Hi Cypher. First of all thanks for helping me. I followed all the instructions you gave me and here are the informations you need:
RKreport[1].txt content:
RogueKiller V4.3.0 by Tigzy
contact at
http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: alx [Admin rights]
Mode: Scan -- Date : 03/14/2011 00:35:20
Bad processes: 0
Registry Entries: 1
[BLACKLIST] HKLM\[...]\Root : LEGACY_USERINIT () -> FOUND
HOSTS File:
127.0.0.1 localhost
127.0.0.1
www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
www.008k.com
127.0.0.1 008k.com
127.0.0.1
www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1
www.032439.com
127.0.0.1 032439.com
127.0.0.1
www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1
www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1
www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1
www.100888290cs.com
127.0.0.1
www.100sexlinks.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
Malwarebytes log content (mbam-log-2011-03-14 (01-01-46).txt):
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Versione database: 6046
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
14/03/2011 1.01.46
mbam-log-2011-03-14 (01-01-46).txt
Tipo di scansione: Scansione veloce (quick scan)
Elementi esaminati: 138497
Tempo trascorso (elapsed time): 6 minuti, 0 secondi
Processi infetti in memoria: 0
Moduli di memoria infetti: 0
(infected registry keys) Chiavi di registro infette: 1
(infected registry values)Valori di registro infetti: 4
(infected entries in registry data)Voci infette nei dati di registro: 0
(infected folders) Cartelle infette: 0
File infetti: 0
Processi infetti in memoria:
(No harmful elements detected)(Non sono stati rilevati elementi nocivi)
Moduli di memoria infetti:
(No harmful elements detected)(Non sono stati rilevati elementi nocivi)
(infected registry keys) Chiavi di registro infette:
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
(infected registry values) Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Value: bf -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Value: bk -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Value: iu -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Value: mu -> Quarantined and deleted successfully.
(infected entries in registry data) Voci infette nei dati di registro:
(No harmful elements detected)(Non sono stati rilevati elementi nocivi)
(infected folders)Cartelle infette:
(No harmful elements detected)(Non sono stati rilevati elementi nocivi)
File infetti:
(No harmful elements detected)(Non sono stati rilevati elementi nocivi)
RSIT log.txt content
Logfile of random's system information tool 1.08 (written by random/random)
Run by alx at 2011-03-14 01:08:40
Microsoft Windows XP Professional Service Pack 2
System drive L: has 70 GB (76%) free of 92 GB
Total RAM: 511 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1.09.51, on 14/03/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
L:\WINDOWS\System32\smss.exe
L:\WINDOWS\system32\winlogon.exe
L:\WINDOWS\system32\services.exe
L:\WINDOWS\system32\lsass.exe
L:\WINDOWS\system32\Ati2evxx.exe
L:\WINDOWS\system32\svchost.exe
L:\WINDOWS\System32\svchost.exe
L:\WINDOWS\system32\Ati2evxx.exe
L:\WINDOWS\Explorer.EXE
L:\WINDOWS\system32\spoolsv.exe
L:\Programmi\ICQ6Toolbar\ICQ Service.exe
L:\Programmi\Java\jre6\bin\jqs.exe
L:\Programmi\McAfee\Common Framework\FrameworkService.exe
L:\Programmi\McAfee\VirusScan Enterprise\Mcshield.exe
L:\Programmi\McAfee\VirusScan Enterprise\VsTskMgr.exe
L:\WINDOWS\system32\slserv.exe
L:\WINDOWS\system32\svchost.exe
L:\WINDOWS\system32\wscntfy.exe
L:\WINDOWS\system32\RunDll32.exe
L:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
L:\WINDOWS\vsnpstd3.exe
L:\WINDOWS\tsnpstd3.exe
L:\Programmi\File comuni\Java\Java Update\jusched.exe
L:\Programmi\McAfee\Common Framework\UdaterUI.exe
L:\Programmi\McAfee\VirusScan Enterprise\SHSTAT.EXE
L:\WINDOWS\system32\ctfmon.exe
L:\Programmi\Messenger\msmsgs.exe
L:\Programmi\Babylon\Babylon.exe
L:\Programmi\Skype\Phone\Skype.exe
L:\WINDOWS\System32\svchost.exe
L:\Programmi\McAfee\Common Framework\McTray.exe
L:\WINDOWS\system32\dllhost.exe
L:\Documents and Settings\alx\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
L:\Documents and Settings\alx\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
L:\Documents and Settings\alx\Documenti\Downloads\RSIT.exe
L:\Programmi\trend micro\alx.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - L:\Programmi\ICQ6Toolbar\20101029021540\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - L:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - L:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - L:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - L:\Programmi\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - L:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - L:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - L:\Programmi\ICQ6Toolbar\20101029021540\ICQToolBar.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "L:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "L:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "L:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] L:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [snpstd3] L:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [tsnpstd3] L:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "L:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "L:\Programmi\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "L:\Programmi\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] L:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "L:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Babylon Translator] L:\Programmi\Babylon\Babylon.exe
O4 - HKCU\..\Run: [Google Update] "L:\Documents and Settings\alx\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "L:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] L:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AdobeUpdater] "L:\Programmi\File comuni\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://L:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - L:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - L:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - L:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - L:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - L:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - L:\Programmi\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - L:\Programmi\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - L:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - L:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} (Java Plug-in 1.6.0_19) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E1D8D2F-4EFD-4714-80A7-D409F75FACD2}: NameServer = 192.168.1.254
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - L:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - L:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - L:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - L:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - L:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - L:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ICQ Service - Unknown owner - L:\Programmi\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - L:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - L:\Programmi\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - L:\Programmi\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - L:\Programmi\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - L:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - L:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7943 bytes
======Scheduled tasks folder======
L:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1214440339-682003330-1003Core.job
L:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1214440339-682003330-1003UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Supporto di collegamento per Adobe PDF Reader - L:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - L:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - L:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - L:\Programmi\McAfee\VirusScan Enterprise\scriptcl.dll [2006-11-30 67136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - L:\Programmi\Java\jre6\bin\jp2ssv.dll [2010-11-20 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - L:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-11-20 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - L:\Programmi\ICQ6Toolbar\20101029021540\ICQToolBar.dll [2010-10-04 1049912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"=L:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe [2008-07-09 919016]
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd []
"Adobe Reader Speed Launcher"=L:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"GrooveMonitor"=L:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"NeroFilterCheck"=L:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"snpstd3"=L:\WINDOWS\vsnpstd3.exe [2006-09-19 827392]
"tsnpstd3"=L:\WINDOWS\tsnpstd3.exe [2007-03-10 270336]
"SunJavaUpdateSched"=L:\Programmi\File comuni\Java\Java Update\jusched.exe [2010-05-14 248552]
"McAfeeUpdaterUI"=L:\Programmi\McAfee\Common Framework\UdaterUI.exe [2006-12-19 136768]
"ShStatEXE"=L:\Programmi\McAfee\VirusScan Enterprise\SHSTAT.EXE [2007-02-22 112216]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=L:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe [2010-12-20 443728]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=L:\WINDOWS\system32\ctfmon.exe [2004-08-19 15360]
"MSMSGS"=L:\Programmi\Messenger\msmsgs.exe [2004-08-19 1667584]
"Babylon Translator"=L:\Programmi\Babylon\Babylon.exe [2001-04-27 1896448]
"Google Update"=L:\Documents and Settings\alx\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-07-29 133104]
"Skype"=L:\Programmi\Skype\Phone\Skype.exe [2010-03-09 26100520]
"SpybotSD TeaTimer"=L:\Programmi\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"AdobeUpdater"=L:\Programmi\File comuni\Adobe\Updater5\AdobeUpdater.exe [2011-03-14 2356088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\L:^Documents and Settings^alx^Menu Avvio^Programmi^Esecuzione automatica^Check for TWS Updates.lnk]
L:\PROGRA~1\Jts\WiseUpdt.exe [2006-11-08 194775]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
L:\WINDOWS\system32\Ati2evxx.dll [2006-05-03 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - L:\WINDOWS\system32\WPDShServiceObj.dll [2006-08-24 133120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=L:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"L:\WINDOWS\system32\sessmgr.exe"="L:\WINDOWS\system32\sessmgr.exe:*

isabled

xpsp2res.dll,-22019"
"L:\Programmi\Microsoft Office\Office12\GROOVE.EXE"="L:\Programmi\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"L:\Programmi\Microsoft Office\Office12\ONENOTE.EXE"="L:\Programmi\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"L:\Programmi\McAfee\Common Framework\FrameworkService.exe"="L:\Programmi\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"L:\Programmi\ICQ6.5\ICQ.exe"="L:\Programmi\ICQ6.5\ICQ.exe:*:Enabled:ICQ.exe"
"L:\Programmi\Skype\Plugin Manager\skypePM.exe"="L:\Programmi\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"L:\Programmi\Skype\Phone\Skype.exe"="L:\Programmi\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"L:\Programmi\ICQ6.5\ICQ.exe"="L:\Programmi\ICQ6.5\ICQ.exe:*:Enabled:ICQ.exe"
======List of files/folders created in the last 2 months======
2011-03-14 01:08:48 ----D---- L:\Programmi\trend micro
2011-03-14 01:08:40 ----D---- L:\rsit
2011-03-14 00:49:45 ----D---- L:\Documents and Settings\alx\Dati applicazioni\Malwarebytes
2011-03-14 00:49:35 ----A---- L:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-03-14 00:49:34 ----D---- L:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2011-03-14 00:49:30 ----D---- L:\Programmi\Malwarebytes' Anti-Malware
2011-03-14 00:49:30 ----A---- L:\WINDOWS\system32\drivers\mbam.sys
2011-03-13 21:05:22 ----D---- L:\WINDOWS\system32\NtmsData
2011-03-12 10:37:54 ----D---- L:\WINDOWS\ERDNT
2011-03-12 10:35:23 ----D---- L:\Programmi\ERUNT
2011-03-12 02:32:44 ----D---- L:\Programmi\totalcmd
2011-03-12 02:32:44 ----D---- L:\Documents and Settings\alx\Dati applicazioni\GHISLER
2011-03-12 02:32:44 ----A---- L:\WINDOWS\UC.PIF
2011-03-12 02:32:44 ----A---- L:\WINDOWS\RAR.PIF
2011-03-12 02:32:44 ----A---- L:\WINDOWS\PKZIP.PIF
2011-03-12 02:32:44 ----A---- L:\WINDOWS\PKUNZIP.PIF
2011-03-12 02:32:44 ----A---- L:\WINDOWS\NOCLOSE.PIF
2011-03-12 02:32:44 ----A---- L:\WINDOWS\LHA.PIF
2011-03-12 02:32:44 ----A---- L:\WINDOWS\ARJ.PIF
2011-03-12 01:14:55 ----D---- L:\Documents and Settings\alx\Dati applicazioni\Safer Networking
2011-03-09 19:22:45 ----D---- L:\WINDOWS\pss
2011-03-09 01:09:00 ----D---- L:\Documents and Settings\alx\Dati applicazioni\Uniblue
2011-03-08 22:32:39 ----D---- L:\Programmi\CCleaner
2011-03-07 23:01:11 ----D---- L:\Documents and Settings\All Users\Dati applicazioni\TEMP
2011-03-07 22:28:52 ----D---- L:\Programmi\VEXPLite
2011-03-07 21:53:02 ----ASH---- L:\hiberfil.sys
2011-02-27 19:42:22 ----A---- L:\WINDOWS\ib.ini
2011-02-27 19:42:19 ----A---- L:\WINDOWS\GetIe.dll
2011-02-27 19:42:15 ----D---- L:\Programmi\Jts
======List of files/folders modified in the last 2 months======
2011-03-14 01:08:59 ----D---- L:\WINDOWS\Prefetch
2011-03-14 01:08:48 ----RD---- L:\Programmi
2011-03-14 01:08:11 ----D---- L:\Documents and Settings\alx\Dati applicazioni\Skype
2011-03-14 00:49:35 ----D---- L:\WINDOWS\system32\drivers
2011-03-14 00:31:56 ----D---- L:\WINDOWS\Temp
2011-03-14 00:28:41 ----D---- L:\WINDOWS\Internet Logs
2011-03-13 23:40:14 ----SD---- L:\WINDOWS\Tasks
2011-03-13 22:53:46 ----D---- L:\WINDOWS
2011-03-13 22:53:45 ----D---- L:\WINDOWS\system32\CatRoot2
2011-03-13 22:53:41 ----D---- L:\WINDOWS\repair
2011-03-13 22:53:33 ----D---- L:\WINDOWS\Registration
2011-03-13 21:05:22 ----D---- L:\WINDOWS\system32
2011-03-13 21:05:21 ----SD---- L:\Documents and Settings\All Users\Dati applicazioni\Microsoft
2011-03-12 13:17:36 ----D---- L:\Programmi\Babylon
2011-03-12 12:07:47 ----A---- L:\WINDOWS\SchedLgU.Txt
2011-03-12 12:02:51 ----D---- L:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2011-03-10 00:27:21 ----D---- L:\WINDOWS\system32\drivers\etc
2011-03-10 00:06:22 ----D---- L:\Documents and Settings\alx\Dati applicazioni\skypePM
2011-03-09 20:53:04 ----SHD---- L:\WINDOWS\Installer
2011-03-09 20:45:15 ----D---- L:\Programmi\File comuni
2011-03-09 00:47:26 ----D---- L:\WINDOWS\Debug
2011-03-09 00:47:25 ----D---- L:\WINDOWS\Minidump
2011-03-08 20:36:03 ----SD---- L:\WINDOWS\Downloaded Program Files
2011-03-08 20:36:03 ----RSD---- L:\WINDOWS\Fonts
2011-03-07 23:07:24 ----D---- L:\WINDOWS\WinSxS
2011-03-07 21:29:08 ----A---- L:\WINDOWS\UEDIT32.INI
2011-03-07 04:27:09 ----RSHDC---- L:\WINDOWS\system32\dllcache
2011-03-07 01:56:23 ----A---- L:\WINDOWS\Wininit.ini
2011-03-06 19:49:20 ----D---- L:\QUARANTINE
2011-02-17 20:02:38 ----A---- L:\WINDOWS\NeroDigital.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 gagp30kx;Filtro Microsoft AGPv3.0 generico per piattaforme processore K8; L:\WINDOWS\system32\DRIVERS\gagp30kx.sys [2004-08-04 46464]
R0 hotcore3;hotcore3; L:\WINDOWS\system32\drivers\hotcore3.sys [2008-06-25 40368]
R0 RecAgent;RecAgent; L:\WINDOWS\system32\DRIVERS\RecAgent.sys [2004-08-03 13776]
R0 srescan;srescan; L:\WINDOWS\system32\ZoneLabs\srescan.sys [2008-02-27 51176]
R1 AmdK7;Driver del processore AMD K7; L:\WINDOWS\system32\DRIVERS\amdk7.sys [2004-08-19 41472]
R1 mferkdk;VSCore mferkdk; \??\L:\Programmi\McAfee\VirusScan Enterprise\mferkdk.sys []
R1 mfetdik;McAfee Inc.; L:\WINDOWS\system32\drivers\mfetdik.sys [2006-11-30 52136]
R1 Uim_IM;UIM Drive Backup Image Plugin; L:\WINDOWS\System32\Drivers\Uim_IM.sys [2007-11-06 131672]
R1 UimBus;Universal Image Mounter Controller; L:\WINDOWS\system32\DRIVERS\UimBus.sys [2007-11-06 32080]
R1 vsdatant;vsdatant; L:\WINDOWS\System32\vsdatant.sys [2008-07-09 394952]
R3 Afc;PPdus ASPI Shell; L:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ati2mtag;ati2mtag; L:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 cmuda;C-Media WDM Audio Interface; L:\WINDOWS\system32\drivers\cmuda.sys [2003-08-20 740992]
R3 hidusb;Driver di classe HID Microsoft; L:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-19 9600]
R3 mfeapfk;McAfee Inc.; L:\WINDOWS\system32\drivers\mfeapfk.sys [2006-11-30 64360]
R3 mfeavfk;McAfee Inc.; L:\WINDOWS\system32\drivers\mfeavfk.sys [2006-11-30 72264]
R3 mfebopk;McAfee Inc.; L:\WINDOWS\system32\drivers\mfebopk.sys [2006-11-30 34152]
R3 mfehidk;McAfee Inc.; L:\WINDOWS\system32\drivers\mfehidk.sys [2007-02-22 170408]
R3 MODEMCSA;Periferica filtro flusso Unimodem; L:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Driver di mouse HID; L:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-19 12160]
R3 Mtlmnt5;Mtlmnt5; L:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys [2004-08-03 126686]
R3 rtl8139;Driver NT scheda Fast Ethernet PCI Realtek basata su RTL8139; L:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 SISNIC;Driver per scheda Fast Ethernet PCI SiS; L:\WINDOWS\system32\DRIVERS\sisnic.sys [2004-08-03 32768]
R3 Slntamr;Smart Link 56K Modem Driver; L:\WINDOWS\system32\DRIVERS\slntamr.sys [2004-08-03 404990]
R3 SlWdmSup;SlWdmSup; L:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [2004-08-03 13240]
R3 SNPSTD3;USB PC Camera (SNPSTD3); L:\WINDOWS\system32\DRIVERS\snpstd3.sys [2007-03-26 10252544]
R3 USBSTOR;Driver archiviazione di massa USB; L:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 CCDECODE;Decoder sottotitoli codificati; L:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MSTEE;Convertitore a T/Sito a sito per flusso Microsoft; L:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 Mtlstrm;Mtlstrm; L:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [2004-08-03 1309184]
S3 NABTSFEC;NABTS/FEC VBI Codec; L:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connesione TV/Video Microsoft; L:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NtMtlFax;NtMtlFax; L:\WINDOWS\system32\DRIVERS\NtMtlFax.sys [2004-08-03 180360]
S3 SLIP;BDA Slip De-Framer; L:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 SlNtHal;SlNtHal; L:\WINDOWS\system32\DRIVERS\Slnthal.sys [2004-08-03 95424]
S3 streamip;BDA IPSink; L:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbscan;Driver scanner USB; L:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WSTCODEC;Codec World Standard Teletext; L:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 WS2IFSL;Ambiente di supporto del provider del Servizio Non-IFS di Windows Socket 2.0; L:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-19 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; L:\WINDOWS\system32\Ati2evxx.exe [2006-05-03 413696]
R2 ICQ Service;ICQ Service; L:\Programmi\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 JavaQuickStarterService;Java Quick Starter; L:\Programmi\Java\jre6\bin\jqs.exe [2010-09-15 153376]
R2 McAfeeFramework;McAfee Framework Service; L:\Programmi\McAfee\Common Framework\FrameworkService.exe [2006-12-19 104000]
R2 McShield;McAfee McShield; L:\Programmi\McAfee\VirusScan Enterprise\Mcshield.exe [2007-02-22 144960]
R2 McTaskManager;McAfee Task Manager; L:\Programmi\McAfee\VirusScan Enterprise\VsTskMgr.exe [2007-02-22 54872]
R2 SLService;SmartLinkService; L:\WINDOWS\system32\slserv.exe [2004-08-19 73796]
S2 ATI Smart;ATI Smart; L:\WINDOWS\system32\ati2sgag.exe [2006-05-03 520192]
S2 vsmon;TrueVector Internet Monitor; L:\WINDOWS\system32\ZoneLabs\vsmon.exe [2008-07-09 75304]
S3 aspnet_state;ASP.NET State Service; L:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; l:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; L:\Programmi\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; L:\Programmi\File comuni\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; L:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
in next reply the content of info.txt; the computer is apparently performing well (like before)