My
OTL.Txt :
OTL logfile created on: 04/08/2012 20:20:28 - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Users\Giacomo\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
7,98 Gb Total Physical Memory | 6,19 Gb Available Physical Memory | 77,55% Memory free
15,95 Gb Paging File | 14,15 Gb Available in Paging File | 88,66% Paging File free
Paging file location(s): c:\pagefile.sys 8170 8170 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 280,48 Gb Free Space | 30,11% Space Free | Partition Type: NTFS
Drive F: | 991,22 Mb Total Space | 972,81 Mb Free Space | 98,14% Space Free | Partition Type: FAT
Computer Name: GIACOMO-PC | User Name: Giacomo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/08/04 20:00:16 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Giacomo\Desktop\OTL.exe
PRC - [2012/07/05 02:25:11 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/05/15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2011/12/06 11:15:40 | 003,508,624 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2011/10/07 12:35:20 | 000,586,880 | ---- | M] () -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
PRC - [2011/10/07 12:34:34 | 000,915,584 | ---- | M] () -- C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
PRC - [2011/10/07 12:34:30 | 000,922,240 | ---- | M] () -- C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
PRC - [2011/08/04 15:06:26 | 001,436,288 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
PRC - [2011/08/02 09:33:30 | 004,910,912 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2011/07/06 20:38:52 | 001,116,288 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
PRC - [2010/11/26 22:50:04 | 002,931,328 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/07 12:34:38 | 000,662,016 | ---- | M] () -- C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMLib.dll
MOD - [2011/08/12 16:48:36 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\BarGadget\BarGadget.dll
MOD - [2011/08/09 13:15:00 | 001,242,624 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Settings\Settings.dll
MOD - [2011/07/29 12:44:16 | 001,611,776 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Sensor Graph\SensorGraph.dll
MOD - [2011/07/26 17:16:16 | 000,880,128 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Sensor\Sensor.dll
MOD - [2011/07/21 21:33:44 | 000,885,760 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\TabGadget\TabGadget.dll
MOD - [2011/07/21 10:06:44 | 000,846,848 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Splitter\Splitter.dll
MOD - [2011/07/12 20:14:52 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\AssistFunc.dll
MOD - [2010/10/05 09:22:50 | 000,253,952 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\pngio.dll
MOD - [2010/10/05 09:22:50 | 000,208,896 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\ImageHelper.dll
MOD - [2010/06/21 16:21:22 | 000,208,896 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\ImageHelper.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2010/08/12 15:00:20 | 000,133,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel® PROSet Monitoring Service)
SRV:
64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/07/18 18:48:47 | 000,113,120 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/07/12 21:16:55 | 000,008,704 | ---- | M] (Hi-Rez Studios) [Auto | Paused] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2012/07/05 02:25:11 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/06/20 01:11:26 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/05/15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Programmi\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Programmi\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/10/07 12:35:20 | 000,586,880 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe -- (AsSysCtrlService)
SRV - [2011/10/07 12:34:34 | 000,915,584 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe -- (asHmComSvc)
SRV - [2011/10/07 12:34:30 | 000,922,240 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe -- (asComSvc)
SRV - [2011/05/31 09:42:06 | 000,210,024 | ---- | M] (DTS) [Auto | Running] -- C:\Programmi\Realtek\Audio\HDA\DTSAudioService64.exe -- (DTSAudioService)
SRV - [2011/03/13 11:58:30 | 000,074,912 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe -- (AtherosSvc)
SRV - [2011/03/01 18:29:58 | 000,130,976 | ---- | M] (Futuremark Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/01/09 22:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmi\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010/01/09 22:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmi\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV - [2009/12/15 22:07:16 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- C:\Program Files (x86)\Dragon Age Origins\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc)
SRV - [2009/08/18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programmi\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2006/12/19 09:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Disabled | Stopped] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:
64bit: - [2012/03/01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2011/11/15 20:32:40 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss)
DRV:
64bit: - [2011/11/08 04:04:03 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:
64bit: - [2011/11/08 04:04:02 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:
64bit: - [2011/10/27 23:08:29 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:
64bit: - [2011/10/27 03:25:54 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(
www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.)
DRV:
64bit: - [2011/10/27 03:25:54 | 000,095,928 | ---- | M] (DEVGURU Co., LTD.(
www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
DRV:
64bit: - [2011/10/27 03:25:52 | 000,172,104 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdmdm.sys -- (sscdmdm)
DRV:
64bit: - [2011/10/27 03:25:52 | 000,136,264 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV:
64bit: - [2011/10/27 03:25:52 | 000,019,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV:
64bit: - [2011/09/14 18:05:34 | 000,394,216 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV:
64bit: - [2011/09/14 18:05:34 | 000,129,000 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV:
64bit: - [2011/03/13 11:58:44 | 000,280,224 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:
64bit: - [2011/03/13 11:58:44 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:
64bit: - [2011/03/13 11:58:44 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:
64bit: - [2011/03/13 11:58:44 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:
64bit: - [2011/03/13 11:58:42 | 000,298,656 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:
64bit: - [2011/03/13 11:58:42 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:
64bit: - [2011/03/13 11:58:42 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:
64bit: - [2011/03/13 10:58:42 | 000,051,872 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AthDfu.sys -- (ATHDFU)
DRV:
64bit: - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010/11/21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:
64bit: - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:
64bit: - [2010/10/19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:
64bit: - [2010/09/21 08:34:18 | 000,313,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) Intel(R)
DRV:
64bit: - [2010/08/10 11:29:15 | 000,120,920 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV:
64bit: - [2009/08/13 22:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:
64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:
64bit: - [2007/02/07 16:51:18 | 000,169,496 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\adiusbawx64.sys -- (adiusbaw)
DRV:
64bit: - [2007/02/07 16:50:58 | 000,058,264 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\adildrx64.sys -- (ELOADER) General Purpose USB Driver (adildrx64.sys)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2007/02/07 16:51:18 | 000,169,496 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\adiusbawx64.sys -- (adiusbaw)
DRV - [2007/02/07 16:50:58 | 000,058,264 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\adildrx64.sys -- (ELOADER) General Purpose USB Driver (adildrx64.sys)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = it-IT
IE - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5C DB E7 68 74 AC CC 01 [binary data]
IE - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.118.0: C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Giacomo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/18 18:48:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/12/25 17:54:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Giacomo\AppData\Roaming\mozilla\Extensions
[2011/12/25 17:54:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Giacomo\AppData\Roaming\mozilla\Extensions\
prism@developer.mozilla.org
[2012/07/21 00:05:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Giacomo\AppData\Roaming\mozilla\Firefox\Profiles\vkjrqkgw.default\extensions
[2012/07/05 01:14:07 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Giacomo\AppData\Roaming\mozilla\Firefox\Profiles\vkjrqkgw.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/12/04 16:31:11 | 000,000,000 | ---D | M] (YTshowRating) -- C:\Users\Giacomo\AppData\Roaming\mozilla\Firefox\Profiles\vkjrqkgw.default\extensions\jid1-m7xzZLMj29zzjA@jetpack
[2012/04/25 14:53:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012/07/18 18:48:48 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/04/21 03:18:25 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/21 03:18:25 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/08/04 13:46:40 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (no name) - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:
64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVBg_DTS] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3742733959-2798518282-3139704220-1019..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-3742733959-2798518282-3139704220-1019..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3742733959-2798518282-3139704220-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3742733959-2798518282-3139704220-1019\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9:
64bit: - Extra Button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9:
64bit: - Extra 'Tools' menuitem : I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9:
64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9:
64bit: - Extra Button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9:
64bit: - Extra 'Tools' menuitem : &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programmi\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programmi\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.4.1)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.4.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C4C3759-8329-43E8-BB45-ADB9DC664B9E}: NameServer = 85.37.17.5 85.38.28.77
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmi\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programmi\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O22:
64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll (Stardock)
O28:
64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programmi\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/08/04 20:19:18 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Users\Giacomo\Desktop\OTL.exe
[2012/08/04 20:14:14 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Roaming\Malwarebytes
[2012/08/04 20:13:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/04 20:13:41 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/08/04 20:13:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/04 20:13:17 | 010,652,120 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Giacomo\Desktop\mbam-setup-1.62.0.1300.exe
[2012/08/04 18:22:37 | 000,000,000 | R--D | C] -- C:\Users\Giacomo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2012/08/04 15:17:12 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\Documents\Combofix
[2012/08/04 13:50:17 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/08/04 13:46:58 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/04 03:34:15 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/08/04 03:34:15 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/08/04 03:34:15 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/08/04 03:34:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/08/04 03:33:56 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/08/03 13:01:41 | 000,000,000 | ---D | C] -- C:\FRST
[2012/08/03 04:36:55 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Local\NPE
[2012/08/03 04:21:59 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012/08/03 00:06:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/08/03 00:06:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/08/02 23:43:15 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Local\ElevatedDiagnostics
[2012/08/02 21:09:50 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2012/08/02 17:54:42 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Roaming\Apple Computer
[2012/08/01 00:04:28 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Local\FLT
[2012/08/01 00:04:27 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\Documents\Shiner
[2012/07/31 23:59:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Orcs Must Die 2
[2012/07/30 03:52:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Solidshield
[2012/07/29 22:59:39 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\Documents\Activision
[2012/07/29 22:33:11 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\Desktop\Nuova cartella (2)
[2012/07/29 19:24:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PROTOTYPE 2
[2012/07/28 19:56:41 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\Documents\Inversion Saves
[2012/07/28 19:36:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Namco Bandai Games
[2012/07/23 12:51:01 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\Documents\Bioshock2
[2012/07/23 12:51:01 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Roaming\Bioshock2
[2012/07/09 04:15:09 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Local\Two Worlds II
[2012/07/09 04:11:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reality Pump
[2012/07/07 17:43:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Krater
[2012/07/07 04:19:49 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Roaming\Nicalis
[2012/07/07 04:15:49 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Roaming\LoneSurvivor
[2012/07/07 04:07:09 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\AppData\Roaming\FatShark
[2012/07/07 03:55:03 | 000,000,000 | ---D | C] -- C:\Users\Giacomo\Documents\Gaslamp Games
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/04 20:13:44 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/04 20:00:16 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Giacomo\Desktop\OTL.exe
[2012/08/04 19:59:06 | 010,652,120 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Giacomo\Desktop\mbam-setup-1.62.0.1300.exe
[2012/08/04 18:29:43 | 000,031,504 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/04 18:29:43 | 000,031,504 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/04 18:22:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/04 18:22:07 | 2129,879,039 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/04 13:46:40 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/08/04 03:31:42 | 001,661,246 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/04 03:31:42 | 000,741,344 | ---- | M] () -- C:\Windows\SysNative\perfh010.dat
[2012/08/04 03:31:42 | 000,654,278 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/08/04 03:31:42 | 000,147,316 | ---- | M] () -- C:\Windows\SysNative\perfc010.dat
[2012/08/04 03:31:42 | 000,122,110 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/08/03 04:47:31 | 000,002,243 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/08/03 00:06:28 | 001,681,944 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/02 16:35:46 | 000,001,456 | ---- | M] () -- C:\Users\Giacomo\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/08/02 03:25:31 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012/08/02 03:25:31 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/08/02 03:25:19 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012/08/01 12:41:25 | 004,979,048 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/01 00:02:19 | 000,002,192 | ---- | M] () -- C:\Users\Public\Desktop\Orcs Must Die! 2.lnk
[2012/07/29 22:58:41 | 000,000,964 | ---- | M] () -- C:\Users\Giacomo\Desktop\Prototype 2.lnk
[2012/07/28 19:39:43 | 000,002,242 | ---- | M] () -- C:\Users\Public\Desktop\Inversion.lnk
[2012/07/27 21:48:36 | 000,000,132 | ---- | M] () -- C:\Users\Giacomo\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/07/25 00:12:04 | 000,000,132 | ---- | M] () -- C:\Users\Giacomo\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2012/07/22 20:31:51 | 000,000,220 | ---- | M] () -- C:\Users\Giacomo\Desktop\BioShock 2.url
[2012/07/10 23:48:32 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012/07/09 04:16:02 | 000,001,651 | ---- | M] () -- C:\Users\Giacomo\Desktop\Two Worlds 2.lnk
[2012/07/07 17:47:31 | 000,001,865 | ---- | M] () -- C:\Users\Giacomo\Desktop\Krater.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/04 20:13:44 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/04 03:34:15 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/08/04 03:34:15 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/08/04 03:34:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/08/04 03:34:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/08/04 03:34:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/08/03 00:06:31 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/01 00:02:19 | 000,002,192 | ---- | C] () -- C:\Users\Public\Desktop\Orcs Must Die! 2.lnk
[2012/07/29 22:58:41 | 000,000,964 | ---- | C] () -- C:\Users\Giacomo\Desktop\Prototype 2.lnk
[2012/07/29 00:00:32 | 000,001,633 | ---- | C] () -- C:\Users\Giacomo\Desktop\DayZ.lnk
[2012/07/28 19:39:43 | 000,002,242 | ---- | C] () -- C:\Users\Public\Desktop\Inversion.lnk
[2012/07/22 20:31:51 | 000,000,220 | ---- | C] () -- C:\Users\Giacomo\Desktop\BioShock 2.url
[2012/07/09 04:16:02 | 000,001,651 | ---- | C] () -- C:\Users\Giacomo\Desktop\Two Worlds 2.lnk
[2012/07/07 17:47:31 | 000,001,865 | ---- | C] () -- C:\Users\Giacomo\Desktop\Krater.lnk
[2012/07/05 02:15:22 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2012/06/21 10:37:14 | 003,166,792 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2012/05/25 15:24:36 | 000,003,584 | ---- | C] () -- C:\Users\Giacomo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/04/11 02:59:04 | 000,000,298 | ---- | C] () -- C:\Windows\vtmb.ini
[2012/02/04 05:10:21 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/12/31 16:08:34 | 000,000,132 | ---- | C] () -- C:\Users\Giacomo\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2011/12/25 02:00:01 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011/12/21 02:13:15 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2011/12/19 03:31:54 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011/11/29 20:49:47 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2011/11/29 20:49:47 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2011/11/29 20:48:24 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011/11/29 19:15:36 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011/11/27 13:24:06 | 002,601,752 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_moh.exe
[2011/11/08 19:18:25 | 000,000,132 | ---- | C] () -- C:\Users\Giacomo\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/11/06 17:29:56 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2011/11/05 17:46:50 | 000,001,456 | ---- | C] () -- C:\Users\Giacomo\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/10/31 12:22:42 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011/10/31 12:22:40 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011/10/31 12:22:40 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011/10/31 12:22:40 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/10/31 12:22:38 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2011/10/28 10:02:04 | 000,283,304 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/28 10:02:03 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/27 20:14:57 | 000,000,169 | ---- | C] () -- C:\Windows\adidsl.ini
[2011/10/27 20:14:57 | 000,000,021 | ---- | C] () -- C:\Windows\Fast800.ini
[2011/10/27 20:14:43 | 000,253,008 | ---- | C] () -- C:\Windows\adirasx64.exe
[2011/10/27 20:14:43 | 000,194,128 | ---- | C] () -- C:\Windows\adiras.exe
[2011/10/27 20:14:43 | 000,000,991 | ---- | C] () -- C:\Windows\adiras.ini
[2011/10/27 20:14:41 | 000,024,576 | ---- | C] () -- C:\Windows\enddisk32.exe
[2011/10/27 17:46:32 | 000,040,927 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2011/10/27 17:41:38 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/10/27 17:41:33 | 000,028,587 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011/10/27 16:15:22 | 001,681,944 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
========== LOP Check ==========
[2011/10/31 04:38:04 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\2K Sports
[2012/07/23 15:27:36 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Bioshock2
[2012/08/01 00:04:20 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\DAEMON Tools Lite
[2012/07/17 02:42:06 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\FatShark
[2011/11/04 04:53:33 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Hothead Games
[2012/02/26 21:27:13 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Kalypso Media
[2012/07/07 04:15:49 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\LoneSurvivor
[2012/07/07 04:19:49 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Nicalis
[2011/10/27 20:49:24 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Origin
[2012/01/29 04:17:15 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\PotPlayerMini64
[2011/10/28 17:25:21 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\PunkBuster
[2011/12/24 04:17:36 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\runic games
[2011/11/28 04:37:32 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Samsung
[2012/05/23 02:13:56 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\six-updater
[2012/05/18 17:30:02 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\six-zsync
[2012/03/03 18:18:39 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\SoftGrid Client
[2012/03/29 03:38:52 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Stardock
[2012/06/17 17:17:19 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\TeamViewer
[2011/11/28 04:50:50 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Temp
[2011/11/08 00:27:00 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\The Creative Assembly
[2011/10/27 17:14:45 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\TP
[2012/04/15 03:30:54 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Tropico 4
[2012/07/13 23:56:36 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\TS3Client
[2012/07/21 00:00:28 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\Ubisoft
[2012/08/02 21:49:09 | 000,000,000 | ---D | M] -- C:\Users\Giacomo\AppData\Roaming\uTorrent
[2012/07/22 17:05:23 | 000,032,556 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >