I'm a newbie here and this is my first post, i hope i do everything in the right way....i try to explain my problem.
Some days ago i plugged an USB pendrive to my pc and i noticed that, at first, the system was not recognizing it and then it stopped working; then i rebooted and i noticed that my pc was very slow like a slug, even if i boot it into safe mode. If i open the task manager, the process named service.exe eat at least 80-90% CPU usage; i realized that it might be caused by a malware or something (i googled around and i found that maybe it was caused by a rootkit). So i downloaded MBRCheck that alerted me about a Whistler - Black Internet rootkit located into the other 2 physical HDD i have on my system (D: and E:, C: was ok). Then i shut off the system and disconnected the power cord of those 2 HDD, but the problem is still there: services.exe eat a lot of CPU. I tried to fix the issue by myself, i runned MalwareBytes (nothing unusual found), Combofix (it took about one hour to do the scan and deleted a couple of directories), Avast Antivirus (nothing found), Hitman Pro(nothing found), HiJackThis (i posted the report on the official board, but everything seemed to be ok). Another strange fact is that when i ran ComboFix it said that there was the Avast real-time scanner running, but in the Task Manager and in the Process Explorer there was no process related to Avast; before running Combofix i uninstalled Avast using CCleaner uninstaller first and then the Avast Remover Tools too.
I tried to search a fix for my problem in this forum too, but nothing worked, so i decided to start this topic; here's the OTL report:
OTL logfile created on: 02/12/2011 13.37.41 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\daneelo\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,00 Gb Total Physical Memory | 2,48 Gb Available Physical Memory | 82,63% Memory free
7,24 Gb Paging File | 6,94 Gb Available in Paging File | 95,91% Paging File free
Paging file location(s): C:\pagefile.sys 4500 9000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 149,04 Gb Total Space | 39,41 Gb Free Space | 26,44% Space Free | Partition Type: NTFS
Computer Name: PC-CASA | User Name: daneelo | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/02 13.36.50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\daneelo\Desktop\OTL.exe
PRC - [2011/11/08 20.17.22 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programmi\Mozilla Firefox\firefox.exe
PRC - [2007/06/13 14.22.28 | 001,035,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/08 20.17.21 | 001,989,592 | ---- | M] () -- C:\Programmi\Mozilla Firefox\mozjs.dll
MOD - [2011/10/08 05.50.00 | 000,355,432 | ---- | M] () -- C:\Programmi\NVIDIA Corporation\nView\nvShell.dll
MOD - [2011/05/26 19.25.51 | 006,271,136 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2009/02/27 18.42.50 | 000,311,296 | ---- | M] () -- C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\pdfshell.ITA
MOD - [2008/09/16 20.18.06 | 000,132,608 | ---- | M] () -- C:\Programmi\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/11/18 14.22.22 | 003,313,752 | ---- | M] () [Disabled | Stopped] -- c:\programmi\file comuni\akamai/netsession_win_d768ebc.dll -- (Akamai)
SRV - [2011/11/05 15.39.15 | 000,072,704 | ---- | M] (Adobe Systems) [Disabled | Stopped] -- C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2011/10/08 05.50.00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\Programmi\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/10/07 11.24.26 | 000,074,752 | ---- | M] (Freemake) [Disabled | Stopped] -- C:\Documents and Settings\All Users\Dati applicazioni\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (FreemakeUtilsService)
SRV - [2011/08/31 17.00.48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/08/15 15.18.10 | 001,361,288 | ---- | M] (LogMeIn Inc.) [Disabled | Stopped] -- C:\Programmi\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2010/01/02 19.07.59 | 000,655,624 | ---- | M] (Acresso Software Inc.) [Disabled | Stopped] -- C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/12/23 22.34.20 | 000,370,688 | ---- | M] (StarWind Software) [Disabled | Stopped] -- C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2007/02/05 10.11.18 | 000,075,320 | ---- | M] (Sony Corporation) [Disabled | Stopped] -- C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2007/02/05 10.11.16 | 000,112,184 | ---- | M] (Sony Corporation) [Disabled | Stopped] -- C:\Programmi\File comuni\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service)
SRV - [2006/12/14 02.21.20 | 000,045,056 | ---- | M] (Sony Corporation) [Disabled | Stopped] -- C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2006/12/14 02.02.08 | 000,069,632 | ---- | M] (Sony Corporation) [Disabled | Stopped] -- C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - [2006/12/14 01.46.16 | 000,057,344 | ---- | M] () [Disabled | Stopped] -- C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2005/11/23 07.58.04 | 000,765,952 | ---- | M] (Diskeeper Corporation) [Disabled | Stopped] -- C:\Programmi\Diskeeper Corporation\Diskeeper\DkService.exe -- (Diskeeper)
SRV - [2005/11/14 01.06.04 | 000,069,632 | ---- | M] (Macrovision Corporation) [Disabled | Stopped] -- C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2003/07/28 20.28.22 | 000,089,136 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - [2011/08/31 17.00.50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/10/15 12.31.36 | 000,436,792 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/03/18 16.35.40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2008/07/25 13.09.24 | 000,845,184 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2008/07/01 04.27.44 | 000,108,800 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2008/02/14 07.12.00 | 001,389,056 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\monfilt.sys -- (monfilt)
DRV - [2006/06/14 12.44.30 | 000,012,288 | R--- | M] (ASUSTeK Computer Inc.) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\EIO_XP.sys -- (EIO_XP)
DRV - [2005/05/27 09.31.28 | 000,022,016 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2005/01/31 11.20.04 | 000,211,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2004/08/13 11.56.20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://getii.com/dvds
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Search-Results"
FF - prefs.js..browser.search.defaultenginename: "Search-Results"
FF - prefs.js..browser.search.defaultthis.engineName: "Veoh Web Player Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search-Results"
FF - prefs.js..browser.search.selectedEngine: "Google Italia"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.it/"
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.4
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {5F590AA2-1221-4113-A6F4-A4BB62414FAC}:0.45.6.20100202.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.5.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.4
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: [email protected]:0.76
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {8be51513-0433-45c1-9203-7b45019df871}:1.0.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: [email protected]:2.1.3.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e2c58150-9d72-11dd-ad8b-0800200c9a66}:1.3.1
FF - prefs.js..extensions.enabledItems: {86FA6F53-95FE-7A69-D8C3-E1454281F8B6}:3.5.3
FF - prefs.js..extensions.enabledItems: {66871bd1-5ba2-4739-b485-2a15f5969bd8}:2.20100123
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - prefs.js..extensions.enabledItems: {c1dffba0-628e-11d9-9669-0800200c9a66}:3.6.3
FF - prefs.js..extensions.enabledItems: [email protected]:3.6
FF - prefs.js..keyword.URL: "http://search.condui...d=CT2653012&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js..network.proxy.type: 0
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port:
FF - user.js..network.proxy.no_proxies_on: ""
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Programmi\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Programmi\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programmi\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmi\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Programmi\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programmi\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programmi\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programmi\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veoh.com/VeohTVPlugin: C:\Programmi\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@veoh.com/VeohWebPlayer: C:\Programmi\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll (Veoh)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmi\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Programmi\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2011/10/10 11.36.57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Programmi\Mozilla Firefox\components [2011/11/08 20.17.22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Programmi\Mozilla Firefox\plugins [2011/06/20 10.44.49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Programmi\Mozilla Thunderbird\components [2011/08/26 16.39.18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Programmi\Mozilla Thunderbird\plugins [2011/06/20 10.44.50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Programmi\Veoh Networks\VeohWebPlayer\FFVideoFinder [2009/09/13 12.45.57 | 000,000,000 | ---D | M]
[2010/07/11 14.20.45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Extensions
[2010/07/11 14.20.45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/11/30 12.27.27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\extensions
[2010/03/26 14.12.46 | 000,000,000 | ---D | M] (Screengrab) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/02/03 16.07.10 | 000,000,000 | ---D | M] (SmoothWheel (mozdev.org)) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}
[2011/11/30 12.27.27 | 000,000,000 | ---D | M] (BitDefender QuickScan) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011/11/13 18.56.55 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/10/20 14.00.51 | 000,000,000 | ---D | M] (printpdf) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\extensions\[email protected]
[2011/04/08 13.26.34 | 000,000,000 | ---D | M] (QuickDrag) -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\extensions\[email protected]
[2010/09/12 16.32.04 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\searchplugins\conduit.xml
[2011/11/25 20.04.16 | 000,002,452 | ---- | M] () -- C:\Documents and Settings\daneelo\Dati applicazioni\Mozilla\Firefox\Profiles\auw417bx.default\searchplugins\google-italia.xml
[2011/11/08 20.17.36 | 000,000,000 | ---D | M] (No name found) -- C:\Programmi\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\DANEELO\DATI APPLICAZIONI\MOZILLA\FIREFOX\PROFILES\AUW417BX.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\DANEELO\DATI APPLICAZIONI\MOZILLA\FIREFOX\PROFILES\AUW417BX.DEFAULT\EXTENSIONS\{75CEEE46-9B64-46F8-94BF-54012DE155F0}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\DANEELO\DATI APPLICAZIONI\MOZILLA\FIREFOX\PROFILES\AUW417BX.DEFAULT\EXTENSIONS\{AE93811A-5C9A-4D34-8462-F7B864FC4696}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\DANEELO\DATI APPLICAZIONI\MOZILLA\FIREFOX\PROFILES\AUW417BX.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\DANEELO\DATI APPLICAZIONI\MOZILLA\FIREFOX\PROFILES\AUW417BX.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\DANEELO\DATI APPLICAZIONI\MOZILLA\FIREFOX\PROFILES\AUW417BX.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\DANEELO\DATI APPLICAZIONI\MOZILLA\FIREFOX\PROFILES\AUW417BX.DEFAULT\EXTENSIONS\[email protected]
[2011/11/08 20.17.22 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Programmi\mozilla firefox\components\browsercomps.dll
[2010/11/12 18.53.06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programmi\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/02 12.29.23 | 000,002,252 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\bing.xml
[2009/11/03 03.26.39 | 000,001,412 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\demauro.xml
[2011/10/02 12.29.23 | 000,000,744 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\eBay-it.xml
[2011/10/02 12.29.23 | 000,000,825 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\hoepli.xml
[2011/10/02 12.29.23 | 000,001,182 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\wikipedia-it.xml
[2011/10/02 12.29.23 | 000,000,953 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\yahoo-it.xml
O1 HOSTS File: ([2011/11/28 14.30.33 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Guida per l'accesso a Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programmi\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programmi\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Scarica con Free Download Manager - C:\Programmi\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Scarica i video con Free Download Manager - C:\Programmi\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Scarica selezionati con Free Download Manager - C:\Programmi\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Scarica tutto con Free Download Manager - C:\Programmi\Free Download Manager\dlall.htm ()
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programmi\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programmi\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF34E6E9-CFCC-4318-B4FC-1D917AA6FB94}: NameServer = 212.216.112.222,212.216.172.162
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programmi\File comuni\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Pagina iniziale corrente) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/19 21.02.28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/02 13.36.49 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\daneelo\Desktop\OTL.exe
[2011/12/01 22.00.37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/12/01 22.00.30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Dati applicazioni\TrojanHunter
[2011/12/01 21.39.36 | 000,000,000 | ---D | C] -- C:\Programmi\TrojanHunter 5.5
[2011/12/01 21.17.34 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/12/01 20.06.54 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/12/01 20.06.54 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/12/01 20.06.54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/12/01 20.06.54 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/12/01 20.05.38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/01 20.02.47 | 004,324,789 | R--- | C] (Swearware) -- C:\Documents and Settings\daneelo\Desktop\ComboFix.exe
[2011/12/01 18.10.44 | 000,636,728 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\daneelo\Desktop\autoruns.exe
[2011/12/01 14.47.41 | 000,000,000 | ---D | C] -- C:\Programmi\Hitman Pro 3.5
[2011/12/01 14.46.59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Hitman Pro
[2011/11/30 13.08.48 | 003,022,624 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\daneelo\Desktop\Procmon.exe
[2011/11/30 12.27.33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Dati applicazioni\QuickScan
[2011/11/29 19.44.43 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Documents and Settings\daneelo\Desktop\boot_cleaner.exe
[2011/11/28 21.01.39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Menu Avvio\Programmi\HiJackThis
[2011/11/28 20.17.26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes' Anti-Malware
[2011/11/28 20.17.23 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/28 18.52.21 | 004,845,856 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\daneelo\Desktop\procexp.exe
[2011/11/28 14.22.49 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/11/28 13.26.00 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\daneelo\Recent
[2011/11/23 18.39.39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Google Earth
[2011/11/21 21.31.32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Menu Avvio\Programmi\The Treasures of Montezuma 3
[2011/11/21 21.31.14 | 000,000,000 | ---D | C] -- C:\WINDOWS\The Treasures of Montezuma 3
[2011/11/21 21.31.14 | 000,000,000 | ---D | C] -- C:\Programmi\The Treasures of Montezuma 3
[2011/11/17 19.48.53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Dati applicazioni\JewelMatch2
[2011/11/16 21.26.13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Menu Avvio\Programmi\Alawar Games
[2011/11/14 18.22.56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Dati applicazioni\BlamGames
[2011/11/10 12.41.26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Impostazioni locali\Dati applicazioni\Akamai
[2011/11/10 12.29.20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daneelo\Documenti\Working Folder 0
[2011/11/06 12.11.24 | 000,000,000 | ---D | C] -- C:\Programmi\NeroPortable
[2011/11/05 15.50.07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\regid.1986-12.com.adobe
[2011/11/05 15.48.36 | 000,000,000 | ---D | C] -- C:\Programmi\PhotoshopPortable
[2011/11/05 15.39.15 | 000,000,000 | ---D | C] -- C:\Programmi\File comuni\Adobe Systems Shared
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/02 13.36.50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\daneelo\Desktop\OTL.exe
[2011/12/02 13.32.41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/12/01 21.39.46 | 000,059,392 | R--- | M] () -- C:\WINDOWS\System32\streamhlp.dll
[2011/12/01 21.22.47 | 000,001,126 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/01 20.03.08 | 004,324,789 | R--- | M] (Swearware) -- C:\Documents and Settings\daneelo\Desktop\ComboFix.exe
[2011/12/01 18.59.59 | 000,002,885 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/01 14.47.42 | 000,023,624 | ---- | M] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2011/12/01 14.47.42 | 000,001,641 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Hitman Pro 3.5.lnk
[2011/11/30 21.10.07 | 000,000,307 | -HS- | M] () -- C:\boot.ini
[2011/11/30 20.36.02 | 000,001,130 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/29 21.40.34 | 000,002,429 | ---- | M] () -- C:\Documents and Settings\daneelo\Desktop\HiJackThis.lnk
[2011/11/29 14.13.13 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\daneelo\Desktop\lol.exe
[2011/11/28 20.17.27 | 000,000,756 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/28 14.30.33 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/11/28 13.59.20 | 000,000,050 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011/11/27 21.46.58 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/27 21.44.07 | 000,001,148 | -H-- | M] () -- C:\Documents and Settings\daneelo\Documenti\Default.rdp
[2011/11/27 20.08.15 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\daneelo\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/23 13.14.01 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/21 21.31.32 | 000,001,783 | ---- | M] () -- C:\Documents and Settings\daneelo\Desktop\The Treasures of Montezuma 3.lnk
[2011/11/09 13.15.34 | 000,636,728 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\daneelo\Desktop\autoruns.exe
[2011/11/08 13.48.58 | 000,004,190 | ---- | M] () -- C:\Documents and Settings\daneelo\Desktop\A Mano Armata.html
[2011/11/06 12.15.12 | 000,000,677 | ---- | M] () -- C:\Documents and Settings\daneelo\Desktop\Nero Express.lnk
[2011/11/06 12.05.11 | 002,588,232 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/05 15.55.45 | 000,000,707 | ---- | M] () -- C:\Documents and Settings\daneelo\Desktop\PhotoshopCS5.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/01 21.39.36 | 000,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2011/12/01 20.06.54 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/12/01 20.06.54 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/12/01 20.06.54 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/12/01 20.06.54 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/12/01 20.06.54 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/12/01 14.47.42 | 000,023,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2011/12/01 14.47.42 | 000,001,641 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Hitman Pro 3.5.lnk
[2011/11/29 14.13.03 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\daneelo\Desktop\lol.exe
[2011/11/28 21.01.40 | 000,002,429 | ---- | C] () -- C:\Documents and Settings\daneelo\Desktop\HiJackThis.lnk
[2011/11/28 20.17.27 | 000,000,756 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/28 13.59.20 | 000,000,050 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2011/11/21 21.31.32 | 000,001,783 | ---- | C] () -- C:\Documents and Settings\daneelo\Desktop\The Treasures of Montezuma 3.lnk
[2011/11/06 12.15.12 | 000,000,677 | ---- | C] () -- C:\Documents and Settings\daneelo\Desktop\Nero Express.lnk
[2011/11/05 15.55.45 | 000,000,707 | ---- | C] () -- C:\Documents and Settings\daneelo\Desktop\PhotoshopCS5.lnk
[2011/11/05 15.41.26 | 000,001,706 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Avvio\Programmi\Adobe Bridge.lnk
[2011/10/30 12.10.04 | 002,130,002 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011/10/13 11.53.25 | 001,689,402 | ---- | C] () -- C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-S-1-5-21-1482476501-1390067357-839522115-1003-0.dat
[2011/10/13 11.53.24 | 000,530,162 | ---- | C] () -- C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\WPFFontCache_v0400-System.dat
[2011/06/20 11.35.19 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2011/01/22 12.30.36 | 000,000,350 | ---- | C] () -- C:\WINDOWS\Vx4SLPlayer.INI
[2010/12/02 01.21.55 | 000,020,682 | ---- | C] () -- C:\Documents and Settings\daneelo\Dati applicazioni\com.koingosw.AlarmClockPro.xml
[2010/10/03 17.52.33 | 000,285,176 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/10/03 17.52.27 | 000,285,176 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/10/03 17.52.27 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/08/11 19.55.13 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/07/10 04.38.00 | 002,195,030 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/03/21 20.32.27 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2010/03/21 20.32.04 | 000,006,211 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2010/03/01 20.09.29 | 000,000,029 | ---- | C] () -- C:\WINDOWS\System32\RfT_R.DAT
[2009/11/14 18.19.50 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\daneelo\Impostazioni locali\Dati applicazioni\fusioncache.dat
[2009/07/13 14.08.09 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/12 19.02.49 | 000,000,669 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2009/05/05 19.22.10 | 000,003,246 | ---- | C] () -- C:\WINDOWS\jsgkxz32.ini
[2009/04/10 16.05.47 | 000,064,000 | ---- | C] () -- C:\WINDOWS\System32\esfw41.bin
[2009/03/13 13.24.18 | 000,000,424 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/02/24 13.31.06 | 000,532,480 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2009/02/23 15.13.12 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\InstMed.exe
[2009/02/23 15.13.03 | 000,009,255 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/02/20 00.53.16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/02/20 00.41.12 | 000,033,792 | ---- | C] () -- C:\Documents and Settings\daneelo\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/19 21.54.09 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/02/19 21.50.52 | 002,588,232 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/19 21.19.23 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/02/19 21.19.16 | 000,027,739 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2009/02/19 21.19.16 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/02/19 21.04.42 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/02/19 20.58.49 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/12/27 15.18.20 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\lwel-manifest.dll
[2008/05/03 04.16.00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/03/01 22.10.20 | 000,000,144 | ---- | C] () -- C:\WINDOWS\Eudcedit.ini
[2008/02/08 17.03.43 | 000,516,096 | ---- | C] () -- C:\WINDOWS\System32\RegisterDialog.dll
[2004/08/19 14.52.50 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/02 13.20.40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2002/10/15 23.54.04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2001/08/31 12.00.00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/31 12.00.00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/31 12.00.00 | 000,552,180 | ---- | C] () -- C:\WINDOWS\System32\perfh010.dat
[2001/08/31 12.00.00 | 000,501,382 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/31 12.00.00 | 000,300,212 | ---- | C] () -- C:\WINDOWS\System32\perfi010.dat
[2001/08/31 12.00.00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/31 12.00.00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/31 12.00.00 | 000,103,538 | ---- | C] () -- C:\WINDOWS\System32\perfc010.dat
[2001/08/31 12.00.00 | 000,087,288 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/31 12.00.00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/31 12.00.00 | 000,034,004 | ---- | C] () -- C:\WINDOWS\System32\perfd010.dat
[2001/08/31 12.00.00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/31 12.00.00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/31 12.00.00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/08/21 11.43.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Alawar Stargaze
[2009/12/13 18.03.47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\AlawarWrapper
[2010/09/19 18.45.46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Alwil Software
[2009/02/20 19.08.40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Azureus
[2011/09/13 12.55.32 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonBJ
[2011/09/13 13.10.29 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonEPP
[2011/09/13 13.10.29 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonIJEPPEX2
[2011/09/13 13.06.21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonIJMSetup
[2011/09/13 12.57.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonIJSetup000
[2011/09/13 13.05.43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\CanonIJWSpt
[2011/05/25 13.04.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Elephant Games
[2009/02/20 01.33.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\FreeDownloadManager.ORG
[2011/10/10 11.36.57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Freemake
[2009/11/16 20.53.03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Hagel Technologies
[2011/12/01 14.47.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Hitman Pro
[2010/09/19 12.50.14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\MAGIX
[2009/10/30 17.40.51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Messenger Plus!
[2011/03/10 17.48.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\MumboJumbo
[2009/05/10 23.38.48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\PaperlessPrinter Data
[2011/06/09 12.48.15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\PlayPond
[2011/11/05 15.50.07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\regid.1986-12.com.adobe
[2010/05/28 13.58.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\SafeNet Sentinel
[2011/08/16 18.41.02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Screentime
[2011/02/11 20.50.29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\SmartSound Software Inc
[2009/03/10 14.47.50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Syncrosoft
[2011/06/08 13.37.44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Top Evidence
[2009/08/12 12.19.25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/09/13 14.04.59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Acoustica
[2011/08/17 11.12.03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Alawar Entertainment
[2011/08/21 11.43.19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Alawar Stargaze
[2011/09/08 19.57.40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Artifex Mundi
[2009/04/24 23.18.34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Artisteer
[2011/06/05 12.27.12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Artogon
[2011/10/10 12.57.12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\avidemux
[2011/03/07 13.40.31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Azureus
[2011/01/08 19.52.35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Big Fish Games
[2011/12/01 18.57.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\BitTorrent
[2011/11/14 18.22.56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\BlamGames
[2009/10/27 20.51.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Blender Foundation
[2011/08/21 12.43.14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Blue Tea Games
[2011/07/13 15.12.22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Boolat Games
[2011/09/13 13.39.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Canon
[2011/09/13 13.19.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\CD-LabelPrint
[2009/05/03 18.12.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\CoSoSys
[2011/03/17 13.00.10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\CursedOnboard
[2011/05/18 18.22.31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\DailyMagic
[2011/10/30 11.57.32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\DieselPuppet
[2011/06/02 12.09.46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\EleFun Games
[2011/02/20 17.22.16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Elephant Games
[2009/04/10 16.18.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\EPSON
[2011/04/09 16.29.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\ERS G-Studio
[2011/10/14 18.36.13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\ERS Game Studios
[2011/11/09 22.06.21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\FileZilla
[2010/09/11 14.47.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\fltk.org
[2011/04/10 13.55.13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Free Download Manager
[2011/11/16 21.27.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Friday's games
[2011/08/21 16.42.58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\GameInvest
[2011/06/20 11.35.19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Ghost Ship Studios
[2011/09/19 12.00.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\gtk-2.0
[2010/12/18 21.21.57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\HdO Adventure
[2011/01/25 20.25.15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\ICQ
[2010/10/18 10.36.16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Icu2
[2011/11/21 21.30.32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\JewelMatch2
[2010/01/11 17.21.29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Leadertech
[2011/06/30 19.09.52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\LestaStudio
[2010/09/19 12.51.20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\MAGIX
[2011/01/12 13.34.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Namco
[2009/03/23 19.20.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Opera
[2010/01/30 20.45.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Orbit
[2011/03/07 13.56.45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Phantasmat_bf_ce1
[2009/12/13 18.05.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Playrix Entertainment
[2011/11/30 12.27.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\QuickScan
[2009/03/09 20.28.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Steinberg
[2010/05/28 18.33.16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\SynthEyes
[2010/07/17 19.50.20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\TeamViewer
[2010/07/11 14.20.41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Thunderbird
[2011/06/08 13.37.44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Top Evidence
[2011/12/01 22.00.30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\TrojanHunter
[2011/07/09 13.14.36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\VampireSagaHL
[2011/09/16 19.38.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Vast Studios
[2011/07/21 11.55.46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\Vogat Interactive
[2010/11/07 15.33.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\daneelo\Dati applicazioni\VoipCheapCom
========== Purity Check ==========
< End of report >
OTL generated this other report labeled "Extras":
OTL Extras logfile created on: 02/12/2011 13.37.41 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\daneelo\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
3,00 Gb Total Physical Memory | 2,48 Gb Available Physical Memory | 82,63% Memory free
7,24 Gb Paging File | 6,94 Gb Available in Paging File | 95,91% Paging File free
Paging file location(s): C:\pagefile.sys 4500 9000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmi
Drive C: | 149,04 Gb Total Space | 39,41 Gb Free Space | 26,44% Space Free | Partition Type: NTFS
Computer Name: PC-CASA | User Name: daneelo | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programmi\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
https [open] -- "C:\Programmi\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programmi\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programmi\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"5900:TCP" = 5900:TCP:*:Enabled:vnc5900
"5800:TCP" = 5800:TCP:*:Enabled:vnc5800
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programmi\ICQ7.2\ICQ.exe" = C:\Programmi\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\Programmi\ICQ7.2\aolload.exe" = C:\Programmi\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programmi\eMule\emule.exe" = C:\Programmi\eMule\emule.exe:*:Enabled:eMule -- (http://www.emule-project.net)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)
"C:\Programmi\Free Download Manager\fdm.exe" = C:\Programmi\Free Download Manager\fdm.exe:*:Enabled:Free Download Manager -- (FreeDownloadManager.ORG)
"C:\Programmi\Mozilla Firefox\firefox.exe" = C:\Programmi\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\WINDOWS\system32\rtcshare.exe" = C:\WINDOWS\system32\rtcshare.exe:*:Enabled:Condivis. App. RTC -- (Microsoft Corporation)
"C:\Programmi\NetMeeting\conf.exe" = C:\Programmi\NetMeeting\conf.exe:*:Disabled:Windows® NetMeeting® -- (Microsoft Corporation)
"C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe" = C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Programmi\Yahoo!\Messenger\YServer.exe" = C:\Programmi\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- (Yahoo! Inc.)
"C:\Programmi\Java\jre6\bin\java.exe" = C:\Programmi\Java\jre6\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programmi\ICQ7.2\ICQ.exe" = C:\Programmi\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\Programmi\ICQ7.2\aolload.exe" = C:\Programmi\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"C:\Documents and Settings\daneelo\Desktop\TeamViewer.Full.5.0.7418\TeamViewer Full 5.0.7418\TeamViewer.exe" = C:\Documents and Settings\daneelo\Desktop\TeamViewer.Full.5.0.7418\TeamViewer Full 5.0.7418\TeamViewer.exe:*:Enabled:TeamViewer -- (TeamViewer GmbH)
"C:\Programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player -- (Veoh Networks)
"C:\Programmi\BitTorrent\BitTorrent.exe" = C:\Programmi\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Programmi\Google\Google Earth\client\googleearth.exe" = C:\Programmi\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
"C:\Programmi\EasyPHP5.3.0\apache\bin\apache.exe" = C:\Programmi\EasyPHP5.3.0\apache\bin\apache.exe:*:Enabled:Apache HTTP Server -- (Apache Software Foundation)
"C:\Programmi\Java\jre6\bin\javaw.exe" = C:\Programmi\Java\jre6\bin\javaw.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programmi\UltraVNC\winvnc.exe" = C:\Programmi\UltraVNC\winvnc.exe:*:Enabled:winvnc.exe -- (UltraVNC)
"C:\Programmi\UltraVNC\vncviewer.exe" = C:\Programmi\UltraVNC\vncviewer.exe:*:Enabled:vncviewer.exe -- (UltraVNC)
"C:\Programmi\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe" = C:\Programmi\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe -- (NVIDIA Corporation)
"C:\Documents and Settings\daneelo\Impostazioni locali\Dati applicazioni\Akamai\netsession_win.exe" = C:\Documents and Settings\daneelo\Impostazioni locali\Dati applicazioni\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Interface -- (Akamai Technologies, Inc)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4800_series" = Canon iP4800 series Printer Driver
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Strumento di caricamento di Windows Live
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{20E5F823-61A4-4BCE-9DF4-5DB43F302B69}" = Diskeeper Professional Premier Edition
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 23
"{2DD388FF-6422-43C9-86A1-C7A99C83E946}" = ASUS nVidia Driver
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32714140-CBC5-3FAF-BFC2-3A7376C3EECF}" = Microsoft .NET Framework 4 Client Profile ITA Language Pack
"{350C9410-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{39AE27EE-A148-48A3-B98D-35498C4D9719}" = Windows Live Messenger
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3d9ac095-e115-4e94-bdef-7f7edf17697d}" = Python 2.6.3
"{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}" = Adobe Setup
"{4344E211-F621-3870-9A08-2F56C71BA0A7}" = Microsoft .NET Framework 4 Extended ITA Language Pack
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F695BCF-9BDC-48AB-8D46-D57CFAD7A248}" = Assistente per l'accesso a Windows Live
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}" = Zune Desktop Theme
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BBB5E4C-3F5E-4C07-BFBE-33B34600783A}" = LogMeIn Hamachi
"{90160410-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel 2003
"{90180410-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint 2003
"{901B0410-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word 2003
"{91A4AD99-69CE-4745-97B7-0E0DFBECFDE5}" = Adobe Illustrator CS
"{928D2FB1-291A-362B-89A4-7075A9D904A4}" = Microsoft Windows SDK for Windows 7 (7.1)
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CEB017E-CC16-4C89-B9E4-AAB5A1DD12F9}" = Windows Live Essentials
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.3
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1040-7B44-A94000000001}" = Adobe Reader 9.4.6 - Italiano
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Pannello di controllo NVIDIA 285.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Driver grafico 285.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.95
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aggiornamenti NVIDIA 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B74D4E10-6884-0000-0000-000000000101}" = Adobe Bridge 1.0
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3C640B8-95B6-40AE-A058-BE4896CD3010}" = Windows Live Call
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Software Logitech QuickCam
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D09605BE-5587-4B0C-86C8-69B5092CB80F}" = Debugging Tools for Windows (x86)
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCA96B5D-02D1-40B2-ABAF-E8ED39754AD3}" = SynthEyes
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_3dcb365ab9e01871fb8c6f27b0ea079" = Adobe After Effects CS4
"Akamai" = Akamai NetSession Interface Service
"ASIO4ALL" = ASIO4ALL
"BitTorrent" = BitTorrent
"Blender" = Blender
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"CCleaner" = CCleaner
"Cool FLAC To MP3 Converter_is1" = Cool FLAC To MP3 Converter 1.0
"DivX Setup.divx.com" = DivX Setup
"dumeter3_is1" = DU Meter
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVDStyler_is1" = DVDStyler v1.8.3 rc 2
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"eMule" = eMule
"EPSON Scanner" = EPSON Scan
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.02
"Exact Audio Copy" = Exact Audio Copy 0.99pb5
"Fass" = Pawsoft Fass
"FileZilla Client" = FileZilla Client 3.2.4
"Firebird SQL Server UK" = Firebird SQL Server - MAGIX Edition
"Free Download Manager_is1" = Free Download Manager 3.0
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"Freemake Video Converter_is1" = Freemake Video Converter versione 2.4.0
"FreePOPs" = NSIS FreePOPs (remove only)
"GlaceVerb_is1" = GlaceVerb 1.01
"HitmanPro35" = Hitman Pro 3.5
"HyperCam 2" = HyperCam 2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Image Grabber II" = Image Grabber II
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Manager Piattaforma
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"Intelligent Shutdown_is1" = Intelligent Shutdown 1.25
"LameACM" = Lame ACM MP3 Codec
"LogMeIn Hamachi" = LogMeIn Hamachi
"MAGIX 3D Maker UK" = MAGIX 3D Maker (embeded)
"MAGIX Movie Edit Pro 16 Plus Download Version UK" = MAGIX Movie Edit Pro 16 Plus Download Version 9.0.1.60 (UK)
"MAGIX Screenshare UK" = MAGIX Screenshare
"MAGIX Speed burnR UK" = MAGIX Speed burnR
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware versione 1.51.2.1300
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Messenger Plus!" = Messenger Plus! 5
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile ITA Language Pack" = Microsoft .NET Framework 4 Client Profile - Language Pack (ITA)
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended ITA Language Pack" = Microsoft .NET Framework 4 Extended - Language Pack (ITA)
"Mozilla Firefox 8.0 (x86 it)" = Mozilla Firefox 8.0 (x86 it)
"Mozilla Thunderbird (8.0)" = Mozilla Thunderbird (8.0)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OJOsoft Total Video Converter_is1" = OJOsoft Total Video Converter
"OpenMG HotFix4.7-07-13-22-01" = OpenMG Limited Patch 4.7-07-14-05-01
"PaperlessPrinter_is1" = PaperlessPrinter version 3.0
"PSPad editor_is1" = PSPad editor
"QcDrv" = Driver di Logitech® Camera
"Redemption Cemetery - Ferris Wheel" = Redemption Cemetery - Ferris Wheel Screen Saver
"Registrazione utente Canon iP4800 series" = Registrazione utente Canon iP4800 series
"SDKSetup_7.1.7600.0.30514" = Microsoft Windows SDK for Windows 7 (7.1)
"Steinberg Cubase SX 1.01" = Steinberg Cubase SX 1.01
"The Treasures of Montezuma 3Final" = The Treasures of Montezuma 3
"Trapcode Particular" = Trapcode Particular
"Ultravnc2_is1" = UltraVnc
"Veoh Web Player Beta" = Veoh Web Player
"VLC media player" = VLC media player 1.1.5
"VobSub" = VobSub v2.23 (Remove Only)
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 28/11/2011 16.08.55 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo HiJackThis.exe, versione 2.0.0.4, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 28/11/2011 16.47.32 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo HiJackThis.exe, versione 2.0.0.4, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 29/11/2011 16.44.21 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo HiJackThis.exe, versione 2.0.0.4, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 29/11/2011 16.49.56 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo wmplayer.exe, versione 11.0.5721.5145, modulo
in stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 30/11/2011 8.49.16 | Computer Name = PC-CASA | Source = Application Error | ID = 1000
Description = Applicazione che ha provocato l'errore procmon.exe, versione 2.96.0.0,
modulo che ha provocato l'errore procmon.exe, versione 2.96.0.0, indirizzo errore
0x0008d231.
Error - 30/11/2011 8.50.36 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo Procmon.exe, versione 2.96.0.0, modulo in stallo
hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 30/11/2011 8.52.29 | Computer Name = PC-CASA | Source = Application Error | ID = 1000
Description = Applicazione che ha provocato l'errore procmon.exe, versione 2.96.0.0,
modulo che ha provocato l'errore procmon.exe, versione 2.96.0.0, indirizzo errore
0x0008d231.
Error - 30/11/2011 9.04.31 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo mmc.exe, versione 5.1.2600.2180, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 30/11/2011 15.09.51 | Computer Name = PC-CASA | Source = Application Error | ID = 1000
Description = Applicazione che ha provocato l'errore procmon.exe, versione 2.96.0.0,
modulo che ha provocato l'errore procmon.exe, versione 2.96.0.0, indirizzo errore
0x0008d231.
Error - 30/11/2011 15.10.57 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo Procmon.exe, versione 2.96.0.0, modulo in stallo
hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
[ Application Events ]
Error - 28/11/2011 16.08.55 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo HiJackThis.exe, versione 2.0.0.4, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 28/11/2011 16.47.32 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo HiJackThis.exe, versione 2.0.0.4, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 29/11/2011 16.44.21 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo HiJackThis.exe, versione 2.0.0.4, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 29/11/2011 16.49.56 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo wmplayer.exe, versione 11.0.5721.5145, modulo
in stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 30/11/2011 8.49.16 | Computer Name = PC-CASA | Source = Application Error | ID = 1000
Description = Applicazione che ha provocato l'errore procmon.exe, versione 2.96.0.0,
modulo che ha provocato l'errore procmon.exe, versione 2.96.0.0, indirizzo errore
0x0008d231.
Error - 30/11/2011 8.50.36 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo Procmon.exe, versione 2.96.0.0, modulo in stallo
hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 30/11/2011 8.52.29 | Computer Name = PC-CASA | Source = Application Error | ID = 1000
Description = Applicazione che ha provocato l'errore procmon.exe, versione 2.96.0.0,
modulo che ha provocato l'errore procmon.exe, versione 2.96.0.0, indirizzo errore
0x0008d231.
Error - 30/11/2011 9.04.31 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo mmc.exe, versione 5.1.2600.2180, modulo in
stallo hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
Error - 30/11/2011 15.09.51 | Computer Name = PC-CASA | Source = Application Error | ID = 1000
Description = Applicazione che ha provocato l'errore procmon.exe, versione 2.96.0.0,
modulo che ha provocato l'errore procmon.exe, versione 2.96.0.0, indirizzo errore
0x0008d231.
Error - 30/11/2011 15.10.57 | Computer Name = PC-CASA | Source = Application Hang | ID = 1002
Description = Applicazione in stallo Procmon.exe, versione 2.96.0.0, modulo in stallo
hungapp, versione 0.0.0.0, indirizzo stallo 0x00000000.
[ System Events ]
Error - 01/12/2011 16.32.11 | Computer Name = PC-CASA | Source = Service Control Manager | ID = 7026
Description = All'avvio non è stato possibile caricare i seguenti driver: EIO_XP
Fips
intelppm
Lbd
sptd
Error - 01/12/2011 16.40.19 | Computer Name = PC-CASA | Source = DCOM | ID = 10005
Description = DCOM ha ricevuto l'errore "%1084" durante il tentativo di avviare
il servizio StiSvc con gli argomenti "" per eseguire il server {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 01/12/2011 17.01.01 | Computer Name = PC-CASA | Source = DCOM | ID = 10005
Description = DCOM ha ricevuto l'errore "%1084" durante il tentativo di avviare
il servizio StiSvc con gli argomenti "" per eseguire il server {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 01/12/2011 17.01.02 | Computer Name = PC-CASA | Source = DCOM | ID = 10005
Description = DCOM ha ricevuto l'errore "%1084" durante il tentativo di avviare
il servizio StiSvc con gli argomenti "" per eseguire il server {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 01/12/2011 17.05.17 | Computer Name = PC-CASA | Source = DCOM | ID = 10005
Description = DCOM ha ricevuto l'errore "%1084" durante il tentativo di avviare
il servizio EventSystem con gli argomenti "" per eseguire il server {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 02/12/2011 8.32.53 | Computer Name = PC-CASA | Source = sptd | ID = 262148
Description = Il driver ha rilevato un errore interno nelle strutture dati per .
Error - 02/12/2011 8.33.02 | Computer Name = PC-CASA | Source = SRService | ID = 104
Description = Processo di inizializzazione di Ripristino configurazione di sistema
non riuscito.
Error - 02/12/2011 8.33.20 | Computer Name = PC-CASA | Source = DCOM | ID = 10005
Description = DCOM ha ricevuto l'errore "%1084" durante il tentativo di avviare
il servizio EventSystem con gli argomenti "" per eseguire il server {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 02/12/2011 8.34.21 | Computer Name = PC-CASA | Source = Service Control Manager | ID = 7023
Description = Servizio Servizio Ripristino configurazione di sistema terminato con
l'errore: %%2
Error - 02/12/2011 8.34.21 | Computer Name = PC-CASA | Source = Service Control Manager | ID = 7026
Description = All'avvio non è stato possibile caricare i seguenti driver: EIO_XP
Fips
intelppm
Lbd
sptd
< End of report >
I sincerely hope i explained my problem clearly, and i want to thank in advance who will give me help....