You posted the Extras log. We really want the OTL log.
Could I see the combofix log from your earlier attempt?
TidServ.B is an infector of the mbr.
Since you have the DVD:
See if repairing the mbr per http://www.ehow.com/...br-windows.html will help.
After you get to the command prompt you need to change to the boot folder so type:
cd \boot
or maybe
cd boot
one of them should work and take you to the folder where bootsect lives.
Ron
Hi,
thanks for your tips.
I'll test to execute the "bootsect /nt60 C:\" or the "bootsect /nt60 ALL".
Nevertheless, here you can find the OTL log file (sorry for my mistake).
Thanks.
FG
OTL logfile created on: 3/28/2011 10:51:13 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\giorgf\Desktop
Enterprise Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148.95 Gb Total Space | 65.49 Gb Free Space | 43.97% Space Free | Partition Type: NTFS
Drive D: | 2.24 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: GIORGF-PC | User Name: giorgf | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/03/28 22:44:11 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\giorgf\Desktop\OTL.exe
PRC - [2011/01/30 00:11:36 | 003,372,856 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
PRC - [2010/12/20 17:57:04 | 000,602,872 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
PRC - [2010/12/19 01:25:16 | 000,048,456 | ---- | M] (Mobile Stream) -- C:\Program Files\Mobile Stream\EasyTether\easytthr.exe
PRC - [2010/11/24 04:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe
PRC - [2010/11/12 18:54:30 | 005,145,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office Communicator\communicator.exe
PRC - [2010/11/11 14:31:54 | 000,334,448 | ---- | M] (VMware, Inc.) -- C:\Windows\System32\vmnetdhcp.exe
PRC - [2010/11/11 14:31:50 | 000,404,080 | ---- | M] (VMware, Inc.) -- C:\Windows\System32\vmnat.exe
PRC - [2010/11/11 14:31:36 | 000,064,112 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\hqtray.exe
PRC - [2010/11/11 14:30:44 | 000,113,264 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\vmware-authd.exe
PRC - [2010/11/11 13:31:44 | 000,539,248 | ---- | M] (VMware, Inc.) -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2010/10/25 11:03:52 | 000,217,088 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
PRC - [2010/03/29 21:26:00 | 000,227,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2009/11/12 14:48:56 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2009/10/31 07:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/01/21 07:49:14 | 000,153,096 | ---- | M] (EMC) -- C:\Program Files\eRoom 7\ERClient7.exe
PRC - [2008/11/04 12:40:24 | 002,087,424 | ---- | M] (Vodafone) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
PRC - [2008/11/04 12:39:20 | 000,014,336 | ---- | M] (Vodafone) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
PRC - [2007/09/25 02:11:35 | 000,329,104 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
PRC - [2007/09/25 02:11:35 | 000,132,496 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
PRC - [2007/07/16 12:58:02 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2007/02/20 12:07:40 | 000,199,752 | ---- | M] (Pinnacle Systems GmbH) -- C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
========== Modules (SafeList) ========== MOD - [2011/03/28 22:44:11 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\giorgf\Desktop\OTL.exe
MOD - [2010/08/21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2010/12/20 17:57:04 | 000,602,872 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2010/11/24 04:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe -- (NAV)
SRV - [2010/11/15 07:55:56 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/11/11 14:31:54 | 000,334,448 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\System32\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2010/11/11 14:31:50 | 000,404,080 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\System32\vmnat.exe -- (VMware NAT Service)
SRV - [2010/11/11 14:30:44 | 000,113,264 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2010/11/11 13:31:44 | 000,539,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2010/10/25 11:03:52 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010/08/19 14:57:14 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files\VMware\VMware Player\vmware-ufad.exe -- (ufad-ws60)
SRV - [2010/03/25 11:25:22 | 030,969,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2009/11/12 14:48:56 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2009/07/14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/14 03:15:36 | 000,038,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lpdsvc.dll -- (LPDSVC)
SRV - [2008/11/04 12:39:20 | 000,014,336 | ---- | M] (Vodafone) [Auto | Running] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2007/07/16 12:58:02 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
========== Driver Services (SafeList) ========== DRV - [2011/03/28 20:58:01 | 000,053,248 | ---- | M] (eSage Lab) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rk_remover.sys -- (rk_remover-boot)
DRV - [2011/03/27 11:35:05 | 001,360,760 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110328.017\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/03/27 11:35:05 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/03/27 11:35:05 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/03/27 11:35:05 | 000,086,008 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110328.017\NAVENG.SYS -- (NAVENG)
DRV - [2011/03/27 11:19:27 | 000,126,512 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/03/09 21:11:42 | 000,800,376 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110309.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011/01/03 10:38:36 | 000,136,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011/01/03 10:38:36 | 000,121,192 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV - [2011/01/03 10:38:36 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl) SAMSUNG Android USB Modem (Filter)
DRV - [2010/12/21 07:55:02 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010/12/01 07:24:00 | 000,295,032 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\NAV\1205000.07D\SYMNETS.SYS -- (SymNetS)
DRV - [2010/11/23 06:59:15 | 000,035,960 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\SymIMV.sys -- (SymIM)
DRV - [2010/11/23 06:08:31 | 000,509,560 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\Drivers\NAV\1205000.07D\SRTSP.SYS -- (SRTSP)
DRV - [2010/11/23 06:08:31 | 000,050,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\NAV\1205000.07D\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/11/18 04:59:55 | 000,652,336 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\system32\drivers\NAV\1205000.07D\SYMEFA.SYS -- (SymEFA)
DRV - [2010/11/16 03:45:33 | 000,136,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\NAV\1205000.07D\Ironx86.SYS -- (SymIRON)
DRV - [2010/11/11 14:32:10 | 000,070,768 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmci.sys -- (vmci)
DRV - [2010/11/11 14:32:08 | 000,854,128 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmx86.sys -- (vmx86)
DRV - [2010/11/11 14:30:34 | 000,024,688 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VMkbd.sys -- (vmkbd)
DRV - [2010/11/11 14:29:26 | 000,026,352 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV - [2010/11/11 13:31:28 | 000,032,368 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hcmon.sys -- (hcmon)
DRV - [2010/11/11 11:04:52 | 000,036,400 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV - [2010/11/11 11:04:52 | 000,016,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV - [2010/11/09 02:50:30 | 000,353,912 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110325.001\IDSvix86.sys -- (IDSVix86)
DRV - [2010/10/25 11:03:52 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010/10/21 04:28:36 | 000,340,016 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\NAV\1205000.07D\SYMDS.SYS -- (SymDS)
DRV - [2010/08/29 18:18:06 | 000,017,232 | ---- | M] (Mobile Stream) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\easytthr.sys -- (easytether)
DRV - [2010/08/19 14:56:38 | 000,022,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files\VMware\VMware Player\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2010/08/16 20:02:49 | 000,019,680 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vpnva.sys -- (vpnva)
DRV - [2009/11/12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009/08/18 13:06:54 | 000,037,120 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gtuqbus.sys -- (GTUQBUS)
DRV - [2009/08/18 13:06:54 | 000,021,248 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gtscser.sys -- (GTSCSER)
DRV - [2009/08/18 13:06:54 | 000,008,064 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gtptser.sys -- (GTPTSER)
DRV - [2009/08/18 13:06:52 | 000,107,776 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gtuhs51.sys -- (GTUHSNDISIPXP)
DRV - [2009/08/18 13:06:52 | 000,067,840 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gtuhsbus.sys -- (GTUHSBUS)
DRV - [2009/08/18 13:06:52 | 000,008,064 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gtuhsser.sys -- (GTUHSSER)
DRV - [2009/07/14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/03/11 15:04:00 | 007,545,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2007/07/16 12:57:12 | 000,306,299 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2007/01/31 14:45:06 | 000,127,376 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE)
DRV - [2007/01/18 16:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2005/09/23 23:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = AB 81 31 BF 2C 84 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = serprx101rm001.services.external.local:8080
========== FireFox ========== FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/03/27 11:56:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/03/06 12:07:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/11/30 00:38:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\giorgf\AppData\Roaming\Mozilla\Extensions
[2010/11/30 00:38:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\giorgf\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
O1 HOSTS File: ([2011/03/28 15:35:08 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Office Communicator\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Windows\System32\nwiz.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [USBToolTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKCU..\Run: [EasyTether] C:\Program Files\Mobile Stream\EasyTether\easytthr.exe (Mobile Stream)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Users\giorgf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor My eRooms (V7).lnk = C:\Program Files\eRoom 7\ERClient7.exe (EMC)
O4 - Startup: C:\Users\giorgf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68}
http://picasaweb.goo...1/uploader2.cab (UploadListView Class)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566}
https://crk01-00i2d-...ries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124}
http://ctseroom02.co...etup/client.cab (ERPageAddin Class)
O16 - DPF: {705EC6D4-B138-4079-A307-EF13E4889A82}
https://crk01-00i2d-...ies/instweb.cab (CSD ActiveX Installer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://isc2educatio...ng/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F8FC1530-0608-11DF-2008-0800200C9A66}
https://crk01-00i1d-...ies/instweb.cab (CSD ActiveX Installer)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/07/14 10:13:55 | 000,000,043 | R--- | M] () - D:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/03/28 22:44:08 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\giorgf\Desktop\OTL.exe
[2011/03/28 22:15:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011/03/28 22:12:18 | 095,812,448 | ---- | C] ( ) -- C:\Users\giorgf\Desktop\setup_9.0.0.722_28.03.2011_22-17.exe
[2011/03/28 22:05:14 | 000,566,272 | ---- | C] (AVAST Software) -- C:\Users\giorgf\Desktop\aswMBR.exe
[2011/03/28 20:53:06 | 000,053,248 | ---- | C] (eSage Lab) -- C:\Windows\System32\drivers\rk_remover.sys
[2011/03/28 20:52:31 | 000,000,000 | ---D | C] -- C:\Users\giorgf\Desktop\tdss_remover_latest
[2011/03/28 15:38:50 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/03/28 15:22:15 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/03/28 14:55:25 | 010,832,208 | ---- | C] (Symantec Corporation) -- C:\Users\giorgf\Desktop\nortonsafeweblite.exe
[2011/03/27 14:19:16 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Local\NPE
[2011/03/27 12:31:03 | 000,035,960 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\SymIMV.sys
[2011/03/27 11:35:39 | 000,652,336 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\NAV\1205000.07D\symefa.sys
[2011/03/27 11:35:39 | 000,509,560 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.sys
[2011/03/27 11:35:39 | 000,340,016 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\NAV\1205000.07D\symds.sys
[2011/03/27 11:35:39 | 000,295,032 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\NAV\1205000.07D\symnets.sys
[2011/03/27 11:35:39 | 000,136,312 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\NAV\1205000.07D\ironx86.sys
[2011/03/27 11:35:39 | 000,050,168 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.sys
[2011/03/27 11:35:30 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NAV\1205000.07D
[2011/03/27 11:19:27 | 000,126,512 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/03/27 11:19:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2011/03/27 11:19:27 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2011/03/27 11:18:56 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NAV
[2011/03/27 11:18:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton AntiVirus
[2011/03/27 11:18:54 | 000,000,000 | ---D | C] -- C:\Program Files\Norton AntiVirus
[2011/03/27 11:18:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2011/03/27 11:18:07 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2011/03/27 11:18:07 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2011/03/27 11:11:56 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/03/18 21:13:28 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Roaming\Canneverbe_Limited
[2011/03/18 21:13:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2011/03/18 21:12:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP
[2011/03/18 21:12:40 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP
[2011/03/16 14:43:51 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/03/14 12:10:24 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Roaming\Insight
[2011/03/11 14:48:17 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/03/10 10:52:27 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Local\Google
[2011/03/10 10:52:09 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Local\Deployment
[2011/03/10 10:52:09 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Local\Apps
[2011/03/08 23:08:51 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/03/08 18:40:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis
[2011/03/08 18:40:55 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/03/08 17:26:44 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Roaming\Malwarebytes
[2011/03/08 17:26:36 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/03/08 17:26:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/08 17:26:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/03/08 17:26:33 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/03/08 17:26:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/07 11:11:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win2PDF
[2011/03/06 23:14:16 | 000,000,000 | ---D | C] -- C:\AVG10
[2011/03/04 19:11:41 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2011/03/03 11:09:30 | 000,000,000 | ---D | C] -- C:\Users\giorgf\Documents\Pinnacle Studio
[2011/03/03 11:08:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle Studio Ultimate Collection
[2011/03/03 10:29:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Studio Plugins
[2011/03/03 10:29:44 | 000,090,112 | ---- | C] (MindVision Software) -- C:\Windows\unvise32.exe
[2011/03/03 10:25:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Pinnacle
[2011/03/03 10:24:55 | 000,000,000 | ---D | C] -- C:\Users\giorgf\AppData\Local\Pinnacle
[2011/03/03 10:24:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle Studio Ultimate
[2011/03/03 10:22:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pinnacle Studio 15
[2011/03/03 10:21:45 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\My Projects
[2011/03/03 10:18:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Pegasus Imaging
[2011/03/03 10:18:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Yahoo!
[2011/03/03 10:18:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Studio 15
[2011/03/03 10:18:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle Studio Plus
[2011/03/03 10:18:19 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Pinnacle
[2011/03/03 10:18:19 | 000,000,000 | ---D | C] -- C:\Program Files\Pinnacle
[2011/03/03 10:14:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle
========== Files - Modified Within 30 Days ========== [2011/03/28 22:48:00 | 000,001,162 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2333114377-402739105-1773717283-1001UA.job
[2011/03/28 22:44:54 | 000,012,272 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/28 22:44:54 | 000,012,272 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/28 22:44:11 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\giorgf\Desktop\OTL.exe
[2011/03/28 22:42:32 | 000,676,474 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/03/28 22:42:32 | 000,126,038 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/03/28 22:41:12 | 000,133,632 | ---- | M] () -- C:\Users\giorgf\Desktop\RKUnhookerLE.EXE
[2011/03/28 22:37:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/03/28 22:37:26 | 2414,321,664 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/28 22:12:18 | 095,812,448 | ---- | M] ( ) -- C:\Users\giorgf\Desktop\setup_9.0.0.722_28.03.2011_22-17.exe
[2011/03/28 22:08:16 | 000,011,980 | ---- | M] () -- C:\Users\giorgf\Desktop\AVPTool.htm
[2011/03/28 22:05:18 | 000,566,272 | ---- | M] (AVAST Software) -- C:\Users\giorgf\Desktop\aswMBR.exe
[2011/03/28 20:58:01 | 000,053,248 | ---- | M] (eSage Lab) -- C:\Windows\System32\drivers\rk_remover.sys
[2011/03/28 20:50:52 | 000,039,605 | ---- | M] () -- C:\Users\giorgf\Desktop\bootkit_remover.rar
[2011/03/28 20:50:30 | 000,385,818 | ---- | M] () -- C:\Users\giorgf\Desktop\tdss_remover_latest.rar
[2011/03/28 20:36:01 | 001,046,814 | ---- | M] () -- C:\Windows\System32\drivers\NAV\1205000.07D\Cat.DB
[2011/03/28 15:35:08 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/03/28 15:04:35 | 392,754,039 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/03/28 14:55:25 | 010,832,208 | ---- | M] (Symantec Corporation) -- C:\Users\giorgf\Desktop\nortonsafeweblite.exe
[2011/03/28 14:21:35 | 000,000,953 | ---- | M] () -- C:\Users\giorgf\Desktop\fnd_gfm fabio.tsv
[2011/03/28 13:48:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2333114377-402739105-1773717283-1001Core.job
[2011/03/28 12:11:58 | 000,000,670 | ---- | M] () -- C:\Windows\1way.ini
[2011/03/27 11:19:27 | 000,126,512 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/03/27 11:19:27 | 000,007,456 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/03/27 11:19:27 | 000,000,805 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF
[2011/03/07 11:11:17 | 000,000,000 | ---- | M] () -- C:\Windows\Progs_.ini
[2011/03/05 21:04:53 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2011/03/03 16:46:05 | 000,012,288 | ---- | M] () -- C:\Users\giorgf\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/03 10:34:12 | 000,473,440 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/03/02 16:19:45 | 000,002,237 | ---- | M] () -- C:\Users\giorgf\Desktop\TI1632144 - Consolidamento Storage e Backup - Shortcut.lnk
========== Files Created - No Company Name ========== [2011/03/28 22:41:09 | 000,133,632 | ---- | C] () -- C:\Users\giorgf\Desktop\RKUnhookerLE.EXE
[2011/03/28 22:08:16 | 000,011,980 | ---- | C] () -- C:\Users\giorgf\Desktop\AVPTool.htm
[2011/03/28 20:50:52 | 000,039,605 | ---- | C] () -- C:\Users\giorgf\Desktop\bootkit_remover.rar
[2011/03/28 20:50:28 | 000,385,818 | ---- | C] () -- C:\Users\giorgf\Desktop\tdss_remover_latest.rar
[2011/03/28 14:21:35 | 000,000,953 | ---- | C] () -- C:\Users\giorgf\Desktop\fnd_gfm fabio.tsv
[2011/03/27 11:55:01 | 001,046,814 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\Cat.DB
[2011/03/27 11:35:39 | 000,007,528 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\iron.cat
[2011/03/27 11:35:39 | 000,007,458 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\symnet.cat
[2011/03/27 11:35:39 | 000,007,456 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\symefa.cat
[2011/03/27 11:35:39 | 000,007,454 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.cat
[2011/03/27 11:35:39 | 000,007,450 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\symds.cat
[2011/03/27 11:35:39 | 000,007,450 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.cat
[2011/03/27 11:35:39 | 000,003,374 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\symefa.inf
[2011/03/27 11:35:39 | 000,002,792 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\symds.inf
[2011/03/27 11:35:39 | 000,001,446 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\symnet.inf
[2011/03/27 11:35:39 | 000,001,389 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.inf
[2011/03/27 11:35:39 | 000,001,383 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.inf
[2011/03/27 11:35:39 | 000,000,742 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\iron.inf
[2011/03/27 11:35:30 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1205000.07D\isolate.ini
[2011/03/27 11:19:27 | 000,007,456 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/03/27 11:19:27 | 000,000,805 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.INF
[2011/03/18 21:12:40 | 000,007,168 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2011/03/16 14:43:27 | 000,001,162 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2333114377-402739105-1773717283-1001UA.job
[2011/03/16 14:43:26 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2333114377-402739105-1773717283-1001Core.job
[2011/03/11 14:48:07 | 392,754,039 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/03/07 11:11:53 | 000,150,760 | ---- | C] () -- C:\Windows\System32\WIN2PDFS.DLL
[2011/03/07 11:11:53 | 000,074,472 | ---- | C] () -- C:\Windows\System32\WIN2PDFM.DLL
[2011/03/07 11:11:17 | 000,000,000 | ---- | C] () -- C:\Windows\Progs_.ini
[2011/03/03 12:47:45 | 000,012,288 | ---- | C] () -- C:\Users\giorgf\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/03 10:16:05 | 000,000,349 | ---- | C] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2011/01/29 18:00:24 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011/01/29 18:00:22 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011/01/29 18:00:22 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011/01/29 18:00:22 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011/01/29 18:00:22 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2011/01/08 20:02:57 | 000,084,480 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/11/18 20:06:00 | 000,000,670 | ---- | C] () -- C:\Windows\1way.ini
[2010/11/18 09:29:02 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2010/11/18 09:29:02 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010/11/14 21:09:17 | 001,724,416 | ---- | C] () -- C:\Windows\System32\nvwdmcpl.dll
[2010/11/14 21:09:17 | 001,657,376 | ---- | C] () -- C:\Windows\System32\nwiz.exe
[2010/11/14 21:09:17 | 001,503,232 | ---- | C] () -- C:\Windows\System32\nView.dll
[2010/11/14 21:09:17 | 001,101,824 | ---- | C] () -- C:\Windows\System32\nvwimg.dll
[2010/11/14 21:09:17 | 000,466,944 | ---- | C] () -- C:\Windows\System32\nvShell.dll
[2010/11/14 21:09:17 | 000,449,056 | ---- | C] () -- C:\Windows\System32\nvAppBar.exe
[2010/11/14 21:09:17 | 000,158,240 | ---- | C] () -- C:\Windows\System32\nvTaskbar.exe
[2009/10/06 09:16:00 | 000,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/07/14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 06:33:53 | 000,473,440 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 04:05:48 | 000,676,474 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 04:05:48 | 000,126,038 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 02:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2008/11/12 14:51:04 | 000,135,882 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2008/08/20 16:45:46 | 000,020,270 | ---- | C] () -- C:\ProgramData\DeviceInstaller.xml
[2008/07/31 11:01:00 | 000,000,000 | ---- | C] () -- C:\Windows\System32\ToolBx.dll
[2008/03/07 17:03:14 | 000,013,312 | ---- | C] () -- C:\Windows\System32\CallSimReader.dll
[2008/03/07 17:02:24 | 000,061,440 | ---- | C] () -- C:\Windows\System32\SimReader.dll
[2007/07/16 12:58:10 | 000,197,408 | ---- | C] () -- C:\Windows\System32\vpnapi.dll
========== LOP Check ========== [2010/11/14 21:45:01 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\AVG10
[2011/03/19 18:19:03 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\BitTorrent
[2010/11/14 23:09:24 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Bytemobile
[2011/03/18 21:13:28 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Canneverbe_Limited
[2010/12/17 10:14:22 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Cisco
[2010/12/23 16:52:31 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\eRoom
[2011/03/11 18:49:33 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\FileZilla
[2011/03/28 11:42:06 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Insight
[2011/02/14 10:19:36 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\PPTminimizer
[2010/11/18 09:28:34 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Samsung
[2010/11/30 00:38:15 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Thunderbird
[2011/01/25 10:46:04 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Trondent Development Corp
[2010/11/14 23:11:34 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Vodafone
[2011/01/07 16:28:22 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\WD
[2010/11/30 00:54:02 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\webex
[2011/02/10 11:33:00 | 000,000,000 | ---D | M] -- C:\Users\giorgf\AppData\Roaming\Xerox
[2011/02/25 12:38:47 | 000,032,634 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== < End of report >