Un po' in ritardo ma ho fatto......
Primo log: Avenger txt:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.comPlatform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" deleted successfully.
File "C:\WINDOWS\System32\drivers\aswSnx.sys" deleted successfully.
File "C:\WINDOWS\System32\drivers\aswSP.sys" deleted successfully.
File "C:\WINDOWS\System32\drivers\aswRdr.sys" deleted successfully.
File "C:\WINDOWS\System32\drivers\aswTdi.sys" deleted successfully.
File "C:\WINDOWS\System32\drivers\aswmon2.sys" deleted successfully.
File "C:\WINDOWS\System32\drivers\aavmker4.sys" deleted successfully.
File "C:\WINDOWS\System32\aswBoot.exe" deleted successfully.
Folder "C:\Documents and Settings\All Users\Application Data\AVAST Software" deleted successfully.
Folder "C:\Program Files\AVAST Software\Avast" deleted successfully.
Folder "C:\Program Files\AVAST Software" deleted successfully.
Error: folder "C:\Program Files\SweetIM" not found!
Deletion of folder "C:\Program Files\SweetIM" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Folder "C:\Program Files\PC Tools Security" deleted successfully.
Folder "C:\Program Files\Common Files\PC Tools" deleted successfully.
Folder "C:\Documents and Settings\All Users\Application Data\PC Tools" deleted successfully.
Folder "C:\Documents and Settings\Administrator\Application Data\Ysru" deleted successfully.
Completed script processing.
*******************
Finished! Terminate
Ecco il log di OTL
OTL logfile created on: 01/03/2012 19.18.53 - Run 2
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000410 | Country: Italy | Language: ITA | Date Format: dd/MM/yyyy
1,99 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 79,50% Memory free
3,84 Gb Paging File | 3,62 Gb Available in Paging File | 94,38% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97,65 Gb Total Space | 34,74 Gb Free Space | 35,58% Space Free | Partition Type: NTFS
Drive D: | 185,55 Gb Total Space | 185,25 Gb Free Space | 99,84% Space Free | Partition Type: NTFS
Drive E: | 182,55 Gb Total Space | 176,63 Gb Free Space | 96,76% Space Free | Partition Type: NTFS
Computer Name: 2F624F151C58483 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\dgdersvc.exe (Devguru Co., Ltd.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - C:\WINDOWS\system32\UAService7.exe ()
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe ()
PRC - C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe ()
========== Modules (No Company Name) ========== MOD - C:\WINDOWS\system32\UAService7.exe ()
MOD - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.ITA ()
MOD - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
MOD - C:\Program Files\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe ()
MOD - C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe ()
========== Win32 Services (SafeList) ========== SRV - (Sony Ericsson PCCompanion) -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe (Avanquest Software)
SRV - (dgdersvc) -- C:\WINDOWS\system32\dgdersvc.exe (Devguru Co., Ltd.)
SRV - (FsUsbExService) -- C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (UserAccess7) SecuROM User Access Service (V7) -- C:\WINDOWS\system32\UAService7.exe ()
SRV - (ACDaemon) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NMSAccessU) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Network WanMiniport First Position) -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe ()
========== Driver Services (SafeList) ========== DRV - (dgderdrv) -- C:\WINDOWS\system32\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV - (FsUsbExDisk) -- C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (sscemdm) -- C:\WINDOWS\system32\drivers\sscemdm.sys (MCCI Corporation)
DRV - (sscebus) SAMSUNG USB Composite Device V2 driver (WDM) -- C:\WINDOWS\system32\drivers\sscebus.sys (MCCI Corporation)
DRV - (sscemdfl) -- C:\WINDOWS\system32\drivers\sscemdfl.sys (MCCI Corporation)
DRV - (RTL8187B) -- C:\WINDOWS\system32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (seehcri) -- C:\WINDOWS\system32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (ggsemc) -- C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) -- C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (USBModem) -- C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) -- C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) -- C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (jrdusbser) -- C:\WINDOWS\system32\drivers\jrdusbser.sys (TCT International Mobile Ltd)
DRV - (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM) -- C:\WINDOWS\system32\drivers\s0016unic.sys (MCCI Corporation)
DRV - (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS) -- C:\WINDOWS\system32\drivers\s0016nd5.sys (MCCI Corporation)
DRV - (s0016mdfl) -- C:\WINDOWS\system32\drivers\s0016mdfl.sys (MCCI Corporation)
DRV - (s0016mdm) -- C:\WINDOWS\system32\drivers\s0016mdm.sys (MCCI Corporation)
DRV - (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM) -- C:\WINDOWS\system32\drivers\s0016mgmt.sys (MCCI Corporation)
DRV - (s0016obex) -- C:\WINDOWS\system32\drivers\s0016obex.sys (MCCI Corporation)
DRV - (s0016bus) Sony Ericsson Device 0016 driver (WDM) -- C:\WINDOWS\system32\drivers\s0016bus.sys (MCCI Corporation)
DRV - (WIBUKEY) -- C:\WINDOWS\system32\drivers\WibuKey.sys (WIBU-SYSTEMS AG)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (Aspi32) -- C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://home.sweetim.com/?barid={61E0045C-A43B-45EF-9714-A01E78F66DF6}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-823518204-436374069-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-823518204-436374069-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-823518204-436374069-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/IE - HKU\S-1-5-21-823518204-436374069-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://it.msn.com/?ocid=iehpIE - HKU\S-1-5-21-823518204-436374069-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = it
IE - HKU\S-1-5-21-823518204-436374069-839522115-500\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\InprocServer32 File not found
IE - HKU\S-1-5-21-823518204-436374069-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-823518204-436374069-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1
========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm IT Customized Web Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com/?barid={61E0045C-A43B-45EF-9714-A01E78F66DF6}"
FF - prefs.js..browser.startup.homepage: "http://it.ask.com/?l=dis&o=APN10023&gct=hp"
FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ZoneAlarm IT Customized Web Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3045718&SearchSource=3&q={searchTerms}"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@research.microsoft.com/HDView: C:\Program Files\Microsoft Research\HD View\nphdview.dll (Microsoft Research)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\PROGRA~1\AVASTS~1\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/08 11.22.08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{1266764D-FC4F-4FA7-B63B-884D53B1680F}: C:\Documents and Settings\Administrator\Application Data\NetAssistant\ [2011/05/18 17.23.56 | 000,000,000 | ---D | M]
[2010/12/11 10.03.38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2012/02/22 18.38.04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jxxl2anu.default\extensions
[2011/09/18 12.03.43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jxxl2anu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/17 19.23.22 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jxxl2anu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/23 19.40.47 | 000,000,000 | ---D | M] (Microsoft Choice Guard) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jxxl2anu.default\extensions\ChoiceGuard@Microsoft
[2011/09/06 11.37.02 | 000,001,819 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jxxl2anu.default\searchplugins\bing.xml
[2011/10/24 11.15.40 | 000,000,927 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jxxl2anu.default\searchplugins\conduit.xml
[2012/02/22 18.38.13 | 000,003,974 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jxxl2anu.default\searchplugins\sweetim.xml
[2011/10/08 11.22.07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\PROGRA~1\AVASTS~1\AVAST\WEBREP\FF
[2011/09/29 08.23.42 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/09/29 02.19.35 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/29 02.59.20 | 000,000,744 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-it.xml
[2011/09/29 02.59.20 | 000,000,825 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\hoepli.xml
[2011/09/29 02.59.20 | 000,001,182 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-it.xml
[2011/09/29 02.59.20 | 000,000,953 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-it.xml
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Zylom Plugin (Enabled) = C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: npFFApi (Enabled) = C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
CHR - plugin: DNA Plug-in (Enabled) = C:\Program Files\DNA\plugins\npbtdna.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: HD View (Enabled) = C:\Program Files\Microsoft Research\HD View\nphdview.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: avast! WebRep = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1367_0\
CHR - Extension: Gmail = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/02/29 13.42.45 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O4 - HKLM..\Run: [ISW] File not found
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-823518204-436374069-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-823518204-436374069-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1658440-DDF2-4877-B55E-97CBB8BA52A5}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/17 07.53.37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 60 Days ========== [2012/03/01 18.57.51 | 000,324,880 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Administrator\Desktop\aswclear.exe
[2012/03/01 13.52.45 | 000,000,000 | ---D | C] -- C:\Avenger
[2012/03/01 13.50.03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\avenger
[2012/02/29 13.56.45 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/02/29 13.56.45 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/02/29 13.56.45 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/02/29 13.56.45 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/02/29 13.56.27 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012/02/29 13.56.08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/29 13.55.15 | 004,422,703 | R--- | C] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2012/02/29 13.38.59 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/02/29 13.36.51 | 000,583,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/02/26 19.09.54 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/02/26 19.07.58 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2012/02/26 18.11.25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\HostsXpert
[2012/02/25 17.27.46 | 005,046,944 | ---- | C] (Check Point Software Technologies LTD) -- C:\Documents and Settings\Administrator\Desktop\clean.exe
[2012/02/23 09.43.21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Recent
[2012/02/22 18.42.31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2012/02/22 18.42.09 | 000,939,368 | ---- | C] (Macromedia, Inc.) -- C:\WINDOWS\System32\flash.ocx
[2012/02/22 12.16.52 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012/02/22 12.14.25 | 000,000,000 | ---D | C] -- C:\Program Files\WindowsUpdate
[2012/02/22 12.14.25 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2012/02/19 18.17.21 | 000,000,000 | ---D | C] -- C:\ccleaner
[2012/02/19 11.15.05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\HiJackThis
[2012/02/19 11.15.04 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2012/02/18 10.40.26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2012/02/18 10.39.46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/18 10.39.41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/02/18 10.39.33 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/02/18 10.39.32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/02/17 19.25.45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/02/17 19.10.44 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012/02/15 10.00.34 | 000,632,320 | ---- | C] (HDE) -- C:\Documents and Settings\Administrator\Desktop\HardDriveEraser2.0.exe
[2012/01/26 13.56.02 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2012/01/26 13.56.02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2012/01/11 16.07.12 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winmm.dll
[2012/01/11 16.07.12 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mciseq.dll
[2012/01/11 16.07.08 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\packager.exe
========== Files - Modified Within 60 Days ========== [2012/03/01 19.11.42 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/01 19.11.42 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\Final Media Player Update Checker.job
[2012/03/01 19.10.28 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/01 19.10.27 | 2137,509,888 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/01 19.07.13 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/03/01 18.57.51 | 000,324,880 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Administrator\Desktop\aswclear.exe
[2012/03/01 13.56.26 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/01 13.49.28 | 000,724,952 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\avenger.zip
[2012/02/29 15.02.12 | 087,765,048 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\avira_free_antivirus_it.exe
[2012/02/29 13.55.36 | 004,422,703 | R--- | M] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2012/02/29 13.42.45 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2012/02/29 13.36.51 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/02/29 13.33.37 | 001,438,944 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/29 09.29.58 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/26 18.10.53 | 000,357,766 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\HostsXpert.zip
[2012/02/25 17.27.46 | 005,046,944 | ---- | M] (Check Point Software Technologies LTD) -- C:\Documents and Settings\Administrator\Desktop\clean.exe
[2012/02/23 16.58.07 | 000,000,210 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to Canon MP495 series Printer.lnk
[2012/02/22 20.07.39 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/02/22 12.16.11 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/02/22 12.16.11 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/02/21 17.12.41 | 000,002,463 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2012/02/19 18.17.47 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012/02/18 10.39.48 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/17 19.21.51 | 000,512,992 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\PCTools_Safe_Install.exe
[2012/02/15 14.52.29 | 000,441,420 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120215-145308.backup
[2012/02/15 10.00.38 | 000,632,320 | ---- | M] (HDE) -- C:\Documents and Settings\Administrator\Desktop\HardDriveEraser2.0.exe
[2012/02/12 11.08.36 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/02/12 11.08.36 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/01/12 17.53.24 | 001,859,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys
[2012/01/12 17.53.24 | 001,859,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
[2012/01/11 20.06.47 | 000,003,072 | ---- | M] () -- C:\WINDOWS\System32\iacenc.dll
[2012/01/11 20.06.47 | 000,003,072 | ---- | M] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/01/11 08.07.44 | 000,441,696 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/11 08.07.43 | 000,071,632 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
========== Files Created - No Company Name ========== [2012/03/01 19.10.27 | 2137,509,888 | -HS- | C] () -- C:\hiberfil.sys
[2012/03/01 13.49.25 | 000,724,952 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\avenger.zip
[2012/02/29 15.01.30 | 087,765,048 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\avira_free_antivirus_it.exe
[2012/02/29 13.56.45 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/29 13.56.45 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/29 13.56.45 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/29 13.56.45 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/29 13.56.45 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/26 18.10.50 | 000,357,766 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\HostsXpert.zip
[2012/02/23 16.58.07 | 000,000,210 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to Canon MP495 series Printer.lnk
[2012/02/22 18.27.05 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/22 18.27.05 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/21 18.56.37 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012/02/19 11.15.05 | 000,002,463 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2012/02/18 10.39.48 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/17 19.22.36 | 000,512,992 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\PCTools_Safe_Install.exe
[2012/02/15 08.37.44 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012/01/11 16.07.17 | 000,386,048 | ---- | C] () -- C:\WINDOWS\System32\dllcache\qdvd.dll
[2011/12/01 09.26.34 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2011/12/01 09.26.34 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2011/11/26 15.37.43 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Filter
[2011/11/26 15.36.18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\PageLibraries
[2011/11/25 19.39.31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLbx.DAT
[2011/11/25 19.32.06 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Frameworks
[2011/11/25 19.32.06 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Generic
[2011/09/14 17.43.31 | 000,307,200 | ---- | C] () -- C:\WINDOWS\System32\AscSQLite.dll
[2011/03/01 09.54.47 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2010/12/19 18.25.21 | 000,000,406 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\quifoto.it_state.xml
[2010/12/11 10.03.08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/11/22 16.47.52 | 000,012,972 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/08/24 11.14.04 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/08/24 11.14.04 | 000,036,640 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/08/24 11.13.48 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2010/08/21 09.14.44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI
[2010/08/21 09.08.47 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Graphics
[2010/08/21 09.08.47 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Grapher
[2010/08/21 09.08.47 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Grand Piano
[2010/08/21 09.08.47 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Gems
[2010/08/21 09.08.47 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Galaxy Swirl
[2010/08/21 09.08.47 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Galactic Static
[2010/08/21 09.08.47 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2010/08/21 09.08.47 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2010/08/21 09.08.47 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2010/08/21 09.08.47 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Hybrid Morph
[2010/08/21 09.08.47 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Hybrid Basic
[2010/08/21 09.08.47 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Horn Section
[2010/07/30 10.54.29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX.INI
[2010/07/26 14.18.38 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2010/07/26 14.18.38 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2010/07/26 14.18.38 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2010/07/26 14.18.38 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010/07/23 10.24.48 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Funk Animals
[2010/07/23 10.24.48 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Fonts
[2010/07/23 10.24.48 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
[2010/07/23 10.24.48 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Guides
[2010/05/20 15.44.07 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\wintab32.dll
[2010/05/18 12.32.05 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\UAService7.exe
[2010/05/08 18.53.31 | 000,057,552 | ---- | C] () -- C:\WINDOWS\System32\WkDos.exe
========== LOP Check ========== [2009/07/27 12.38.50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Activision
[2012/02/23 17.27.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\BitTorrent
[2009/05/17 15.12.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Canneverbe_Limited
[2012/01/18 14.25.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Canon
[2011/05/08 11.12.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Canon Easy-WebPrint EX
[2010/07/02 19.02.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\CheckPoint
[2010/09/10 16.36.56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\CMW
[2012/02/19 17.49.35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\DNA
[2010/08/04 18.54.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\eTeks
[2011/05/19 13.03.19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\FinalMediaPlayer
[2011/08/27 17.57.57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\go
[2010/08/15 15.20.58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Graphisoft
[2010/07/25 11.26.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\gtk-2.0
[2010/07/08 17.06.10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Leadertech
[2009/09/01 16.13.41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\LG Electronics
[2010/12/28 09.34.45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\MSNInstaller
[2011/05/18 17.23.56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\NetAssistant
[2010/08/21 09.13.21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Nikon
[2010/05/20 15.47.12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\progeSOFT
[2010/11/22 16.41.45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\quifoto.it.AD8D60F8E4A090C6E6ED2EA5F019293CE7B5FB4D.1
[2010/08/24 11.13.13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Samsung
[2011/10/26 18.13.31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Vopa
[2010/04/11 11.28.23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\widestream
[2010/05/25 19.07.53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Zylom
[2010/02/11 19.13.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/05/08 11.07.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/05/08 11.16.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonEPP
[2011/09/11 17.56.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011/05/08 11.16.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX2
[2011/05/08 11.12.07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJMSetup
[2011/05/23 18.39.48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/05/08 11.10.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJWSpt
[2012/02/25 17.26.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CheckPoint
[2011/11/23 12.02.08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/29 13.50.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easy Driver Pro
[2011/06/19 18.45.22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easybits GO
[2011/11/25 19.39.31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2010/09/19 14.50.15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2011/10/26 18.22.04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/11/27 19.41.02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/05/25 19.08.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2011/11/25 19.23.41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2010/08/24 11.14.08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2012/02/19 16.50.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/11/23 18.52.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TmForever
[2010/08/21 09.08.47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/11/13 13.19.53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZA_PreservedFiles
[2010/05/25 19.07.45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
[2011/09/16 13.14.09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/03/21 12.38.21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/02/23 09.16.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2009/06/20 16.26.57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2012/03/01 19.11.42 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\Final Media Player Update Checker.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Spero di aver fatto tutto bene!
ma perchè è così lento ad avviarsi?
Problemi di età?????!!!!!:-)))
Buona serata!