ecco il log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-04-2014
Ran by Administrator (administrator) on USER on 25-04-2014 00:38:45
Running from C:\Documents and Settings\Administrator\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Italian Standard
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/==================== Processes (Whitelisted) =================
(Sandboxie Holdings, LLC) C:\Programmi\Sandboxie\SbieSvc.exe
(Ahead Software AG) C:\Programmi\Ahead\InCD\InCDsrv.exe
(AVAST Software) C:\Programmi\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\WINDOWS\System32\SCardSvr.exe
(AVAST Software) C:\Programmi\AVAST Software\Avast\AvastUI.exe
(PeerBlock, LLC) C:\Programmi\PeerBlock\peerblock.exe
(Microsoft Corporation) C:\Programmi\Messenger\msmsgs.exe
(Sandboxie Holdings, LLC) C:\Programmi\Sandboxie\SbieCtrl.exe
(Oracle Corporation) C:\Programmi\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AvastUI.exe] => C:\Programmi\AVAST Software\Avast\AvastUI.exe [3873704 2014-04-21] (AVAST Software)
HKU\.DEFAULT\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000
HKU\S-1-5-21-1801674531-515967899-725345543-500\...\Run: [PowerBar] => [X]
HKU\S-1-5-21-1801674531-515967899-725345543-500\...\Run: [PeerBlock] => C:\Programmi\PeerBlock\peerblock.exe [2122824 2014-01-14] (PeerBlock, LLC)
HKU\S-1-5-21-1801674531-515967899-725345543-500\...\Run: [MSMSGS] => C:\Programmi\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-1801674531-515967899-725345543-500\...\Run: [SandboxieControl] => C:\Programmi\Sandboxie\SbieCtrl.exe [543432 2014-01-17] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-1801674531-515967899-725345543-500\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000
==================== Internet (Whitelisted) ====================
ProxyServer: http
ftp
https
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.virgilio.it/HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchHKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmi\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Indirizzo - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - Co&llegamenti - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {D821DC4A-0814-435E-9820-661C543A4679}
http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocxDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabHandler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmi\File comuni\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
ShellExecuteHooks: Hook per l'esecuzione degli URL - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [8492032 2012-06-08] (Microsoft Corporation)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @checkpoint.com/FFApi - C:\Programmi\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll No File
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Programmi\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Programmi\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Extension: FT Downloader - C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi [2013-06-26]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (Docs) - C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-01]
CHR Extension: (Google Drive) - C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-01]
CHR Extension: (YouTube) - C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-01]
CHR Extension: (Ricerca Google) - C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-01]
CHR Extension: (Gmail) - C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-01]
CHR HKLM\...\Chrome\Extension: [lgnbhdnimikkoodkogjlcllngimhlapp] - C:\Programmi\FTDownloader.com\FTDownloader10.crx [2013-06-01]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Programmi\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-21] (AVAST Software)
S3 IDriverT; C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation)
R2 InCDsrv; C:\Programmi\Ahead\InCD\InCDsrv.exe [1151090 2004-09-07] (Ahead Software AG)
R2 JavaQuickStarterService; C:\Programmi\Java\jre7\bin\jqs.exe [182696 2013-12-18] (Oracle Corporation)
R2 MDM; C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE [322120 2003-06-19] (Microsoft Corporation)
S3 ose; C:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE [89136 2003-07-28] (Microsoft Corporation)
R2 SbieSvc; C:\Programmi\Sandboxie\SbieSvc.exe [131272 2014-01-17] (Sandboxie Holdings, LLC)
S3 WMPNetworkSvc; C:\Programmi\Windows Media Player\WMPNetwk.exe [918528 2006-11-02] (Microsoft Corporation)
S3 gusvc; "C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe" [X]
==================== Drivers (Whitelisted) ====================
S3 ACSSCR; C:\WINDOWS\System32\DRIVERS\a38usbxp.sys [24832 2004-04-30] (Advanced Card Systems Ltd)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-04-21] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-04-21] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [54832 2014-04-21] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-04-21] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [776976 2014-04-21] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [411552 2014-04-21] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57672 2014-04-21] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [180632 2014-04-21] ()
S3 Cardex; C:\WINDOWS\system32\drivers\TBPANEL.SYS [5306 2002-07-27] (Windows (R) 2000 DDK provider)
S3 CardReaderFilter; C:\WINDOWS\system32\Drivers\USBCRFT.SYS [17408 2012-03-25] (ICSI Technology Ltd.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 FETND5BV; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [43008 2006-03-15] (VIA Technologies, Inc. )
S3 FETNDIS; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. )
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
R0 Imagedrv; C:\WINDOWS\System32\DRIVERS\imagedrv.sys [89184 2003-03-29] (Ahead Software AG and its licensors)
R4 InCDfs; C:\WINDOWS\system32\Drivers\InCDfs.sys [91136 2004-09-07] (Ahead Software AG)
R1 InCDPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys [28544 2004-09-07] (Ahead Software AG)
U1 InCDrec; C:\WINDOWS\system32\Drivers\InCDrec.sys [5760 2004-09-07] (Ahead Software AG)
R3 irsir; C:\WINDOWS\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation)
R3 MarvinBus; C:\WINDOWS\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH)
R3 ms_mpu401; C:\WINDOWS\System32\drivers\msmpu401.sys [2944 2001-08-18] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 pbfilter; C:\Programmi\PeerBlock\pbfilter.sys [19016 2014-01-14] ()
R3 pfc; C:\WINDOWS\System32\drivers\pfc.sys [10368 2003-12-05] (Padus, Inc.)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 SbieDrv; C:\Programmi\Sandboxie\SbieDrv.sys [161888 2014-01-17] (Sandboxie Holdings, LLC)
R2 TBPanel; C:\WINDOWS\system32\Drivers\TBPanel.sys [5306 2002-07-27] (Windows (R) 2000 DDK provider)
R3 ttp9; C:\WINDOWS\System32\drivers\ttp9.sys [52224 2003-02-10] (TerraTec Electronic GmbH)
S3 usb_rndis; C:\WINDOWS\System32\DRIVERS\usb8023.sys [12928 2013-02-12] (Microsoft Corporation)
R0 videX32; C:\WINDOWS\System32\DRIVERS\videX32.sys [9728 2006-02-23] (VIA Technologies, Inc.)
R0 xfilt; C:\WINDOWS\System32\DRIVERS\xfilt.sys [11264 2006-02-23] (VIA Technologies,Inc)
U4 dwshd; \SystemRoot\System32\drivers\dwshd.sys [X]
S4 IntelIde; No ImagePath
S2 nvcap; system32\DRIVERS\nvcap.sys [X]
S2 NVXBAR; system32\DRIVERS\NVxbar.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-25 00:35 - 2014-04-25 00:38 - 00011991 _____ () C:\Documents and Settings\Administrator\Desktop\FRST.txt
2014-04-25 00:05 - 2014-04-25 00:38 - 00000000 ____D () C:\FRST
2014-04-25 00:04 - 2014-04-25 00:04 - 01048576 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\FRST.exe
2014-04-24 18:47 - 2014-04-24 18:47 - 00079444 _____ () C:\Documents and Settings\Administrator\Documenti\usbdeview.zip
2014-04-24 18:45 - 2013-09-03 11:53 - 00008322 _____ () C:\Documents and Settings\Administrator\Desktop\USBDeview_lng.ini
2014-04-24 18:44 - 2014-04-24 18:44 - 00003215 _____ () C:\Documents and Settings\Administrator\Documenti\usbdeview_italian.zip
2014-04-24 15:18 - 2014-04-24 15:39 - 653006972 _____ () C:\Documents and Settings\Administrator\Documenti\Artista Sconosciuto - Titolo Sconosciuto.wav
2014-04-24 15:18 - 2014-04-24 15:18 - 00001495 _____ () C:\Documents and Settings\Administrator\Documenti\Artista Sconosciuto - Titolo Sconosciuto.cue
2014-04-24 12:53 - 2014-04-24 12:53 - 00090112 _____ () C:\WINDOWS\Minidump\Mini042414-01.dmp
2014-04-21 15:51 - 2014-04-21 15:51 - 00000162 ____H () C:\Documents and Settings\Administrator\Desktop\~$051.part
2014-04-21 12:33 - 2014-04-25 00:39 - 00000370 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-04-21 12:33 - 2014-04-21 12:33 - 00001697 _____ () C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2014-04-21 12:33 - 2014-04-21 12:33 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Avvio\Programmi\Avast
2014-04-21 12:33 - 2014-04-21 12:33 - 00000000 ____D () C:\Documents and Settings\Administrator\Dati applicazioni\AVAST Software
2014-04-21 12:32 - 2014-04-21 12:32 - 00776976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00411552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00271264 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-04-21 12:32 - 2014-04-21 12:32 - 00180632 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00057672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00054832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-04-21 12:32 - 2014-04-21 12:32 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00000000 ____D () C:\Programmi\AVAST Software
2014-04-13 18:18 - 2014-04-13 18:18 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\Start MAC.app
2014-04-13 18:18 - 2014-04-13 18:18 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\PC
2014-04-13 18:17 - 2014-04-13 18:18 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\MAC
2014-04-13 18:17 - 2010-10-14 12:59 - 00139264 _____ (Verbatim) C:\Documents and Settings\Administrator\Desktop\Start PC.exe
2014-04-13 17:49 - 2014-04-13 17:49 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB958644$
2014-04-13 17:49 - 2014-04-13 17:49 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB957097$
2014-04-13 17:49 - 2014-04-13 17:49 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB957095$
2014-04-13 17:49 - 2014-04-13 17:49 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956841$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956803$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956802$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB955069$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB954600$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB954211$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB952954$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB952287$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951748$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951698$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951376-v2$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951376$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951066$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB950974$
2014-04-13 17:46 - 2014-04-13 17:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB950762$
2014-04-13 17:46 - 2014-04-13 17:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB946648$
2014-04-13 17:46 - 2014-04-13 17:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB938464$
2014-04-13 09:07 - 2011-07-13 04:55 - 02237440 ____R (OldTimer Tools) C:\OTLPE.exe
2014-04-13 09:06 - 2014-04-13 09:06 - 00000000 ____D () C:\_OTL
2014-04-13 08:42 - 2014-04-13 22:52 - 00065122 _____ () C:\OTL.Txt
2014-04-13 03:18 - 2014-04-13 03:21 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-13 03:18 - 2014-04-13 03:18 - 00000749 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-13 03:18 - 2014-04-13 03:18 - 00000000 ____D () C:\Programmi\Malwarebytes Anti-Malware
2014-04-13 03:18 - 2014-04-13 03:18 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes Anti-Malware
2014-04-13 03:18 - 2014-04-03 09:51 - 00050648 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-12 20:54 - 2014-04-13 09:07 - 00000000 ____D () C:\Documents and Settings\All Users\Dati applicazioni\2992199F9A
2014-04-10 00:31 - 2014-04-10 00:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-04-06 22:58 - 2014-04-06 22:58 - 00000698 _____ () C:\Documents and Settings\Administrator\Desktop\Collegamento a DVD Shrink 3.2.lnk
2014-04-05 17:55 - 2014-04-06 00:38 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\Nuova cartella
2014-04-01 23:53 - 2014-04-01 23:53 - 00000000 ____D () C:\Documents and Settings\All Users\Dati applicazioni\vsosdk
2014-04-01 23:35 - 2014-04-01 23:35 - 00000642 _____ () C:\Documents and Settings\Administrator\Desktop\Collegamento a DVDFab.lnk
2014-04-01 23:32 - 2014-04-24 14:13 - 00000000 ____D () C:\Documents and Settings\Administrator\Dati applicazioni\Vso
2014-04-01 23:32 - 2014-04-02 00:03 - 00000000 ____D () C:\Programmi\DVDFab 5
2014-04-01 23:32 - 2014-04-01 23:36 - 00000000 ____D () C:\Documents and Settings\Administrator\Documenti\DVDFab
2014-04-01 23:32 - 2014-04-01 23:32 - 00087608 _____ () C:\Documents and Settings\Administrator\Dati applicazioni\inst.exe
2014-04-01 23:32 - 2014-04-01 23:32 - 00047360 _____ (VSO Software) C:\WINDOWS\system32\Drivers\pcouffin.sys
2014-04-01 23:32 - 2014-04-01 23:32 - 00047360 _____ (VSO Software) C:\Documents and Settings\Administrator\Dati applicazioni\pcouffin.sys
2014-04-01 23:32 - 2014-04-01 23:32 - 00007887 _____ () C:\Documents and Settings\Administrator\Dati applicazioni\pcouffin.cat
2014-04-01 23:32 - 2014-04-01 23:32 - 00000034 _____ () C:\Documents and Settings\Administrator\Dati applicazioni\pcouffin.log
2014-04-01 23:30 - 2014-04-01 23:30 - 00000000 ___RD () C:\Sandbox
2014-04-01 23:18 - 2014-04-14 20:26 - 00001318 _____ () C:\WINDOWS\Sandboxie.ini
2014-04-01 23:18 - 2014-04-01 23:18 - 00000756 _____ () C:\Documents and Settings\Administrator\Desktop\Browser Web nell'area virtuale.lnk
2014-04-01 23:18 - 2014-04-01 23:18 - 00000000 ____D () C:\Programmi\Sandboxie
2014-04-01 23:18 - 2014-04-01 23:18 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Avvio\Programmi\Sandboxie
2014-04-01 23:08 - 2014-04-24 14:59 - 00000000 ____D () C:\Documents and Settings\All Users\Dati applicazioni\DVD Shrink
2014-04-01 23:08 - 2014-04-01 23:08 - 00000000 ____D () C:\Programmi\DVD Shrink
2014-04-01 23:04 - 2014-04-01 23:04 - 00004190 _____ () C:\Documents and Settings\Administrator\Desktop\Nmc_2014-04-01_23-04-16.log
2014-04-01 23:02 - 2014-04-01 23:02 - 00002674 _____ () C:\Documents and Settings\Administrator\Desktop\Nmc_2014-04-01_23-02-26.log
==================== One Month Modified Files and Folders =======
2014-04-25 00:39 - 2014-04-21 12:33 - 00000370 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-04-25 00:38 - 2014-04-25 00:35 - 00011991 _____ () C:\Documents and Settings\Administrator\Desktop\FRST.txt
2014-04-25 00:38 - 2014-04-25 00:05 - 00000000 ____D () C:\FRST
2014-04-25 00:38 - 2007-06-26 18:40 - 01181920 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-25 00:38 - 2006-03-02 14:00 - 00522524 _____ () C:\WINDOWS\system32\perfh010.dat
2014-04-25 00:38 - 2006-03-02 14:00 - 00090088 _____ () C:\WINDOWS\system32\perfc010.dat
2014-04-25 00:34 - 2012-10-28 23:11 - 00000000 ____D () C:\Programmi\PeerBlock
2014-04-25 00:34 - 2012-05-26 21:23 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-04-25 00:34 - 2007-06-26 19:58 - 01202052 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-25 00:34 - 2006-03-02 14:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-04-25 00:33 - 2014-03-13 23:56 - 00000238 _____ () C:\WINDOWS\Tasks\Notifica di interruzione del servizio per Microsoft Windows XP - Accesso.job
2014-04-25 00:33 - 2012-05-26 21:23 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-04-25 00:33 - 2007-06-27 00:29 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-04-25 00:32 - 2007-06-27 00:29 - 00032610 _____ () C:\WINDOWS\SchedLgU.Txt
2014-04-25 00:32 - 2007-06-27 00:29 - 00000306 ___SH () C:\Documents and Settings\Administrator\ntuser.ini
2014-04-25 00:04 - 2014-04-25 00:04 - 01048576 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\FRST.exe
2014-04-24 18:49 - 2012-10-21 18:29 - 00000000 ____D () C:\Documents and Settings\Administrator\Documenti\mm+2
2014-04-24 18:47 - 2014-04-24 18:47 - 00079444 _____ () C:\Documents and Settings\Administrator\Documenti\usbdeview.zip
2014-04-24 18:47 - 2007-06-27 00:29 - 00000000 ___RD () C:\Documents and Settings\Administrator\Documenti
2014-04-24 18:44 - 2014-04-24 18:44 - 00003215 _____ () C:\Documents and Settings\Administrator\Documenti\usbdeview_italian.zip
2014-04-24 18:44 - 2013-12-20 21:55 - 00000978 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-04-24 15:41 - 2007-06-27 00:29 - 00000000 ___RD () C:\Documents and Settings\Administrator\Documenti\Musica
2014-04-24 15:39 - 2014-04-24 15:18 - 653006972 _____ () C:\Documents and Settings\Administrator\Documenti\Artista Sconosciuto - Titolo Sconosciuto.wav
2014-04-24 15:18 - 2014-04-24 15:18 - 00001495 _____ () C:\Documents and Settings\Administrator\Documenti\Artista Sconosciuto - Titolo Sconosciuto.cue
2014-04-24 15:16 - 2012-12-08 23:43 - 00000000 ____D () C:\Documents and Settings\Administrator\Dati applicazioni\AccurateRip
2014-04-24 14:59 - 2014-04-01 23:08 - 00000000 ____D () C:\Documents and Settings\All Users\Dati applicazioni\DVD Shrink
2014-04-24 14:13 - 2014-04-01 23:32 - 00000000 ____D () C:\Documents and Settings\Administrator\Dati applicazioni\Vso
2014-04-24 12:53 - 2014-04-24 12:53 - 00090112 _____ () C:\WINDOWS\Minidump\Mini042414-01.dmp
2014-04-24 12:53 - 2007-12-14 12:22 - 00000000 ____D () C:\WINDOWS\Minidump
2014-04-24 09:29 - 2007-06-27 09:05 - 00000000 __SHD () C:\Documents and Settings\Administrator\UserData
2014-04-24 09:29 - 2007-06-27 00:29 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-04-21 21:27 - 2013-10-30 22:18 - 00000000 ____D () C:\Documents and Settings\Administrator\Documenti\Calibre Library
2014-04-21 21:16 - 2013-12-25 02:09 - 00000699 _____ () C:\Documents and Settings\All Users\Desktop\calibre - E-book management.lnk
2014-04-21 21:16 - 2013-12-25 02:09 - 00000000 ____D () C:\Programmi\Calibre2
2014-04-21 21:16 - 2013-12-25 02:09 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Avvio\Programmi\calibre - E-book Management
2014-04-21 15:51 - 2014-04-21 15:51 - 00000162 ____H () C:\Documents and Settings\Administrator\Desktop\~$051.part
2014-04-21 12:33 - 2014-04-21 12:33 - 00001697 _____ () C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2014-04-21 12:33 - 2014-04-21 12:33 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Avvio\Programmi\Avast
2014-04-21 12:33 - 2014-04-21 12:33 - 00000000 ____D () C:\Documents and Settings\Administrator\Dati applicazioni\AVAST Software
2014-04-21 12:33 - 2007-06-27 00:29 - 00000000 __RHD () C:\Documents and Settings\Administrator\Dati applicazioni
2014-04-21 12:33 - 2007-06-26 18:39 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Avvio\Programmi
2014-04-21 12:32 - 2014-04-21 12:32 - 00776976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00411552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00271264 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-04-21 12:32 - 2014-04-21 12:32 - 00180632 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00057672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00054832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-04-21 12:32 - 2014-04-21 12:32 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-04-21 12:32 - 2014-04-21 12:32 - 00000000 ____D () C:\Programmi\AVAST Software
2014-04-21 12:32 - 2007-06-26 18:40 - 00000000 ___RD () C:\Programmi
2014-04-21 12:31 - 2012-07-29 20:28 - 00000000 ____D () C:\Documents and Settings\All Users\Dati applicazioni\AVAST Software
2014-04-21 11:54 - 2013-10-01 23:10 - 88524609 _____ () C:\Documents and Settings\Administrator\Documenti\Avast_Free.zip
2014-04-14 20:26 - 2014-04-01 23:18 - 00001318 _____ () C:\WINDOWS\Sandboxie.ini
2014-04-13 22:52 - 2014-04-13 08:42 - 00065122 _____ () C:\OTL.Txt
2014-04-13 18:18 - 2014-04-13 18:18 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\Start MAC.app
2014-04-13 18:18 - 2014-04-13 18:18 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\PC
2014-04-13 18:18 - 2014-04-13 18:17 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\MAC
2014-04-13 17:55 - 2008-12-28 22:56 - 00000768 _____ () C:\Documents and Settings\LocalService\Menu Avvio\Programmi\Windows Media Player.lnk
2014-04-13 17:55 - 2008-02-17 19:55 - 00000000 ____D () C:\Documents and Settings\LocalService\Menu Avvio\Programmi
2014-04-13 17:54 - 2008-12-28 22:56 - 00000247 _____ () C:\WINDOWS\system32\spupdwxp.log
2014-04-13 17:51 - 2007-06-26 18:33 - 00000000 ____D () C:\WINDOWS\security
2014-04-13 17:49 - 2014-04-13 17:49 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB958644$
2014-04-13 17:49 - 2014-04-13 17:49 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB957097$
2014-04-13 17:49 - 2014-04-13 17:49 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB957095$
2014-04-13 17:49 - 2014-04-13 17:49 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956841$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956803$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956802$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB955069$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB954600$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB954211$
2014-04-13 17:48 - 2014-04-13 17:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB952954$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB952287$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951748$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951698$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951376-v2$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951376$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951066$
2014-04-13 17:47 - 2014-04-13 17:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB950974$
2014-04-13 17:46 - 2014-04-13 17:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB950762$
2014-04-13 17:46 - 2014-04-13 17:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB946648$
2014-04-13 17:46 - 2014-04-13 17:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB938464$
2014-04-13 17:46 - 2007-06-26 19:56 - 00000000 ____D () C:\Programmi\Messenger
2014-04-13 17:43 - 2007-06-26 19:59 - 00001563 _____ () C:\Documents and Settings\All Users\Menu Avvio\Impostazioni accesso ai programmi.lnk
2014-04-13 17:43 - 2007-06-26 19:55 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Avvio\Programmi\Accessori
2014-04-13 17:43 - 2007-06-26 18:39 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Avvio
2014-04-13 17:42 - 2007-06-27 08:03 - 00000000 ____D () C:\WINDOWS\system32\ReinstallBackups
2014-04-13 17:42 - 2007-06-26 18:33 - 00000000 ____D () C:\WINDOWS\Help
2014-04-13 17:28 - 2007-06-27 18:05 - 00033280 _____ () C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-13 16:22 - 2012-03-12 20:23 - 00002441 _____ () C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
2014-04-13 16:20 - 2008-02-12 16:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB921503$
2014-04-13 09:07 - 2014-04-12 20:54 - 00000000 ____D () C:\Documents and Settings\All Users\Dati applicazioni\2992199F9A
2014-04-13 09:07 - 2007-06-27 00:29 - 00000000 ___RD () C:\Documents and Settings\Administrator\Menu Avvio\Programmi\Esecuzione automatica
2014-04-13 09:06 - 2014-04-13 09:06 - 00000000 ____D () C:\_OTL
2014-04-13 03:26 - 2014-03-03 20:16 - 00000000 ____D () C:\Kaspersky Rescue Disk 10.0
2014-04-13 03:21 - 2014-04-13 03:18 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-13 03:18 - 2014-04-13 03:18 - 00000749 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-13 03:18 - 2014-04-13 03:18 - 00000000 ____D () C:\Programmi\Malwarebytes Anti-Malware
2014-04-13 03:18 - 2014-04-13 03:18 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Avvio\Programmi\Malwarebytes Anti-Malware
2014-04-13 03:18 - 2012-06-15 19:55 - 00000000 ____D () C:\Documents and Settings\Administrator\Dati applicazioni\Malwarebytes
2014-04-13 03:18 - 2012-06-15 19:54 - 00000000 ____D () C:\Programmi\Malwarebytes' Anti-Malware
2014-04-13 03:18 - 2012-06-15 19:54 - 00000000 ____D () C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2014-04-12 21:06 - 2012-04-25 11:29 - 00000000 ____D () C:\WINDOWS\pss
2014-04-12 21:06 - 2007-06-26 18:38 - 00000211 ___SH () C:\boot.ini
2014-04-12 21:06 - 2006-03-02 14:00 - 00000828 _____ () C:\WINDOWS\win.ini
2014-04-12 21:06 - 2006-03-02 14:00 - 00000227 _____ () C:\WINDOWS\system.ini
2014-04-12 20:54 - 2007-06-26 18:39 - 00000000 __RHD () C:\Documents and Settings\All Users\Dati applicazioni
2014-04-10 00:31 - 2014-04-10 00:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-04-10 00:31 - 2013-07-17 13:39 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-04-10 00:29 - 2009-10-25 19:25 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-04-10 00:29 - 2007-06-27 10:46 - 88028728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-04-06 22:58 - 2014-04-06 22:58 - 00000698 _____ () C:\Documents and Settings\Administrator\Desktop\Collegamento a DVD Shrink 3.2.lnk
2014-04-06 21:58 - 2007-06-27 00:29 - 00000000 ___HD () C:\Documents and Settings\Administrator\Impostazioni locali
2014-04-06 00:38 - 2014-04-05 17:55 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\Nuova cartella
2014-04-05 18:06 - 2012-12-23 20:44 - 00000000 ____D () C:\Documents and Settings\Administrator\Dati applicazioni\vlc
2014-04-03 09:51 - 2014-04-13 03:18 - 00050648 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-03 09:50 - 2012-06-15 19:54 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-04-02 00:03 - 2014-04-01 23:32 - 00000000 ____D () C:\Programmi\DVDFab 5
2014-04-01 23:53 - 2014-04-01 23:53 - 00000000 ____D () C:\Documents and Settings\All Users\Dati applicazioni\vsosdk
2014-04-01 23:36 - 2014-04-01 23:32 - 00000000 ____D () C:\Documents and Settings\Administrator\Documenti\DVDFab
2014-04-01 23:35 - 2014-04-01 23:35 - 00000642 _____ () C:\Documents and Settings\Administrator\Desktop\Collegamento a DVDFab.lnk
2014-04-01 23:32 - 2014-04-01 23:32 - 00087608 _____ () C:\Documents and Settings\Administrator\Dati applicazioni\inst.exe
2014-04-01 23:32 - 2014-04-01 23:32 - 00047360 _____ (VSO Software) C:\WINDOWS\system32\Drivers\pcouffin.sys
2014-04-01 23:32 - 2014-04-01 23:32 - 00047360 _____ (VSO Software) C:\Documents and Settings\Administrator\Dati applicazioni\pcouffin.sys
2014-04-01 23:32 - 2014-04-01 23:32 - 00007887 _____ () C:\Documents and Settings\Administrator\Dati applicazioni\pcouffin.cat
2014-04-01 23:32 - 2014-04-01 23:32 - 00000034 _____ () C:\Documents and Settings\Administrator\Dati applicazioni\pcouffin.log
2014-04-01 23:30 - 2014-04-01 23:30 - 00000000 ___RD () C:\Sandbox
2014-04-01 23:18 - 2014-04-01 23:18 - 00000756 _____ () C:\Documents and Settings\Administrator\Desktop\Browser Web nell'area virtuale.lnk
2014-04-01 23:18 - 2014-04-01 23:18 - 00000000 ____D () C:\Programmi\Sandboxie
2014-04-01 23:18 - 2014-04-01 23:18 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Avvio\Programmi\Sandboxie
2014-04-01 23:08 - 2014-04-01 23:08 - 00000000 ____D () C:\Programmi\DVD Shrink
2014-04-01 23:04 - 2014-04-01 23:04 - 00004190 _____ () C:\Documents and Settings\Administrator\Desktop\Nmc_2014-04-01_23-04-16.log
2014-04-01 23:02 - 2014-04-01 23:02 - 00002674 _____ () C:\Documents and Settings\Administrator\Desktop\Nmc_2014-04-01_23-02-26.log
2014-03-30 21:22 - 2007-06-27 00:29 - 00000000 ___RD () C:\Documents and Settings\Administrator\Preferiti
2014-03-26 01:09 - 2012-07-29 21:46 - 00000000 ____D () C:\Documents and Settings\Administrator\Dati applicazioni\PCToolsFirewallPlus
2014-03-26 01:09 - 2012-07-29 21:45 - 00000000 ____D () C:\Programmi\PC Tools Firewall Plus
2014-03-26 01:09 - 2007-06-26 18:40 - 00000000 ____D () C:\Programmi\File comuni
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2006-03-02 14:00] - [2008-04-14 04:14] - 1036288 ____A (Microsoft Corporation) 70d7f99d95615c3c278367756287db71
C:\WINDOWS\system32\winlogon.exe
[2006-03-02 14:00] - [2008-04-14 04:14] - 0510464 ____A (Microsoft Corporation) 9259170d29b5a256735fcb8b80280857
C:\WINDOWS\system32\svchost.exe
[2006-03-02 14:00] - [2008-04-14 04:14] - 0014336 ____A (Microsoft Corporation) bb8363abec09aa2f9b363484e282117c
C:\WINDOWS\system32\services.exe
[2006-03-02 14:00] - [2009-02-09 13:22] - 0111104 ____A (Microsoft Corporation) 26845f272435302e0f3322e660a24f7d
C:\WINDOWS\system32\User32.dll
[2006-03-02 14:00] - [2008-04-14 04:13] - 0579584 ____A (Microsoft Corporation) fa94696c0727bd59e517c674cd6e7c72
C:\WINDOWS\system32\userinit.exe
[2006-03-02 14:00] - [2008-04-14 04:14] - 0026624 ____A (Microsoft Corporation) df69726907357c3add243f48902b0331
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys
[2006-03-02 14:00] - [2008-04-14 03:49] - 0053376 ____A (Microsoft Corporation) e46c1b5a56da7da603d09dfcc79ec59e
==================== End Of Log ============================