First of all many thanks to whomever will help me.
I didn't note any real problem but i was feeling something was wrong.
I've been trying to install the last version of Sandboxie but this new version didn't work.
I gave a look at Task Manager and found out a suspicious Geurge.exe running.
Scan with mbam found several adware programs and geuge.exe. Sent to quarantine.
Reboot.
Scan with trendmicro housecall found following viruses:
- explorer.exe PTCH BAMITAL SMX
- winlogon.exe PTCH BAMITAL SMX
- ms.dll Troj PATCHER JU
Scan of the files with VirusTotal confirmed the viruses.
I asked TrendMicro Housecall to fix them and after doing it, it answered that for one of them the fix was not possible and it asked to reboot.
After reboot new scan showed that the viruses were all still there but i had a new problem. After a while (10 minutes to two hours) i get a windows error saying "Generic Host Process for Win32 Services" and taskbar disappears, i cannot call taskmanager with CTRL + ALT + DEL. I cannot open Explorer and i can only shut by brute force the pc.
Reboot : even new scan with Mbam are not possible as i get a runtime error when i try to open it.
Here it follows OTL.txt
OTL logfile created on: 29/03/2011 11.19.42 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Utilia\OTL
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
1.014,00 Mb Total Physical Memory | 163,00 Mb Available Physical Memory | 16,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 71,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 139,05 Gb Total Space | 106,45 Gb Free Space | 76,56% Space Free | Partition Type: NTFS
Computer Name: PB | User Name: ute_A | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/03/29 11.17.25 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Utilia\OTL\OTL.exe
PRC - [2011/03/25 11.44.43 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Programmi\Mozilla Firefox\firefox.exe
PRC - [2011/01/17 19.40.50 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Programmi\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 19.40.50 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Programmi\OpenOffice.org 3\program\soffice.bin
PRC - [2009/07/27 16.08.40 | 000,630,784 | ---- | M] (Chicony) -- C:\Programmi\Video Web Camera\traybar.exe
PRC - [2009/05/01 05.13.34 | 000,092,696 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\PersistenceThread.exe
PRC - [2009/03/18 10.46.30 | 001,160,736 | ---- | M] (Acer Incorporated) -- C:\Programmi\Packard Bell\SetupMyPC\SmpSys.exe
PRC - [2009/03/05 09.42.08 | 000,805,384 | ---- | M] (Dritek System Inc.) -- C:\Programmi\Launch Manager\LManager.exe
PRC - [2008/10/17 11.44.58 | 000,091,432 | ---- | M] (CyberLink Corp.) -- C:\Programmi\CyberLink\PowerDVD8\PDVD8Serv.exe
PRC - [2008/04/14 14.00.00 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/09/11 01.45.04 | 000,124,832 | ---- | M] () -- C:\Programmi\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
PRC - [2002/08/14 16.21.28 | 000,094,208 | ---- | M] (Symantec Corporation) -- C:\Programmi\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
PRC - [2002/08/14 16.21.16 | 000,200,704 | ---- | M] (Symantec Corporation) -- C:\Programmi\Symantec\Norton Ghost 2003\GhostStartService.exe
========== Modules (SafeList) ==========
MOD - [2011/03/29 11.17.25 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Utilia\OTL\OTL.exe
MOD - [2008/04/14 14.00.00 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2009/08/14 14.46.30 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007/09/11 01.45.04 | 000,124,832 | ---- | M] () [Auto | Running] -- C:\Programmi\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor6.0)
SRV - [2002/08/14 16.21.16 | 000,200,704 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programmi\Symantec\Norton Ghost 2003\GhostStartService.exe -- (GhostStartService)
========== Driver Services (SafeList) ==========
DRV - [2009/07/29 08.49.04 | 005,870,080 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/04/16 05.10.06 | 000,132,480 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/02/20 10.53.18 | 001,952,512 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2007/10/01 15.59.46 | 001,769,984 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2002/08/14 16.11.16 | 000,005,632 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Programmi\Symantec\Norton Ghost 2003\GhPciScan.sys -- (GhPciScan)
DRV - [2002/08/14 16.03.36 | 000,017,005 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.pack...83wu65f47l1r461
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.pack...83wu65f47l1r461
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.pack...83wu65f47l1r461
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.pack...83wu65f47l1r461
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.80
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Programmi\Mozilla Firefox\components [2011/03/25 11.44.50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Programmi\Mozilla Firefox\plugins [2011/03/28 12.17.28 | 000,000,000 | ---D | M]
[2009/11/23 11.20.02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ute_A\Dati applicazioni\Mozilla\Extensions
[2011/03/29 09.21.41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ute_A\Dati applicazioni\Mozilla\Firefox\Profiles\07tfzd58.default\extensions
[2011/03/26 09.37.23 | 000,000,000 | ---D | M] (BitDefender QuickScan) -- C:\Documents and Settings\ute_A\Dati applicazioni\Mozilla\Firefox\Profiles\07tfzd58.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011/03/28 12.30.42 | 000,000,000 | ---D | M] (No name found) -- C:\Programmi\Mozilla Firefox\extensions
[2011/03/28 12.17.31 | 000,000,000 | ---D | M] (Java Console) -- C:\Programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/03/28 12.17.11 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMMI\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/28 12.17.10 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programmi\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/03/12 11.18.20 | 000,000,744 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\eBay-it.xml
[2011/03/12 11.18.20 | 000,000,825 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\hoepli.xml
[2011/03/12 11.18.20 | 000,001,182 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\wikipedia-it.xml
[2011/03/12 11.18.20 | 000,000,953 | ---- | M] () -- C:\Programmi\Mozilla Firefox\searchplugins\yahoo-it.xml
O1 HOSTS File: ([2008/04/14 14.00.00 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Guida per l'accesso a Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - File not found
O4 - HKLM..\Run: [AmIcoSinglun] File not found
O4 - HKLM..\Run: [AzMixerSel] C:\Programmi\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Programmi\Video Web Camera\traybar.exe (Chicony)
O4 - HKLM..\Run: [GhostStartTrayApp] C:\Programmi\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Programmi\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Programmi\CyberLink\PowerDVD8\Language\Language.exe ()
O4 - HKLM..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe (Intel Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [RemoteControl8] C:\Programmi\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\System32\csnp2uvc.dll ( )
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKCU..\Run: [cdoosoft] File not found
O4 - HKCU..\Run: [SmpcSys] C:\Programmi\Packard Bell\SetupMyPC\SmpSys.exe (Acer Incorporated)
O4 - Startup: C:\Documents and Settings\ute_A\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.3.lnk = C:\Programmi\OpenOffice.org 3\program\quickstart.exe ()
F3 - HKCU WinNT: Load - (C:\WINDOWS\system32\mswinvks.exe) - C:\WINDOWS\system32\mswinvks.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.101.93.101 83.103.25.250
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\WINDOWS\system32\mswinvks.exe) - C:\WINDOWS\system32\mswinvks.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igdlogin: DllName - igdlogin.dll - C:\WINDOWS\System32\igdlogin.dll ()
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/14 11.59.46 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/03/11 11.25.00 | 000,000,000 | ---D | M] - C:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/03/29 09.06.53 | 000,000,000 | ---D | C] -- C:\_____VIRUS
[2011/03/29 07.09.41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ute_A\Menu Avvio\Programmi\CyberLink PowerDVD 8
[2011/03/28 12.47.47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dati applicazioni\Macromedia
[2011/03/28 12.47.42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dati applicazioni\Adobe
[2011/03/28 12.29.51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documenti\sun
[2011/03/28 12.25.52 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\OpenOffice.org 3.3
[2011/03/28 12.18.51 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/03/28 12.17.41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Sun
[2011/03/28 12.17.39 | 000,000,000 | ---D | C] -- C:\Programmi\File comuni\Java
[2011/03/28 12.17.05 | 000,000,000 | ---D | C] -- C:\Programmi\Java
[2011/03/28 00.14.46 | 000,000,000 | ---D | C] -- C:\_edo
[2011/03/27 19.05.16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ute_A\Dati applicazioni\Bc
[2011/03/27 18.44.55 | 000,090,112 | ---- | C] (FDSoftware) -- C:\WINDOWS\System32\URLLabel.ocx
[2011/03/27 18.44.54 | 001,626,112 | ---- | C] (Chilkat Software, Inc.) -- C:\WINDOWS\System32\ChilkatMail_v7_9.dll
[2011/03/27 18.44.53 | 000,000,000 | ---D | C] -- C:\Programmi\AuctionSleuthxx
[2011/03/27 18.44.53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\AuctionSleuth
[2011/03/26 13.48.03 | 000,000,000 | ---D | C] -- C:\__Listen
[2011/03/23 10.54.08 | 000,000,000 | ---D | C] -- C:\_________ToBeSaved_Used
[2011/03/22 14.38.41 | 000,000,000 | ---D | C] -- C:\___EXDOC_VIKT
[2011/03/21 14.04.10 | 000,000,000 | ---D | C] -- C:\__Butta
[2011/03/07 13.14.36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ute_A\Impostazioni locali\Dati applicazioni\Identities
[2011/03/06 11.40.01 | 000,492,504 | ---- | C] (sqlite.org) -- C:\WINDOWS\System32\sqlite3.dll
[2011/03/06 11.40.01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\uninstall
[2011/03/06 11.40.01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\searchplugins
[2011/03/06 11.40.00 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\res
[2011/03/06 11.40.00 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\plugins
[2011/03/06 11.39.59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\modules
[2011/03/06 11.39.59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\greprefs
[2011/03/06 11.39.59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\defaults
[2011/03/06 11.39.58 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\components
[2011/03/06 11.39.57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\chrome
[2009/08/19 23.06.54 | 000,196,608 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc.dll
[2009/08/19 23.06.48 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2uvc.dll
========== Files - Modified Within 30 Days ==========
[2011/03/29 11.08.00 | 000,001,128 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/29 10.58.00 | 000,001,240 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1392284910-4097411637-2529006832-1006UA.job
[2011/03/29 08.58.00 | 000,001,188 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1392284910-4097411637-2529006832-1006Core.job
[2011/03/29 07.09.35 | 000,001,124 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/29 07.09.14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/03/29 07.09.11 | 1063,522,304 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/28 20.54.53 | 000,003,584 | ---- | M] () -- C:\WINDOWS\System32\ms.dll
[2011/03/28 18.32.48 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/03/28 18.32.39 | 000,269,392 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/28 17.31.46 | 006,815,744 | ---- | M] () -- C:\Documents and Settings\ute_A\NTUSER.bak
[2011/03/28 12.28.02 | 000,000,838 | ---- | M] () -- C:\Documents and Settings\ute_A\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.3.lnk
[2011/03/28 12.25.56 | 000,000,885 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.3.lnk
[2011/03/28 12.16.26 | 000,449,362 | ---- | M] () -- C:\WINDOWS\System32\perfh010.dat
[2011/03/28 12.16.26 | 000,402,740 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/28 12.16.26 | 000,075,346 | ---- | M] () -- C:\WINDOWS\System32\perfc010.dat
[2011/03/28 12.16.26 | 000,063,350 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/26 14.15.04 | 000,041,472 | ---- | M] () -- C:\Documents and Settings\ute_A\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/25 11.43.10 | 000,013,030 | ---- | M] () -- C:\PDOXUSRS.NET
[2011/03/12 12.14.07 | 000,000,170 | ---- | M] () -- C:\test.ini
[2011/03/06 11.40.01 | 000,492,504 | ---- | M] (sqlite.org) -- C:\WINDOWS\System32\sqlite3.dll
[2011/03/06 11.40.01 | 000,000,723 | ---- | M] () -- C:\WINDOWS\System32\updater.ini
[2011/03/06 11.40.01 | 000,000,478 | ---- | M] () -- C:\WINDOWS\System32\softokn3.chk
[2011/03/06 11.40.01 | 000,000,003 | ---- | M] () -- C:\WINDOWS\System32\update.locale
[2011/03/06 11.40.00 | 000,016,246 | ---- | M] () -- C:\WINDOWS\System32\removed-files
[2011/03/06 11.40.00 | 000,000,478 | ---- | M] () -- C:\WINDOWS\System32\nssdbm3.chk
[2011/03/06 11.40.00 | 000,000,142 | ---- | M] () -- C:\WINDOWS\System32\platform.ini
[2011/03/06 11.39.59 | 001,016,280 | ---- | M] () -- C:\WINDOWS\System32\js3250.dll
[2011/03/06 11.39.59 | 000,002,994 | ---- | M] () -- C:\WINDOWS\System32\crashreporter.ini
[2011/03/06 11.39.59 | 000,000,737 | ---- | M] () -- C:\WINDOWS\System32\crashreporter-override.ini
[2011/03/06 11.39.59 | 000,000,478 | ---- | M] () -- C:\WINDOWS\System32\freebl3.chk
[2011/03/06 11.39.59 | 000,000,115 | ---- | M] () -- C:\WINDOWS\System32\dependentlibs.list
[2011/03/06 11.39.57 | 000,031,393 | ---- | M] () -- C:\WINDOWS\System32\LICENSE
[2011/03/06 11.39.57 | 000,004,496 | ---- | M] () -- C:\WINDOWS\System32\blocklist.xml
[2011/03/06 11.39.57 | 000,002,129 | ---- | M] () -- C:\WINDOWS\System32\application.ini
[2011/03/06 11.39.57 | 000,000,220 | ---- | M] () -- C:\WINDOWS\System32\browserconfig.properties
[2011/03/06 11.39.57 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\.autoreg
========== Files Created - No Company Name ==========
[2011/03/28 12.28.02 | 000,000,838 | ---- | C] () -- C:\Documents and Settings\ute_A\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.3.lnk
[2011/03/28 12.25.56 | 000,000,885 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.3.lnk
[2011/03/12 12.13.37 | 000,000,170 | ---- | C] () -- C:\test.ini
[2011/03/06 11.40.01 | 000,000,723 | ---- | C] () -- C:\WINDOWS\System32\updater.ini
[2011/03/06 11.40.01 | 000,000,478 | ---- | C] () -- C:\WINDOWS\System32\softokn3.chk
[2011/03/06 11.40.01 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\update.locale
[2011/03/06 11.40.00 | 000,016,246 | ---- | C] () -- C:\WINDOWS\System32\removed-files
[2011/03/06 11.40.00 | 000,000,478 | ---- | C] () -- C:\WINDOWS\System32\nssdbm3.chk
[2011/03/06 11.40.00 | 000,000,142 | ---- | C] () -- C:\WINDOWS\System32\platform.ini
[2011/03/06 11.39.59 | 001,016,280 | ---- | C] () -- C:\WINDOWS\System32\js3250.dll
[2011/03/06 11.39.59 | 000,002,994 | ---- | C] () -- C:\WINDOWS\System32\crashreporter.ini
[2011/03/06 11.39.59 | 000,000,737 | ---- | C] () -- C:\WINDOWS\System32\crashreporter-override.ini
[2011/03/06 11.39.59 | 000,000,478 | ---- | C] () -- C:\WINDOWS\System32\freebl3.chk
[2011/03/06 11.39.59 | 000,000,115 | ---- | C] () -- C:\WINDOWS\System32\dependentlibs.list
[2011/03/06 11.39.57 | 000,031,393 | ---- | C] () -- C:\WINDOWS\System32\LICENSE
[2011/03/06 11.39.57 | 000,004,496 | ---- | C] () -- C:\WINDOWS\System32\blocklist.xml
[2011/03/06 11.39.57 | 000,002,129 | ---- | C] () -- C:\WINDOWS\System32\application.ini
[2011/03/06 11.39.57 | 000,000,220 | ---- | C] () -- C:\WINDOWS\System32\browserconfig.properties
[2011/03/06 11.39.57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\.autoreg
[2010/08/09 18.12.38 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010/07/18 16.17.22 | 000,011,264 | ---- | C] () -- C:\WINDOWS\DCEBoot.exe
[2010/07/13 08.49.09 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\LocalService\Dati applicazioni\hwzypv.dat
[2010/07/09 17.12.37 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\NetworkService\Dati applicazioni\hwzypv.dat
[2010/06/27 19.14.57 | 000,000,012 | -H-- | C] () -- C:\WINDOWS\SEE-52.DAT
[2010/03/10 19.04.49 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\ute_A\Impostazioni locali\Dati applicazioni\housecall.guid.cache
[2010/03/08 20.00.09 | 000,000,073 | ---- | C] () -- C:\WINDOWS\EurekaLog.ini
[2010/01/08 16.21.21 | 000,003,882 | -HS- | C] () -- C:\WINDOWS\System32\mswins.DLL
[2010/01/08 16.21.20 | 000,000,042 | -HS- | C] () -- C:\WINDOWS\System32\mswins.sys
[2009/11/23 11.19.56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/11/21 20.34.29 | 000,000,141 | ---- | C] () -- C:\Documents and Settings\ute_A\Impostazioni locali\Dati applicazioni\fusioncache.dat
[2009/11/21 18.13.15 | 000,041,472 | ---- | C] () -- C:\Documents and Settings\ute_A\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/19 23.06.54 | 000,028,160 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncduvc.sys
[2009/08/19 23.06.53 | 001,769,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2uvc.sys
[2009/08/19 23.06.53 | 000,000,245 | ---- | C] () -- C:\WINDOWS\PidList.ini
[2009/08/14 20.32.04 | 000,449,362 | ---- | C] () -- C:\WINDOWS\System32\perfh010.dat
[2009/08/14 20.32.04 | 000,300,212 | ---- | C] () -- C:\WINDOWS\System32\perfi010.dat
[2009/08/14 20.32.04 | 000,075,346 | ---- | C] () -- C:\WINDOWS\System32\perfc010.dat
[2009/08/14 20.32.04 | 000,034,004 | ---- | C] () -- C:\WINDOWS\System32\perfd010.dat
[2009/08/14 20.31.53 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\ms.dll
[2009/08/14 20.31.49 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2009/08/14 20.31.46 | 000,402,740 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2009/08/14 20.31.46 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2009/08/14 20.31.46 | 000,063,350 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2009/08/14 20.31.46 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2009/08/14 20.31.45 | 000,004,524 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2009/08/14 20.31.44 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2009/08/14 20.31.44 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2009/08/14 20.31.40 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2009/08/14 20.31.40 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2009/08/14 20.31.34 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2009/08/14 20.31.30 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2009/08/14 16.01.23 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/08/14 14.37.12 | 000,000,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\SamSfPa.dat
[2009/08/14 14.34.16 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2009/08/14 14.28.52 | 000,004,343 | ---- | C] () -- C:\WINDOWS\System32\lpgun.ini
[2009/08/14 14.28.42 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\igdlogin.dll
[2009/08/14 12.50.24 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/08/14 12.49.18 | 000,269,392 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/14 12.03.44 | 000,032,768 | ---- | C] () -- C:\WINDOWS\AMove.exe
[2009/08/14 12.03.44 | 000,000,544 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2009/08/14 12.02.34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/08/14 11.56.59 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/08/14 11.55.16 | 000,003,476 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/11/29 16.43.20 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\sherlock2.exe
========== LOP Check ==========
[2011/03/27 18.54.19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\AuctionSleuth
[2010/05/21 10.01.16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonIJEGV
[2010/05/20 11.57.41 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonIJScan
[2009/08/19 23.12.39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Temp
[2011/03/28 13.07.52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\Bc
[2010/06/25 20.33.45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\Canon
[2009/12/25 01.34.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\Foxit
[2010/07/09 17.12.23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\Foxit Software
[2010/08/09 20.37.36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\FreeFileSync
[2009/11/23 13.05.19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\OpenOffice.org
[2009/11/21 15.23.35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\Packard Bell
[2010/01/08 18.51.29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\QuickScan
[2010/07/11 07.56.50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ute_A\Dati applicazioni\Thinstall
========== Purity Check ==========
< End of report >
Thanks again
edofal