TVAnts -> %ProgramFiles%\TVAnts -> [2009/02/02 14.12.42 | 00,000,000 | ---D | C] Thunderbird.rar -> G:\Documenti\Thunderbird.rar -> [2009/01/30 17.14.36 | 47,298,7973 | ---- | C] () VP2_Quick_Ref_Guide_Rev_A.pdf -> %UserProfile%\Desktop\VP2_Quick_Ref_Guide_Rev_A.pdf -> [2009/01/30 11.11.30 | 00,161,604 | ---- | C] () WinRAR -> %AppData%\WinRAR -> [2009/01/29 15.41.43 | 00,000,000 | ---D | C] ERUNT -> %SystemRoot%\ERUNT -> [2009/01/29 15.27.54 | 00,000,000 | ---D | C] SDFix -> %SystemDrive%\SDFix -> [2009/01/29 15.13.04 | 00,000,000 | ---D | C] avenger.zip -> %UserProfile%\Desktop\avenger.zip -> [2009/01/29 14.48.00 | 00,724,952 | ---- | C] () Thunderbird 2.0.0.19 (it) - 2009-01-29.pcv -> G:\Documenti\Thunderbird 2.0.0.19 (it) - 2009-01-29.pcv -> [2009/01/29 09.32.35 | 41,112,0482 | ---- | C] () gmer.ini -> %SystemRoot%\gmer.ini -> [2009/01/29 09.16.22 | 00,000,250 | ---- | C] () gmer.dll -> %SystemRoot%\gmer.dll -> [2009/01/29 09.16.19 | 00,884,736 | ---- | C] () gmer.exe -> %SystemRoot%\gmer.exe -> [2009/01/29 09.16.19 | 00,811,008 | ---- | C] () gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> [2009/01/29 09.16.19 | 00,085,969 | ---- | C] (GMER) gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [2009/01/29 09.16.19 | 00,000,080 | ---- | C] () autorun.inf -> %SystemDrive%\autorun.inf -> [2009/01/28 14.23.24 | 00,000,000 | RHSD | C] Turbine -> %UserProfile%\Desktop\Turbine -> [2009/01/27 14.11.29 | 00,000,000 | ---D | C] E_DCINST.DLL -> %SystemRoot%\System32\E_DCINST.DLL -> [2009/01/27 11.12.25 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) EBPPORT4.DAT -> %SystemRoot%\System32\EBPPORT4.DAT -> [2009/01/27 11.12.24 | 00,000,182 | ---- | C] () [Files/Folders - Modified Within 30 Days] 1 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> 4 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/02/25 09.49.23 | 11,124,736 | -H-- | M] () OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/02/25 09.45.49 | 00,661,370 | ---- | M] () index.dat -> %SystemRoot%\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2009/02/25 09.35.18 | 00,032,768 | ---- | M] () index.dat -> %SystemRoot%\Temp\Cronologia\History.IE5\index.dat -> [2009/02/25 09.35.18 | 00,016,384 | ---- | M] () index.dat -> %SystemRoot%\Temp\Cookies\index.dat -> [2009/02/25 09.35.18 | 00,016,384 | ---- | M] () GUEST.lnk -> %UserProfile%\Desktop\GUEST.lnk -> [2009/02/25 09.15.04 | 00,000,345 | ---- | M] () Perflib_Perfdata_274.dat -> %SystemRoot%\System32\Perflib_Perfdata_274.dat -> [2009/02/25 08.56.37 | 00,016,384 | ---- | M] () PSEXESVC.EXE -> %SystemRoot%\PSEXESVC.EXE -> [2009/02/24 16.37.39 | 00,053,248 | ---- | M] (Sysinternals) system.ini -> %SystemRoot%\system.ini -> [2009/02/24 16.29.48 | 00,000,227 | ---- | M] () hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2009/02/24 16.28.37 | 00,000,027 | ---- | M] () ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/02/24 16.24.26 | 00,000,306 | -HS- | M] () export.bat -> %UserProfile%\Desktop\export.bat -> [2009/02/24 15.18.17 | 00,000,096 | ---- | M] () d3d9caps.dat -> %SystemRoot%\System32\d3d9caps.dat -> [2009/02/24 14.42.26 | 00,001,744 | ---- | M] () eMule Incoming.lnk -> %UserProfile%\Desktop\eMule Incoming.lnk -> [2009/02/24 14.39.29 | 00,000,377 | ---- | M] () OTListIt2.exe -> %UserProfile%\Desktop\OTListIt2.exe -> [2009/02/23 17.13.08 | 00,494,080 | ---- | M] (OldTimer Tools) ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [2009/02/23 16.14.21 | 02,924,943 | R--- | M] () Immagine.jpg -> %UserProfile%\Desktop\Immagine.jpg -> [2009/02/20 14.37.12 | 00,057,568 | ---- | M] () Flash_Disinfector.exe -> %UserProfile%\Desktop\Flash_Disinfector.exe -> [2009/02/20 10.11.01 | 00,132,597 | ---- | M] () ntuser.pol -> %UserProfile%\ntuser.pol -> [2009/02/19 17.59.18 | 00,000,458 | RHS- | M] () klif.sys -> %SystemRoot%\System32\drivers\klif.sys -> [2009/02/19 15.55.55 | 00,230,032 | ---- | M] (Kaspersky Lab) klbg.sys -> %SystemRoot%\System32\drivers\klbg.sys -> [2009/02/19 15.55.55 | 00,033,808 | ---- | M] (Kaspersky Lab) klin.dat -> %SystemRoot%\System32\drivers\klin.dat -> [2009/02/19 15.55.53 | 00,101,287 | ---- | M] () klick.dat -> %SystemRoot%\System32\drivers\klick.dat -> [2009/02/19 15.55.53 | 00,089,601 | ---- | M] () NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [2009/02/19 15.13.20 | 00,000,069 | ---- | M] () athena_speech_export.dat -> %UserProfile%\Desktop\athena_speech_export.dat -> [2009/02/16 15.40.50 | 00,025,037 | ---- | M] () ONLINESCANNER.html -> %UserProfile%\Desktop\ONLINESCANNER.html -> [2009/02/16 14.43.45 | 00,026,560 | ---- | M] () FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009/02/16 09.05.46 | 00,259,048 | ---- | M] () Mozilla Firefox.lnk -> %AllUsersProfile%\Desktop\Mozilla Firefox.lnk -> [2009/02/13 17.48.19 | 00,001,461 | ---- | M] () OTMoveIt3.exe -> %UserProfile%\Desktop\OTMoveIt3.exe -> [2009/02/13 10.21.43 | 00,348,160 | ---- | M] (OldTimer Tools) imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009/02/13 09.26.35 | 00,001,410 | ---- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/02/12 17.38.16 | 00,000,006 | -H-- | M] () Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/02/12 16.36.36 | 00,000,565 | ---- | M] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/02/11 10.19.42 | 00,038,496 | ---- | M] (Malwarebytes Corporation) mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/02/11 10.19.34 | 00,015,504 | ---- | M] (Malwarebytes Corporation) hosts.20090220-115800.backup -> %SystemRoot%\System32\drivers\etc\hosts.20090220-115800.backup -> [2009/02/11 01.29.44 | 00,610,711 | ---- | M] () Schema elettrico.zip -> %UserProfile%\Desktop\Schema elettrico.zip -> [2009/02/04 17.06.33 | 00,083,730 | ---- | M] () pc.xls -> G:\Documenti\pc.xls -> [2009/02/04 11.04.46 | 00,013,824 | ---- | M] () ntuser.pol -> %AllUsersProfile%\ntuser.pol -> [2009/02/03 17.02.59 | 00,002,564 | RHS- | M] () Thunderbird.rar -> G:\Documenti\Thunderbird.rar -> [2009/01/30 17.31.58 | 47,298,7973 | ---- | M] () VP2_Quick_Ref_Guide_Rev_A.pdf -> %UserProfile%\Desktop\VP2_Quick_Ref_Guide_Rev_A.pdf -> [2009/01/30 11.11.32 | 00,161,604 | ---- | M] () avenger.zip -> %UserProfile%\Desktop\avenger.zip -> [2009/01/29 14.48.09 | 00,724,952 | ---- | M] () Thunderbird 2.0.0.19 (it) - 2009-01-29.pcv -> G:\Documenti\Thunderbird 2.0.0.19 (it) - 2009-01-29.pcv -> [2009/01/29 09.36.45 | 41,112,0482 | ---- | M] () gmer.ini -> %SystemRoot%\gmer.ini -> [2009/01/29 09.17.55 | 00,000,250 | ---- | M] () gmer.dll -> %SystemRoot%\gmer.dll -> [2009/01/29 09.16.19 | 00,884,736 | ---- | M] () gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> [2009/01/29 09.16.19 | 00,085,969 | ---- | M] (GMER) gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [2009/01/29 09.16.19 | 00,000,080 | ---- | M] () HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/01/28 14.10.05 | 00,001,451 | ---- | M] () GDIPFONTCACHEV1.DAT -> %UserProfile%\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT -> [2009/01/27 10.18.57 | 00,060,680 | ---- | M] () qmgr0.dat -> %AllUsersProfile%\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat -> [2007/08/01 15.33.40 | 00,004,232 | ---- | M] () qmgr1.dat -> %AllUsersProfile%\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat -> [2007/08/01 15.33.39 | 00,004,617 | ---- | M] () opa11.dat -> %AllUsersProfile%\Dati applicazioni\Microsoft\OFFICE\DATA\opa11.dat -> [2007/03/22 10.58.21 | 00,011,064 | ---- | M] () [Files/Folders - Unicode - All] ? -> C:\WINNT\὚ -> [2007/03/20 11.08.09 | 00,000,000 | ---- | M] () [Alternate Data Streams] @Alternate Data Stream - 4 bytes -> %UserProfile%\text.txt:ciao.txt @Alternate Data Stream - 4 bytes -> %UserProfile%\text.txt:secret.txt < End of report > [/code]