Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

virus!!!

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

virus!!!

Messaggioda pmarco66 » mar gen 10, 2012 1:26 pm

buongiorno
ho beccato un virus con il mio portatile (windows 7 64 bit)
mi ha disabilitato sophos e non mi permette il riavvio in modalita' provvisoria; i disci di avvio di avira e di kaspersky (che molte volte mi hanno ripulito per bene i pc infetti) si bloccano e non riescono a fare la scansione.
mi potete aiutare?
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda Ginho » mar gen 10, 2012 2:07 pm

Prova ad utilizzare Microsoft Standalone System Sweeper.

Trovi una guida qui: http://www.MegaLab.it/7435/come-ripulire-un-pc-infetto-con-microsoft-standalone-system-sweeper

Segui anche le indicazioni di questo post: http://www.MegaLab.it/forum/topic65911.html

[^]
App: https://play.google.com/store/apps/details?id=it.economiasprint
Avatar utente
Ginho
Silver Member
Silver Member
 
Messaggi: 1344
Iscritto il: gio lug 21, 2011 12:28 pm
Località: Ferrara

Re: virus!!!

Messaggioda hashcat » mar gen 10, 2012 2:52 pm

La procedura di analisi, disinfezione e pulizia che ti consiglio di seguire è la seguente:


  1. HitmanPro (Richiede Internet) (Rilevamento e rimozione) (Scansioni molto veloci)
  2. TDSSKiller (Rilevazione e rimozione di determinati rootkit/bootkit)
  3. Combofix (Analisi avanzata e rimozione)
  4. DDS (Analisi veloce non invasiva)
  5. OTL (Analisi dettagliata)


Termina tutti processi in esecuzione con RKill

Scarica HitmanPro e configuralo così:
Immagine
Fai una Scansione Completa, attiva la licenza di prova e rimuovi tutte le minacce. Al termine della scansione salva il log ed inseriscilo nel tuo prossimo messaggio:
Immagine

Istruzioni d'uso TDSSKiller:

  1. Scarica TDSSKiller da qui
  2. Esegui TDSSKiller e clicca su "Start Scan"
  3. Al termine della scansione verrà mostrata una schermata con i rilevamenti
  4. Seleziona l'opzione "Cure" per i rilevamenti "malicious" e l'opzione "Skip" per quelli "Suspicious"
  5. Clicca su Next/Continue per applicare le azioni
  6. Per portare a termine la disinfezione TDSSKiller potrebbe richiedere un riavvio del computer
  7. Al termine della procedura posta il log di TDSSKiller che si trova in C:\TDSSKillerxxxx


Istruzioni d'utilizzo di Combofix:

  1. Scaricare Combofix da qui
  2. Disconnettere il computer da Internet
  3. Disattivare o terminare tutte le protezioni in tempo reale di programmi anti-spyware, antivirus, anti-malware, che possono influenzare ComboFix
  4. Fare doppio clic sul file
  5. Non utilizzare il computer durante l'esecuzione di Combofix (nemmeno mouse e tastiera)
  6. Quando Combofix finirà, salverà un log in C:\ComboFix.txt
  7. Inserisci il log di Combofix nel tuo prossimo messaggio
  8. Se il log di Combofix dovesse essere molto lungo caricalo su MediaFire

Per informazioni aggiuntive leggere la guida:
http://www.bleepingcomputer.com/combofix/it/come-usare-combofix


Istruzioni d'uso DDS:

  1. Scarica DDS da qui
  2. Disabilita temporaneamente tutte le protezioni in tempo reale di programmi anti-spyware, antivirus, anti-malware, che possono influenzare DDS
  3. Avvialo facendo doppio click
  4. Aspetta fino al completamento della scansione
  5. Al termine della scansione verranno generati due log e appariranno due finestre del Blocco Note
  6. Salva il log DDS come DDS.txt sul Desktop ed includilo nel tuo prossimo messaggio
  7. Salva il log Attach come Attach.txt sul Desktop ed includilo nel tuo prossimo messaggio
  8. Se i log dovessero eccedere il numero massimo di caratteri consentiti per messaggio caricali su MediaFire


E un log di OTL:

  1. Scarica OTL da qui
  2. Disattivare o terminare tutte le protezioni in tempo reale di programmi anti-spyware, antivirus, anti-malware, che possono influenzare OTL
  3. Avviare OTL mediante doppio click
  4. Quando apparirà la schermata di OTL regolare le impostazioni come segue:
    Immagine
  5. Cliccare su Run Scan per avviare la scansione
  6. Non utilizzare il computer durante l'esecuzione di OTL
  7. Al termine della scansione verranno generati due log e appariranno due finestre del Blocco Note
  8. Salva il log OTL come OTL.txt sul Desktop ed includilo nel tuo prossimo messaggio
  9. Salva il log Extra come Extra.txt sul Desktop ed includilo nel tuo prossimo messaggio
  10. Se i log dovessero eccedere il numero massimo di caratteri consentiti per messaggio caricali su MediaFire

[^] [^]
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm


Re: virus!!!

Messaggioda ste_95 » mar gen 10, 2012 3:57 pm

Ragazzi! È quasi sicuramente un caso di bagle, e tutti i software di sicurezza proposti falliranno di nuovo quasi sicuramente!
Questa la procedura di rimozione http://www.MegaLab.it/3724/il-worm-bagl ... -rimozione
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Re: virus!!!

Messaggioda hashcat » mar gen 10, 2012 4:59 pm

ste_95 ha scritto:Ragazzi! È quasi sicuramente un caso di bagle, e tutti i software di sicurezza proposti falliranno di nuovo quasi sicuramente!
Questa la procedura di rimozione http://www.MegaLab.it/3724/il-worm-bagl ... -rimozione

Effettivamente non ci avevo pensato [B)]

La procedura che ho inserito potrebbe comunque funzionare, se così non fosse utilizza FindyKill (il download presente nell'articolo non è funzionante) [^]
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: virus!!!

Messaggioda pmarco66 » mer gen 11, 2012 12:57 pm

scarico findykill, lo avvio, mi compare la schermata ma non mi da la lista dei comandi...
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda hashcat » mer gen 11, 2012 1:04 pm

pmarco66 ha scritto:scarico findykill, lo avvio, mi compare la schermata ma non mi da la lista dei comandi...

Prova a rinominarlo in modo casuale ed eseguilo come amministratore.
Hai provato anche gli altri strumenti?

P.S.: Quando appare la schermata iniziale prova a premere invio.
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: virus!!!

Messaggioda pmarco66 » mer gen 11, 2012 1:34 pm

lo faccio ma non succede nulla
con altri tools niente di nuovo
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda hashcat » mer gen 11, 2012 2:27 pm

pmarco66 ha scritto:lo faccio ma non succede nulla
con altri tools niente di nuovo

Hai seguito la procedura che avevo indicato qui (HitmanPro etc.)?
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: virus!!!

Messaggioda pmarco66 » dom gen 15, 2012 10:27 pm

scansione con findykill e anche gli altri programmi effettuata ma non trovato malware però' il pc continua ad avere sophos disattivato ed avvio in modalita' provvisoria non funzionante
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda hashcat » lun gen 16, 2012 8:49 am

pmarco66 ha scritto:scansione con findykill e anche gli altri programmi effettuata ma non trovato malware però' il pc continua ad avere sophos disattivato ed avvio in modalita' provvisoria non funzionante

Come ti avevo richiesto desiderei leggere i log generati da questi prodotti per aiutarti con la rimozione

[grazie]


P.S.: Puoi ripristinare la modalità provvisoria con questo programma:

http://www.softpedia.com/get/Antivirus/SMFixer.shtml
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: virus!!!

Messaggioda pmarco66 » mar gen 17, 2012 11:41 pm

############################## | FindyKill V5.056 |

# User : emarco (Administrators) # PCMARCO2
# Update on 20/11/2011 by El Desaparecido
# Start at: 23:30:55 | 17/01/2012
# Website : http://eldesaparecido.com/
# Contact : contact@eldesaparecido.com

# Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
# Microsoft Windows 7 Professional (6.1.7601 64-bit) # Service Pack 1
# Internet Explorer 9.0.8112.16421
# Windows Firewall Status : Enabled

# C:\ # Disco rigido locale # 78,12 Go (26,47 Go free) # NTFS
# D:\ # Disco rigido locale # 29,49 Go (1,42 Go free) # NTFS
# E:\ # Disco rigido locale # 125,27 Go (36,76 Go free) [Storage] # NTFS
# F:\ # Disco CD-ROM

################## | Infected processes stopped |


################## | Infected File |


################## | Reference Bagle MD5 ... |


################## | MD5 ... |


################## | Bagle Trace ... |


################## | Crack .... |


################## | Registry |

[HKCU\Software\Classes\ed2k]
[HKCR\ed2k]

################## | State |

# Showing of hidden files : OK

# Safe boot mode : OK

# (!) Uac = 0x0 ( Good = 0x1 | Bad = 0x0 )

# Ndisuio ( NDIS User Mode ) -> Start = 3 ( Good = 3 | Bad = 4 )

# EapHost ( Extensible Authentication Protocol Host ) -> Start = 3 ( Good = 2 | Bad = 4 )

# WwanSvc ( AutoConfig Service WWAN ) -> Start = 3 ( Good = 2 | Bad = 4 )

# MpsSvc ( Windows Firewall ) -> Start = 2 ( Good = 2 | Bad = 4 )

# SharedAccess ( Windows Firewall - Internet Connection Sharing ) -> Start = 2 ( Good = 2 | Bad = 4 )

# windefend ( Windows Defender ) -> Start = 2 ( Good = 2 | Bad = 4 )

# wuauserv ( Windows Update ) -> Start = 2 ( Good = 2 | Bad = 4 )

# wscsvc ( Windows Security Center ) -> Start = 2 ( Good = 2 | Bad = 4 )


################## | End of Report # FindyKill V5.056 ! |
Ultima modifica di The Doctor il mer gen 18, 2012 8:37 am, modificato 1 volta in totale.
Motivazione: Inserito TAG MEMO
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda pmarco66 » mar gen 17, 2012 11:54 pm

<?xml version="1.0"?>
-<Log filesProcessed="33116" timeSpentInSecs="168" date="2012-01-17T23:49:03" version="3.6.0.138" scan="Normal" computer="PCMARCO2">-<Item status="None" score="43.0" type="Suspicious"><File hash="92B1B2BAF33F9DFA77AC8D191851A760B897681A37C965F3ED9D989EAEB18785" path="C:\Program Files (x86)\BitTorrent\BitTorrent.exe"/>-<References><File path="C:\ProgramData\Microsoft\Windows\Start Menu\BitTorrent.lnk"/><Key path="HKU\S-1-5-21-3815140021-4139662573-755630772-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files (x86)\BitTorrent\BitTorrent.exe"/></References></Item></Log>
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda pmarco66 » mer gen 18, 2012 12:08 am

00:06:33.0798 5232 TDSS rootkit removing tool 2.7.3.0 Jan 16 2012 18:53:41
00:06:33.0892 5232 ============================================================
00:06:33.0892 5232 Current date / time: 2012/01/18 00:06:33.0892
00:06:33.0892 5232 SystemInfo:
00:06:33.0892 5232
00:06:33.0907 5232 OS Version: 6.1.7601 ServicePack: 1.0
00:06:33.0907 5232 Product type: Workstation
00:06:33.0907 5232 ComputerName: PCMARCO2
00:06:33.0907 5232 UserName: emarco
00:06:33.0907 5232 Windows directory: C:\Windows
00:06:33.0907 5232 System windows directory: C:\Windows
00:06:33.0907 5232 Running under WOW64
00:06:33.0907 5232 Processor architecture: Intel x64
00:06:33.0907 5232 Number of processors: 4
00:06:33.0907 5232 Page size: 0x1000
00:06:33.0907 5232 Boot type: Normal boot
00:06:33.0907 5232 ============================================================
00:06:34.0828 5232 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
00:06:34.0937 5232 Initialize success
00:06:52.0893 5820 ============================================================
00:06:52.0893 5820 Scan started
00:06:52.0893 5820 Mode: Manual;
00:06:52.0893 5820 ============================================================
00:06:53.0595 5820 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
00:06:53.0610 5820 1394ohci - ok
00:06:53.0641 5820 Acceler (627371b2d48f64cecc4d019114fb140d) C:\Windows\system32\DRIVERS\Accelern.sys
00:06:53.0657 5820 Acceler - ok
00:06:53.0704 5820 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
00:06:53.0719 5820 ACPI - ok
00:06:53.0751 5820 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
00:06:53.0751 5820 AcpiPmi - ok
00:06:53.0813 5820 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
00:06:53.0813 5820 adp94xx - ok
00:06:53.0829 5820 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
00:06:53.0829 5820 adpahci - ok
00:06:53.0844 5820 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
00:06:53.0844 5820 adpu320 - ok
00:06:53.0875 5820 Afc - ok
00:06:53.0922 5820 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
00:06:53.0922 5820 AFD - ok
00:06:53.0953 5820 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
00:06:53.0953 5820 agp440 - ok
00:06:53.0969 5820 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
00:06:53.0969 5820 aliide - ok
00:06:53.0985 5820 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
00:06:53.0985 5820 amdide - ok
00:06:54.0000 5820 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
00:06:54.0000 5820 AmdK8 - ok
00:06:54.0016 5820 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
00:06:54.0016 5820 AmdPPM - ok
00:06:54.0063 5820 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
00:06:54.0063 5820 amdsata - ok
00:06:54.0078 5820 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
00:06:54.0078 5820 amdsbs - ok
00:06:54.0125 5820 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
00:06:54.0125 5820 amdxata - ok
00:06:54.0172 5820 ApfiltrService (8655a2983a86d6675135b1ff6892055d) C:\Windows\system32\DRIVERS\Apfiltr.sys
00:06:54.0172 5820 ApfiltrService - ok
00:06:54.0203 5820 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
00:06:54.0203 5820 AppID - ok
00:06:54.0234 5820 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
00:06:54.0234 5820 arc - ok
00:06:54.0250 5820 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
00:06:54.0250 5820 arcsas - ok
00:06:54.0297 5820 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
00:06:54.0297 5820 AsyncMac - ok
00:06:54.0312 5820 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
00:06:54.0312 5820 atapi - ok
00:06:54.0343 5820 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
00:06:54.0343 5820 b06bdrv - ok
00:06:54.0406 5820 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
00:06:54.0406 5820 b57nd60a - ok
00:06:54.0421 5820 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
00:06:54.0421 5820 Beep - ok
00:06:54.0484 5820 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
00:06:54.0484 5820 blbdrive - ok
00:06:54.0531 5820 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
00:06:54.0531 5820 bowser - ok
00:06:54.0546 5820 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
00:06:54.0546 5820 BrFiltLo - ok
00:06:54.0546 5820 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
00:06:54.0546 5820 BrFiltUp - ok
00:06:54.0577 5820 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
00:06:54.0593 5820 BridgeMP - ok
00:06:54.0609 5820 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
00:06:54.0609 5820 Brserid - ok
00:06:54.0624 5820 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
00:06:54.0624 5820 BrSerWdm - ok
00:06:54.0624 5820 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
00:06:54.0624 5820 BrUsbMdm - ok
00:06:54.0640 5820 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
00:06:54.0640 5820 BrUsbSer - ok
00:06:54.0687 5820 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
00:06:54.0687 5820 BthEnum - ok
00:06:54.0718 5820 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
00:06:54.0718 5820 BTHMODEM - ok
00:06:54.0733 5820 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
00:06:54.0733 5820 BthPan - ok
00:06:54.0780 5820 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys
00:06:54.0796 5820 BTHPORT - ok
00:06:54.0827 5820 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys
00:06:54.0827 5820 BTHUSB - ok
00:06:54.0843 5820 catchme - ok
00:06:54.0874 5820 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
00:06:54.0874 5820 cdfs - ok
00:06:54.0936 5820 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
00:06:54.0936 5820 cdrom - ok
00:06:54.0952 5820 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
00:06:54.0952 5820 circlass - ok
00:06:54.0983 5820 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
00:06:54.0983 5820 CLFS - ok
00:06:55.0045 5820 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
00:06:55.0045 5820 CmBatt - ok
00:06:55.0061 5820 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
00:06:55.0061 5820 cmdide - ok
00:06:55.0092 5820 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
00:06:55.0108 5820 CNG - ok
00:06:55.0123 5820 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
00:06:55.0123 5820 Compbatt - ok
00:06:55.0170 5820 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
00:06:55.0170 5820 CompositeBus - ok
00:06:55.0186 5820 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
00:06:55.0186 5820 crcdisk - ok
00:06:55.0264 5820 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
00:06:55.0264 5820 CSC - ok
00:06:55.0295 5820 CtClsFlt - ok
00:06:55.0342 5820 CVirtA (44bddeb03c84a1c993c992ffb5700357) C:\Windows\system32\DRIVERS\CVirtA64.sys
00:06:55.0342 5820 CVirtA - ok
00:06:55.0389 5820 CVPNDRVA (79af0e203d089af442a3f70ed00a37fb) C:\Windows\system32\Drivers\CVPNDRVA.sys
00:06:55.0389 5820 CVPNDRVA - ok
00:06:55.0435 5820 cvusbdrv (a84caae89b487931200b969d94018afa) C:\Windows\system32\Drivers\cvusbdrv.sys
00:06:55.0435 5820 cvusbdrv - ok
00:06:55.0498 5820 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
00:06:55.0498 5820 DfsC - ok
00:06:55.0576 5820 DgiVecp (cfbb4907c7542180b5e0282301240006) C:\Windows\system32\Drivers\DgiVecp.sys
00:06:55.0576 5820 DgiVecp - ok
00:06:55.0623 5820 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
00:06:55.0623 5820 discache - ok
00:06:55.0669 5820 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
00:06:55.0669 5820 Disk - ok
00:06:55.0701 5820 DNE (05cb5910b3ca6019fc3cca815ee06ffb) C:\Windows\system32\DRIVERS\dne64x.sys
00:06:55.0701 5820 DNE - ok
00:06:55.0747 5820 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
00:06:55.0857 5820 drmkaud - ok
00:06:56.0169 5820 DVMIO (ad00375d9aba8db72d0e38129af0277a) C:\Program Files (x86)\Dell\Reader 2.1\dvmio_x64.sys
00:06:56.0169 5820 DVMIO - ok
00:06:56.0231 5820 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
00:06:56.0262 5820 DXGKrnl - ok
00:06:56.0309 5820 e1kexpress (60c5b36e07be8b3af3911c3d10303cfe) C:\Windows\system32\DRIVERS\e1k62x64.sys
00:06:56.0309 5820 e1kexpress - ok
00:06:56.0403 5820 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
00:06:56.0465 5820 ebdrv - ok
00:06:56.0621 5820 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
00:06:56.0637 5820 elxstor - ok
00:06:56.0668 5820 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
00:06:56.0668 5820 ErrDev - ok
00:06:56.0699 5820 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
00:06:56.0699 5820 exfat - ok
00:06:56.0730 5820 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
00:06:56.0730 5820 fastfat - ok
00:06:56.0761 5820 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
00:06:56.0761 5820 fdc - ok
00:06:56.0793 5820 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
00:06:56.0793 5820 FileInfo - ok
00:06:56.0808 5820 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
00:06:56.0808 5820 Filetrace - ok
00:06:56.0824 5820 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
00:06:56.0824 5820 flpydisk - ok
00:06:56.0855 5820 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
00:06:56.0871 5820 FltMgr - ok
00:06:56.0886 5820 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
00:06:56.0886 5820 FsDepends - ok
00:06:56.0917 5820 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
00:06:56.0917 5820 Fs_Rec - ok
00:06:56.0964 5820 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
00:06:56.0964 5820 fvevol - ok
00:06:56.0995 5820 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
00:06:56.0995 5820 gagp30kx - ok
00:06:57.0073 5820 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
00:06:57.0073 5820 hcw85cir - ok
00:06:57.0120 5820 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
00:06:57.0120 5820 HdAudAddService - ok
00:06:57.0151 5820 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
00:06:57.0151 5820 HDAudBus - ok
00:06:57.0198 5820 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
00:06:57.0198 5820 HECIx64 - ok
00:06:57.0214 5820 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
00:06:57.0214 5820 HidBatt - ok
00:06:57.0229 5820 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
00:06:57.0229 5820 HidBth - ok
00:06:57.0229 5820 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
00:06:57.0245 5820 HidIr - ok
00:06:57.0261 5820 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
00:06:57.0261 5820 HidUsb - ok
00:06:57.0292 5820 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
00:06:57.0307 5820 HpSAMD - ok
00:06:57.0354 5820 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
00:06:57.0370 5820 HTTP - ok
00:06:57.0417 5820 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
00:06:57.0417 5820 hwpolicy - ok
00:06:57.0432 5820 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
00:06:57.0448 5820 i8042prt - ok
00:06:57.0495 5820 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
00:06:57.0495 5820 iaStorV - ok
00:06:57.0713 5820 igfx (31569a2e836c12014148bf7342716946) C:\Windows\system32\DRIVERS\igdkmd64.sys
00:06:57.0760 5820 igfx - ok
00:06:57.0791 5820 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
00:06:57.0791 5820 iirsp - ok
00:06:57.0822 5820 Impcd (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
00:06:57.0822 5820 Impcd - ok
00:06:57.0869 5820 IntcDAud (03c74719d48056a1078f3a51ceb76baa) C:\Windows\system32\DRIVERS\IntcDAud.sys
00:06:57.0869 5820 IntcDAud - ok
00:06:57.0900 5820 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
00:06:57.0900 5820 intelide - ok
00:06:57.0931 5820 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
00:06:57.0931 5820 intelppm - ok
00:06:57.0963 5820 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
00:06:57.0978 5820 IpFilterDriver - ok
00:06:57.0994 5820 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
00:06:57.0994 5820 IPMIDRV - ok
00:06:58.0041 5820 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
00:06:58.0041 5820 IPNAT - ok
00:06:58.0072 5820 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
00:06:58.0072 5820 IRENUM - ok
00:06:58.0103 5820 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
00:06:58.0103 5820 isapnp - ok
00:06:58.0119 5820 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
00:06:58.0134 5820 iScsiPrt - ok
00:06:58.0165 5820 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
00:06:58.0165 5820 kbdclass - ok
00:06:58.0197 5820 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
00:06:58.0197 5820 kbdhid - ok
00:06:58.0243 5820 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
00:06:58.0243 5820 KSecDD - ok
00:06:58.0290 5820 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
00:06:58.0290 5820 KSecPkg - ok
00:06:58.0306 5820 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
00:06:58.0306 5820 ksthunk - ok
00:06:58.0368 5820 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
00:06:58.0368 5820 lltdio - ok
00:06:58.0431 5820 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
00:06:58.0431 5820 LSI_FC - ok
00:06:58.0446 5820 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
00:06:58.0446 5820 LSI_SAS - ok
00:06:58.0446 5820 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
00:06:58.0462 5820 LSI_SAS2 - ok
00:06:58.0462 5820 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
00:06:58.0477 5820 LSI_SCSI - ok
00:06:58.0509 5820 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
00:06:58.0509 5820 luafv - ok
00:06:58.0571 5820 MBAMProtector (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys
00:06:58.0571 5820 MBAMProtector - ok
00:06:58.0602 5820 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
00:06:58.0602 5820 megasas - ok
00:06:58.0618 5820 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
00:06:58.0618 5820 MegaSR - ok
00:06:58.0649 5820 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
00:06:58.0649 5820 Modem - ok
00:06:58.0665 5820 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
00:06:58.0665 5820 monitor - ok
00:06:58.0680 5820 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
00:06:58.0680 5820 mouclass - ok
00:06:58.0711 5820 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
00:06:58.0711 5820 mouhid - ok
00:06:58.0743 5820 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
00:06:58.0743 5820 mountmgr - ok
00:06:58.0774 5820 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
00:06:58.0774 5820 mpio - ok
00:06:58.0805 5820 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
00:06:58.0805 5820 mpsdrv - ok
00:06:58.0836 5820 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
00:06:58.0836 5820 MRxDAV - ok
00:06:58.0883 5820 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
00:06:58.0883 5820 mrxsmb - ok
00:06:58.0930 5820 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
00:06:58.0930 5820 mrxsmb10 - ok
00:06:58.0945 5820 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
00:06:58.0945 5820 mrxsmb20 - ok
00:06:58.0977 5820 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
00:06:58.0977 5820 msahci - ok
00:06:59.0008 5820 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
00:06:59.0008 5820 msdsm - ok
00:06:59.0039 5820 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
00:06:59.0039 5820 Msfs - ok
00:06:59.0086 5820 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
00:06:59.0086 5820 mshidkmdf - ok
00:06:59.0101 5820 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
00:06:59.0101 5820 msisadrv - ok
00:06:59.0148 5820 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
00:06:59.0148 5820 MSKSSRV - ok
00:06:59.0179 5820 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
00:06:59.0195 5820 MSPCLOCK - ok
00:06:59.0226 5820 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
00:06:59.0226 5820 MSPQM - ok
00:06:59.0273 5820 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
00:06:59.0273 5820 MsRPC - ok
00:06:59.0304 5820 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
00:06:59.0304 5820 mssmbios - ok
00:06:59.0320 5820 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
00:06:59.0320 5820 MSTEE - ok
00:06:59.0335 5820 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
00:06:59.0335 5820 MTConfig - ok
00:06:59.0382 5820 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
00:06:59.0382 5820 Mup - ok
00:06:59.0445 5820 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
00:06:59.0445 5820 NativeWifiP - ok
00:06:59.0538 5820 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
00:06:59.0554 5820 NDIS - ok
00:06:59.0601 5820 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
00:06:59.0601 5820 NdisCap - ok
00:06:59.0632 5820 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
00:06:59.0632 5820 NdisTapi - ok
00:06:59.0679 5820 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
00:06:59.0679 5820 Ndisuio - ok
00:06:59.0710 5820 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
00:06:59.0710 5820 NdisWan - ok
00:06:59.0757 5820 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
00:06:59.0757 5820 NDProxy - ok
00:06:59.0835 5820 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
00:06:59.0835 5820 NetBIOS - ok
00:06:59.0866 5820 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
00:06:59.0881 5820 NetBT - ok
00:07:00.0069 5820 NETw5s64 (4d85a450edef10c38882182753a49aae) C:\Windows\system32\DRIVERS\NETw5s64.sys
00:07:00.0178 5820 NETw5s64 - ok
00:07:00.0287 5820 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
00:07:00.0287 5820 nfrd960 - ok
00:07:00.0318 5820 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
00:07:00.0318 5820 Npfs - ok
00:07:00.0349 5820 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
00:07:00.0349 5820 nsiproxy - ok
00:07:00.0412 5820 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
00:07:00.0443 5820 Ntfs - ok
00:07:00.0459 5820 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
00:07:00.0459 5820 Null - ok
00:07:00.0505 5820 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
00:07:00.0505 5820 nvraid - ok
00:07:00.0552 5820 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
00:07:00.0552 5820 nvstor - ok
00:07:00.0599 5820 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
00:07:00.0599 5820 nv_agp - ok
00:07:00.0630 5820 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
00:07:00.0630 5820 ohci1394 - ok
00:07:00.0693 5820 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
00:07:00.0693 5820 Parport - ok
00:07:00.0724 5820 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
00:07:00.0724 5820 partmgr - ok
00:07:00.0771 5820 PBADRV (363b3f857abee85767e01e3044c539cd) C:\Windows\system32\DRIVERS\PBADRV.sys
00:07:00.0786 5820 PBADRV - ok
00:07:00.0849 5820 pccsmcfd (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
00:07:00.0849 5820 pccsmcfd - ok
00:07:00.0864 5820 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
00:07:00.0864 5820 pci - ok
00:07:00.0880 5820 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
00:07:00.0880 5820 pciide - ok
00:07:00.0911 5820 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
00:07:00.0911 5820 pcmcia - ok
00:07:00.0927 5820 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
00:07:00.0927 5820 pcw - ok
00:07:00.0958 5820 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
00:07:00.0973 5820 PEAUTH - ok
00:07:01.0051 5820 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
00:07:01.0051 5820 PptpMiniport - ok
00:07:01.0067 5820 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
00:07:01.0067 5820 Processor - ok
00:07:01.0114 5820 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
00:07:01.0114 5820 Psched - ok
00:07:01.0192 5820 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
00:07:01.0223 5820 ql2300 - ok
00:07:01.0239 5820 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
00:07:01.0239 5820 ql40xx - ok
00:07:01.0270 5820 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
00:07:01.0270 5820 QWAVEdrv - ok
00:07:01.0285 5820 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
00:07:01.0285 5820 RasAcd - ok
00:07:01.0332 5820 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
00:07:01.0332 5820 RasAgileVpn - ok
00:07:01.0363 5820 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
00:07:01.0363 5820 Rasl2tp - ok
00:07:01.0410 5820 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
00:07:01.0410 5820 RasPppoe - ok
00:07:01.0457 5820 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
00:07:01.0457 5820 RasSstp - ok
00:07:01.0504 5820 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
00:07:01.0504 5820 rdbss - ok
00:07:01.0535 5820 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
00:07:01.0535 5820 rdpbus - ok
00:07:01.0551 5820 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
00:07:01.0551 5820 RDPCDD - ok
00:07:01.0597 5820 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
00:07:01.0597 5820 RDPDR - ok
00:07:01.0629 5820 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
00:07:01.0629 5820 RDPENCDD - ok
00:07:01.0691 5820 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
00:07:01.0691 5820 RDPREFMP - ok
00:07:01.0722 5820 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
00:07:01.0722 5820 RDPWD - ok
00:07:01.0753 5820 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
00:07:01.0753 5820 rdyboost - ok
00:07:01.0800 5820 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
00:07:01.0800 5820 RFCOMM - ok
00:07:01.0847 5820 risdpcie (91c2ae052652e7abd88155f11d667ed2) C:\Windows\system32\DRIVERS\risdpe64.sys
00:07:01.0847 5820 risdpcie - ok
00:07:01.0878 5820 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
00:07:01.0878 5820 rspndr - ok
00:07:01.0925 5820 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
00:07:01.0925 5820 s3cap - ok
00:07:02.0081 5820 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Users\emarco\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS
00:07:02.0081 5820 SASDIFSV - ok
00:07:02.0128 5820 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Users\emarco\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS
00:07:02.0128 5820 SASKUTIL - ok
00:07:02.0190 5820 SAVOnAccess (d9057e8ca97628e275979a09ea66b34b) C:\Windows\system32\DRIVERS\savonaccess.sys
00:07:02.0190 5820 SAVOnAccess - ok
00:07:02.0221 5820 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
00:07:02.0221 5820 sbp2port - ok
00:07:02.0253 5820 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
00:07:02.0253 5820 scfilter - ok
00:07:02.0284 5820 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys
00:07:02.0284 5820 sdbus - ok
00:07:02.0315 5820 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
00:07:02.0315 5820 secdrv - ok
00:07:02.0393 5820 Sentinel64 (255476b54c82a89416efdf09fd62f107) C:\Windows\System32\Drivers\Sentinel64.sys
00:07:02.0393 5820 Sentinel64 - ok
00:07:02.0455 5820 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
00:07:02.0455 5820 Serenum - ok
00:07:02.0471 5820 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
00:07:02.0487 5820 Serial - ok
00:07:02.0518 5820 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
00:07:02.0518 5820 sermouse - ok
00:07:02.0565 5820 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
00:07:02.0565 5820 sffdisk - ok
00:07:02.0580 5820 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
00:07:02.0580 5820 sffp_mmc - ok
00:07:02.0596 5820 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
00:07:02.0596 5820 sffp_sd - ok
00:07:02.0627 5820 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
00:07:02.0627 5820 sfloppy - ok
00:07:02.0658 5820 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
00:07:02.0658 5820 SiSRaid2 - ok
00:07:02.0689 5820 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
00:07:02.0689 5820 SiSRaid4 - ok
00:07:02.0705 5820 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
00:07:02.0705 5820 Smb - ok
00:07:02.0752 5820 SNTUSB64 (2d5576c01c8a34aa614870e745fe8f19) C:\Windows\system32\DRIVERS\SNTUSB64.SYS
00:07:02.0752 5820 SNTUSB64 - ok
00:07:02.0814 5820 SophosBootDriver (69fbe35a8165adbc313aa7f64b868ca1) C:\Windows\system32\DRIVERS\SophosBootDriver.sys
00:07:02.0814 5820 SophosBootDriver - ok
00:07:02.0830 5820 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
00:07:02.0830 5820 spldr - ok
00:07:02.0877 5820 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
00:07:02.0892 5820 srv - ok
00:07:02.0908 5820 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
00:07:02.0923 5820 srv2 - ok
00:07:02.0939 5820 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
00:07:02.0939 5820 srvnet - ok
00:07:02.0986 5820 SSPORT (0211ab46b73a2623b86c1cfcb30579ab) C:\Windows\system32\Drivers\SSPORT.sys
00:07:03.0001 5820 SSPORT - ok
00:07:03.0017 5820 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
00:07:03.0017 5820 stexstor - ok
00:07:03.0048 5820 StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys
00:07:03.0048 5820 StillCam - ok
00:07:03.0095 5820 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
00:07:03.0095 5820 storflt - ok
00:07:03.0126 5820 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
00:07:03.0126 5820 storvsc - ok
00:07:03.0142 5820 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
00:07:03.0142 5820 swenum - ok
00:07:03.0251 5820 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
00:07:03.0267 5820 Tcpip - ok
00:07:03.0345 5820 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
00:07:03.0360 5820 TCPIP6 - ok
00:07:03.0423 5820 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
00:07:03.0423 5820 tcpipreg - ok
00:07:03.0454 5820 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
00:07:03.0454 5820 TDPIPE - ok
00:07:03.0469 5820 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
00:07:03.0469 5820 TDTCP - ok
00:07:03.0501 5820 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
00:07:03.0516 5820 tdx - ok
00:07:03.0532 5820 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
00:07:03.0532 5820 TermDD - ok
00:07:03.0579 5820 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
00:07:03.0579 5820 tssecsrv - ok
00:07:03.0610 5820 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
00:07:03.0610 5820 TsUsbFlt - ok
00:07:03.0657 5820 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
00:07:03.0672 5820 tunnel - ok
00:07:03.0672 5820 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
00:07:03.0672 5820 uagp35 - ok
00:07:03.0719 5820 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
00:07:03.0735 5820 udfs - ok
00:07:03.0781 5820 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
00:07:03.0781 5820 uliagpkx - ok
00:07:03.0813 5820 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
00:07:03.0813 5820 umbus - ok
00:07:03.0844 5820 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
00:07:03.0844 5820 UmPass - ok
00:07:03.0891 5820 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
00:07:03.0891 5820 usbccgp - ok
00:07:03.0937 5820 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
00:07:03.0937 5820 usbcir - ok
00:07:03.0969 5820 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
00:07:03.0969 5820 usbehci - ok
00:07:03.0984 5820 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
00:07:04.0000 5820 usbhub - ok
00:07:04.0031 5820 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
00:07:04.0031 5820 usbohci - ok
00:07:04.0062 5820 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
00:07:04.0062 5820 usbprint - ok
00:07:04.0109 5820 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
00:07:04.0109 5820 usbscan - ok
00:07:04.0140 5820 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
00:07:04.0156 5820 USBSTOR - ok
00:07:04.0156 5820 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
00:07:04.0156 5820 usbuhci - ok
00:07:04.0203 5820 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
00:07:04.0218 5820 usbvideo - ok
00:07:04.0234 5820 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
00:07:04.0234 5820 vdrvroot - ok
00:07:04.0265 5820 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
00:07:04.0265 5820 vga - ok
00:07:04.0296 5820 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
00:07:04.0296 5820 VgaSave - ok
00:07:04.0327 5820 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
00:07:04.0327 5820 vhdmp - ok
00:07:04.0343 5820 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
00:07:04.0343 5820 viaide - ok
00:07:04.0374 5820 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
00:07:04.0390 5820 vmbus - ok
00:07:04.0421 5820 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
00:07:04.0421 5820 VMBusHID - ok
00:07:04.0452 5820 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
00:07:04.0452 5820 volmgr - ok
00:07:04.0499 5820 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
00:07:04.0499 5820 volmgrx - ok
00:07:04.0530 5820 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
00:07:04.0530 5820 volsnap - ok
00:07:04.0577 5820 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
00:07:04.0577 5820 vsmraid - ok
00:07:04.0593 5820 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
00:07:04.0593 5820 vwifibus - ok
00:07:04.0624 5820 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
00:07:04.0624 5820 vwififlt - ok
00:07:04.0639 5820 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
00:07:04.0639 5820 vwifimp - ok
00:07:04.0655 5820 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
00:07:04.0655 5820 WacomPen - ok
00:07:04.0702 5820 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
00:07:04.0702 5820 WANARP - ok
00:07:04.0717 5820 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
00:07:04.0717 5820 Wanarpv6 - ok
00:07:04.0764 5820 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
00:07:04.0764 5820 Wd - ok
00:07:04.0811 5820 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
00:07:04.0811 5820 Wdf01000 - ok
00:07:04.0873 5820 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
00:07:04.0873 5820 WfpLwf - ok
00:07:04.0905 5820 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
00:07:04.0905 5820 WIMMount - ok
00:07:04.0967 5820 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\drivers\WinUSB.sys
00:07:04.0967 5820 WinUsb - ok
00:07:05.0029 5820 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
00:07:05.0029 5820 WmiAcpi - ok
00:07:05.0061 5820 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
00:07:05.0076 5820 ws2ifsl - ok
00:07:05.0123 5820 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
00:07:05.0123 5820 WudfPf - ok
00:07:05.0139 5820 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
00:07:05.0139 5820 WUDFRd - ok
00:07:05.0201 5820 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
00:07:05.0232 5820 \Device\Harddisk0\DR0 - ok
00:07:05.0248 5820 Boot (0x1200) (4274d3b441c2748b3e5698edb7fcae01) \Device\Harddisk0\DR0\Partition0
00:07:05.0248 5820 \Device\Harddisk0\DR0\Partition0 - ok
00:07:05.0279 5820 Boot (0x1200) (85df3adf7dd7c9469cfd00829aef4dd0) \Device\Harddisk0\DR0\Partition1
00:07:05.0279 5820 \Device\Harddisk0\DR0\Partition1 - ok
00:07:05.0295 5820 Boot (0x1200) (e0913f501e9094229944e253f129333b) \Device\Harddisk0\DR0\Partition2
00:07:05.0295 5820 \Device\Harddisk0\DR0\Partition2 - ok
00:07:05.0295 5820 ============================================================
00:07:05.0295 5820 Scan finished
00:07:05.0295 5820 ============================================================
00:07:05.0310 3096 Detected object count: 0
00:07:05.0310 3096 Actual detected object count: 0
00:07:48.0117 5448 Deinitialize success
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda pmarco66 » mer gen 18, 2012 12:33 am

ComboFix 12-01-09.07 - emarco 18/01/2012 0:21.2.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.39.1040.18.3894.2171 [GMT 1:00]
Eseguito da: c:\users\emarco\Desktop\nr5e4rfv4.exe
AV: Sophos Anti-Virus *Disabled/Outdated* {479CCF92-4960-B3E0-7373-BF453B467D2C}
SP: Sophos Anti-Virus *Disabled/Outdated* {FCFD2E76-6F5A-BC6E-49C3-843740C13791}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
- MODALITÀ CON FUNZIONALITÀ RIDOTTE -
.
.
((((((((((((((((((((((((( Files Creati Da 2011-12-17 al 2012-01-17 )))))))))))))))))))))))))))))))))))
.
.
2012-01-17 23:22 . 2012-01-17 23:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-17 23:13 . 2012-01-17 23:13 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FAAD307-D7F1-4F54-A8DE-033B30DA7821}\offreg.dll
2012-01-17 23:13 . 2011-11-21 11:40 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FAAD307-D7F1-4F54-A8DE-033B30DA7821}\mpengine.dll
2012-01-12 20:58 . 2012-01-17 22:49 25160 ----a-w- c:\windows\system32\drivers\hitmanpro36.sys
2012-01-12 20:57 . 2012-01-12 20:57 -------- d-----w- c:\program files\HitmanPro
2012-01-12 20:56 . 2012-01-12 20:58 -------- d-----w- c:\programdata\HitmanPro
2012-01-12 20:43 . 2012-01-17 22:34 -------- d-----w- C:\FyK
2012-01-11 16:51 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 16:51 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 16:51 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 16:51 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 16:51 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 16:51 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 16:51 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 16:51 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-10 12:20 . 2012-01-10 12:20 -------- d-----w- c:\program files (x86)\Common Files\PCSuite
2012-01-10 12:19 . 2012-01-10 12:19 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2012-01-06 10:47 . 2012-01-06 10:47 -------- d-----w- c:\users\emarco\AppData\Roaming\SUPERAntiSpyware.com
2012-01-06 10:47 . 2012-01-06 10:47 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-01-05 10:01 . 2012-01-05 10:01 -------- d-----w- c:\users\emarco\AppData\Roaming\DVDVideoSoft
2012-01-05 10:00 . 2012-01-05 10:01 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft
2012-01-05 10:00 . 2012-01-05 10:00 -------- d-----w- c:\program files (x86)\DVDVideoSoft
2012-01-05 09:37 . 2012-01-05 09:37 -------- d-----w- c:\programdata\eMule
2012-01-05 09:37 . 2012-01-05 09:37 -------- d-----w- c:\users\emarco\AppData\Local\eMule
2012-01-05 09:37 . 2012-01-05 09:37 -------- d-----w- c:\program files (x86)\eMule
2012-01-04 18:22 . 2012-01-04 18:22 1409 ----a-w- c:\windows\QTFont.for
2012-01-04 18:22 . 2012-01-04 18:22 -------- d-----w- c:\users\emarco\AppData\Roaming\Panasonic
2012-01-04 18:16 . 2012-01-12 21:17 -------- d-----w- c:\users\Administrator
2012-01-04 18:16 . 2012-01-04 18:16 -------- d-----w- c:\program files (x86)\MP4Tool
2012-01-04 16:20 . 2012-01-04 16:20 143360 ----a-w- c:\program files (x86)\Internet Explorer\Plugin\npqtplugin7.dll
2012-01-04 16:20 . 2012-01-04 16:20 143360 ----a-w- c:\program files (x86)\Internet Explorer\Plugin\npqtplugin6.dll
2012-01-04 16:20 . 2012-01-04 16:20 143360 ----a-w- c:\program files (x86)\Internet Explorer\Plugin\npqtplugin5.dll
2012-01-04 16:20 . 2012-01-04 16:20 143360 ----a-w- c:\program files (x86)\Internet Explorer\Plugin\npqtplugin4.dll
2012-01-04 16:20 . 2012-01-04 16:20 143360 ----a-w- c:\program files (x86)\Internet Explorer\Plugin\npqtplugin3.dll
2012-01-04 16:20 . 2012-01-04 16:20 143360 ----a-w- c:\program files (x86)\Internet Explorer\Plugin\npqtplugin2.dll
2012-01-04 16:20 . 2012-01-04 16:20 143360 ----a-w- c:\program files (x86)\Internet Explorer\Plugin\npqtplugin.dll
2012-01-04 16:19 . 2012-01-04 16:20 -------- d-----w- c:\program files (x86)\QuickTime
2012-01-04 16:19 . 2012-01-04 16:19 -------- d-----w- c:\programdata\Apple Computer
2012-01-04 16:19 . 2012-01-04 16:19 -------- d-----w- c:\users\emarco\AppData\Local\Apple
2012-01-04 16:19 . 2012-01-04 16:19 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-01-04 16:19 . 2012-01-04 16:19 -------- d-----w- c:\programdata\Apple
2012-01-04 16:18 . 2012-01-04 16:18 -------- d-----w- c:\users\emarco\AppData\Local\ArcSoft
2012-01-04 16:17 . 2006-09-18 07:50 22784 ----a-w- c:\windows\SysWow64\drivers\afc.sys
2012-01-04 16:17 . 2005-04-27 15:36 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2012-01-04 16:17 . 2012-01-04 16:17 -------- d-----w- c:\program files (x86)\Common Files\ArcSoft
2012-01-04 16:16 . 2012-01-04 16:17 -------- d-----w- c:\windows\SysWow64\MediaImpression Slideshow
2012-01-04 16:16 . 2012-01-04 16:16 -------- d-----w- c:\program files (x86)\ArcSoft
2012-01-04 16:14 . 2007-06-21 23:10 501912 ----a-w- c:\windows\SysWow64\PICSDK2.dll
2012-01-04 16:14 . 2006-10-30 23:10 71840 ----a-w- c:\windows\SysWow64\EPPicMgr.dll
2012-01-04 16:14 . 2006-10-30 23:10 120992 ----a-w- c:\windows\SysWow64\EpPicPrt.dll
2012-01-04 16:14 . 2006-10-19 23:10 80024 ----a-w- c:\windows\SysWow64\PICSDK.dll
2012-01-04 16:14 . 2006-10-19 23:10 108704 ----a-w- c:\windows\SysWow64\PICEntry.dll
2012-01-04 16:13 . 2008-09-25 20:07 45056 ----a-w- c:\windows\SysWow64\PhDi2.sys
2012-01-04 16:00 . 2012-01-04 16:00 -------- d-----w- c:\users\emarco\AppData\Roaming\InstallShield
2012-01-04 15:57 . 2012-01-04 16:13 -------- d-----w- c:\program files (x86)\Panasonic
2012-01-03 20:27 . 2010-11-16 20:24 750440 ------w- c:\windows\system32\HPDiscoPM9311.dll
2012-01-03 20:27 . 2012-01-03 20:29 -------- d-----w- c:\programdata\HP
2012-01-03 20:27 . 2012-01-03 20:27 -------- d-----w- c:\program files (x86)\HP
2012-01-03 20:26 . 2012-01-03 20:26 -------- d-----w- c:\program files\HP
2012-01-03 20:11 . 2012-01-03 20:32 -------- d-----w- c:\users\emarco\AppData\Local\HP
2012-01-03 13:35 . 2012-01-03 13:35 -------- d-----w- c:\users\emarco\AppData\Local\S2PC
2012-01-03 13:35 . 2008-06-26 02:44 587264 ----a-w- c:\windows\system32\ssmgr64.cpl
2012-01-03 13:35 . 2012-01-03 13:35 -------- d-----w- c:\windows\Samsung
2012-01-03 13:30 . 2001-09-05 02:18 77824 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2012-01-03 13:30 . 2001-09-05 02:18 225280 ----a-w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2012-01-03 13:30 . 2001-09-05 02:14 176128 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2012-01-03 13:30 . 2001-09-05 02:13 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2012-01-03 13:30 . 2007-10-23 02:53 110592 ----a-r- c:\windows\Wiainst.exe
2012-01-03 13:28 . 2009-02-03 10:08 14848 ----a-w- c:\windows\system32\SaSegFlt.dll
2012-01-03 13:28 . 2009-02-03 10:08 160768 ----a-w- c:\windows\system32\SaMinDrv.dll
2012-01-03 13:28 . 2009-02-03 10:08 36864 ----a-w- c:\windows\system32\SaImgFlt.dll
2012-01-03 13:28 . 2009-02-03 10:08 13312 ----a-w- c:\windows\system32\SaErHdlr.dll
2012-01-03 13:27 . 2012-01-03 13:27 -------- d-----w- c:\program files (x86)\Samsung
2012-01-03 12:37 . 2012-01-03 12:37 -------- d-----w- c:\program files (x86)\FreeTime
2012-01-03 12:14 . 2012-01-03 13:38 -------- d-----w- c:\program files (x86)\Common Files\Hewlett-Packard
2012-01-03 07:36 . 2012-01-03 07:36 -------- d-----w- c:\program files\Common Files\Deterministic Networks
2012-01-03 07:36 . 2012-01-03 07:36 -------- d-----w- c:\program files (x86)\Cisco Systems
2011-12-19 21:05 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-19 21:05 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-19 21:05 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-19 21:05 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-19 21:05 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-19 21:05 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-10 14:24 . 2011-01-19 11:56 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-18 22:03 . 2011-06-09 18:36 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-15 13:29 . 2010-11-02 09:02 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-11-01 09:07 . 2011-01-20 18:14 57856 ----a-w- c:\windows\system32\nmwcdclsx64.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-12_21.13.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-13 13:46 . 2011-11-17 05:28 96768 c:\windows\SysWOW64\sspicli.dll
- 2011-04-18 09:38 . 2010-11-20 12:08 96768 c:\windows\SysWOW64\sspicli.dll
- 2011-04-18 09:38 . 2010-11-20 12:21 22016 c:\windows\SysWOW64\secur32.dll
+ 2012-01-13 13:46 . 2011-11-17 05:34 22016 c:\windows\SysWOW64\secur32.dll
+ 2010-11-02 08:12 . 2012-01-17 22:27 57708 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-01-17 22:27 30226 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-11-02 08:07 . 2012-01-17 22:27 11680 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3815140021-4139662573-755630772-1000_UserData.bin
- 2011-04-18 09:38 . 2010-11-20 13:27 29184 c:\windows\system32\sspisrv.dll
+ 2012-01-13 13:46 . 2011-11-17 06:35 29184 c:\windows\system32\sspisrv.dll
- 2011-04-18 09:38 . 2010-11-20 13:27 28160 c:\windows\system32\secur32.dll
+ 2012-01-13 13:46 . 2011-11-17 06:35 28160 c:\windows\system32\secur32.dll
+ 2012-01-13 13:46 . 2011-11-17 06:33 31232 c:\windows\system32\lsass.exe
- 2009-07-13 23:20 . 2009-07-14 01:39 31232 c:\windows\system32\lsass.exe
+ 2012-01-13 13:46 . 2011-11-17 06:49 95600 c:\windows\system32\drivers\ksecdd.sys
- 2010-10-29 14:37 . 2012-01-12 19:36 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-10-29 14:37 . 2012-01-17 22:29 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-10-29 14:37 . 2012-01-17 22:29 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-10-29 14:37 . 2012-01-12 19:36 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-01-12 19:36 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-01-17 22:29 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-12 21:13 . 2012-01-12 21:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-17 22:24 . 2012-01-17 22:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-17 22:24 . 2012-01-17 22:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-12 21:13 . 2012-01-12 21:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-04-18 09:39 . 2010-11-20 12:21 314880 c:\windows\SysWOW64\webio.dll
+ 2012-01-13 13:46 . 2011-11-17 05:35 314880 c:\windows\SysWOW64\webio.dll
+ 2012-01-13 13:46 . 2011-11-17 05:34 224768 c:\windows\SysWOW64\schannel.dll
- 2011-04-18 09:39 . 2010-11-20 13:27 395776 c:\windows\system32\webio.dll
+ 2012-01-13 13:46 . 2011-11-17 06:35 395776 c:\windows\system32\webio.dll
+ 2010-11-02 06:37 . 2012-01-15 20:43 203650 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2010-11-02 14:00 . 2012-01-15 20:39 263386 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2012-01-13 13:46 . 2011-11-17 06:35 136192 c:\windows\system32\sspicli.dll
- 2011-04-18 09:39 . 2010-11-20 13:27 136192 c:\windows\system32\sspicli.dll
- 2011-04-18 09:39 . 2010-11-20 13:27 340992 c:\windows\system32\schannel.dll
+ 2012-01-13 13:46 . 2011-11-17 06:35 340992 c:\windows\system32\schannel.dll
- 2009-07-14 11:12 . 2012-01-12 20:56 701426 c:\windows\system32\perfh010.dat
+ 2009-07-14 11:12 . 2012-01-17 22:30 701426 c:\windows\system32\perfh010.dat
- 2009-07-14 02:36 . 2012-01-12 20:56 618912 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-01-17 22:30 618912 c:\windows\system32\perfh009.dat
+ 2009-07-14 11:12 . 2012-01-17 22:30 128740 c:\windows\system32\perfc010.dat
- 2009-07-14 11:12 . 2012-01-12 20:56 128740 c:\windows\system32\perfc010.dat
+ 2009-07-14 02:36 . 2012-01-17 22:30 107232 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-12 20:56 107232 c:\windows\system32\perfc009.dat
+ 2012-01-13 13:46 . 2011-11-17 06:49 152432 c:\windows\system32\drivers\ksecpkg.sys
+ 2012-01-13 13:46 . 2011-11-17 06:44 459232 c:\windows\system32\drivers\cng.sys
+ 2009-07-14 04:46 . 2012-01-17 22:33 150888 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2009-07-14 05:01 . 2012-01-12 21:12 461844 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-01-17 22:23 461844 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-01-13 13:46 . 2011-11-17 06:35 1447936 c:\windows\system32\lsasrv.dll
- 2011-04-18 09:39 . 2010-11-20 13:26 1447936 c:\windows\system32\lsasrv.dll
- 2009-07-14 04:45 . 2012-01-11 18:31 7389805 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2012-01-13 21:48 7389805 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 02:34 . 2012-01-13 13:47 10747904 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:34 . 2011-12-19 21:19 10747904 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2010-11-13 11:40 . 2012-01-17 22:23 21223244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3815140021-4139662573-755630772-1000-12288.dat
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-12-31 39408]
"PC Suite Tray"="c:\program files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" [2011-12-16 1508408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"PNMService"="c:\program files (x86)\Intel\IntelPNM\PNMService.exe" [2010-01-20 400896]
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2010-09-16 112152]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992]
"DellBtrEvent"="c:\program files (x86)\Dell\Reader 2.1\DellBtrEvent.exe" [2010-05-13 160768]
"Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2010-09-21 439536]
"LaCie Hard Drive Configuration"="c:\program files (x86)\LaCie\SAFE Hard Drive\SAFE Hard Drive Configuration.exe" [2007-01-18 3624960]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2009-02-27 552960]
"3170 Scan2PC"="c:\windows\twain_32\Samsung\CLX3170\Scan2Pc.exe" [2009-01-30 503808]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 31232]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2008-03-28 413696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Dell System Manager.lnk - c:\program files\Dell\Dell System Manager\DCPSysMgr.exe [2010-8-24 1549680]
TdmNotify.lnk - c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe [2010-3-29 185192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Servizio di Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-31 136176]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-05 1436424]
R3 gupdatem;Servizio Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-31 136176]
R3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;c:\windows\system32\DRIVERS\SNTUSB64.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [x]
S1 DVMIO;DVMIO;c:\program files (x86)\Dell\Reader 2.1\dvmio_x64.sys [2010-05-04 20624]
S1 SASDIFSV;SASDIFSV;c:\users\emarco\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\users\emarco\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x]
S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 buttonsvc64;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [2009-11-20 373024]
S2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2010-03-23 1039776]
S2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2010-03-23 31136]
S2 dcpsysmgrsvc;Dell System Manager Service;c:\program files\Dell\Dell System Manager\DCPSysMgrSvc.exe [2010-08-24 517488]
S2 DvmMDES;DeviceVM Meta Data Export Service;c:\program files (x86)\Dell\Reader 2.1\DVMExportService.exe [2010-05-04 327680]
S2 LaCie Safe Hard Drive Enabler;LaCie Safe Hard Drive Enabler;c:\program files (x86)\LaCie\SAFE Hard Drive\SafeService.exe [2006-11-30 61440]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 mitsijm2011;Gestore dei processi di Autodesk Moldflow Inventor Tool Suite Integration 2011;c:\program files\Autodesk\Inventor 2011\Moldflow\bin\mitsijm.exe [2010-01-23 673792]
S2 QDLService2kDell;Qualcomm Gobi 2000 Download Service (Dell);c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kDell.exe [2010-04-26 330488]
S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe64.sys [x]
S2 Sentinel64;Sentinel64;c:\windows\System32\Drivers\Sentinel64.sys [x]
S2 SentinelKeysServer;Sentinel Keys Server;c:\program files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [2009-09-16 369952]
S2 SentinelSecurityRuntime;Sentinel Security Runtime;c:\program files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [2009-09-16 292128]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [x]
S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2010-10-08 1541360]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-09-16 2538520]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
S3 cvusbdrv;Dell ControlVault;c:\windows\system32\Drivers\cvusbdrv.sys [x]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Audio schermo Intel(R);c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 NETw5s64;Driver scheda Intel(R) Wireless WiFi Link per Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - 37420237
*NewlyCreated* - 63230237
*Deregistered* - 37420237
*Deregistered* - 63230237
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-31 18:02]
.
2012-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-31 18:02]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2010-03-29 12:00 60784 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2010-03-29 12:00 60784 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-06-04 392048]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-28 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-28 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-28 415256]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2010-06-22 34232]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll
.
------- Scansione supplementare -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.lnf.infn.it/public/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\emarco\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: SmarThru4 Capture Selection - c:\program files (x86)\SmarThru 4\x64\WebCapture.dll2.htm
IE: SmarThru4 Save as HTML - c:\program files (x86)\SmarThru 4\x64\WebCapture.dll1.htm
IE: SmarThru4 Save Selected Text - c:\program files (x86)\SmarThru 4\x64\WebCapture.dll.htm
IE: SmarThru4 Web Capture - c:\program files (x86)\SmarThru 4\x64\WebCapture.dll
TCP: DhcpNameServer = 192.168.2.1
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-SRService
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2012-01-18 00:26:00
ComboFix-quarantined-files.txt 2012-01-17 23:26
ComboFix2.txt 2012-01-12 21:17
.
Pre-Run: 27.931.602.944 byte disponibili
Post-Run: 28.069.797.888 byte disponibili
.
- - End Of File - - DA9DD093FD5988E314D6D3C721B58B46
Ultima modifica di The Doctor il mer gen 18, 2012 8:38 am, modificato 1 volta in totale.
Motivazione: Inserito TAG MEMO
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda pmarco66 » mer gen 18, 2012 12:49 am

OTL Extras logfile created on: 18/01/2012 00:41:03 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\emarco\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy

3,80 Gb Total Physical Memory | 2,13 Gb Available Physical Memory | 55,91% Memory free
7,60 Gb Paging File | 6,00 Gb Available in Paging File | 78,89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 78,12 Gb Total Space | 26,19 Gb Free Space | 33,52% Space Free | Partition Type: NTFS
Drive D: | 29,49 Gb Total Space | 1,42 Gb Free Space | 4,80% Space Free | Partition Type: NTFS
Drive E: | 125,27 Gb Total Space | 36,76 Gb Free Space | 29,34% Space Free | Partition Type: NTFS

Computer Name: PCMARCO2 | User Name: emarco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L"
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L"
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0003C1E0-E0E7-49BB-A0F6-4AE6D2B09202}" = UPEK TouchChip Fingerprint Reader
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{0DB0EA38-E806-44ED-A892-489F2E305080}" = Dell System Manager
"{131A2659-99A9-4A89-B012-22A898EAE9DA}" = EMBASSY Security Center Lite
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{25B473DB-CC8D-384A-ACE7-7CFB119B7E03}" = Microsoft .NET Framework 4 Client Profile ITA Language Pack
"{3A054F41-D0F2-4C82-9879-348766D84118}" = BS64MMWrapper
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{5783F2D7-9005-0410-0102-0060B0CE6BBA}" = AutoCAD Mechanical 2011
"{5783F2D7-9005-0410-1102-0060B0CE6BBA}" = AutoCAD Mechanical 2011 Language Pack - Italiano
"{5783F2D7-9028-0409-0100-0060B0CE6BBA}" = DWG TrueView 2011
"{5B62638A-30C6-42A4-BF2A-FED6F2C0B345}" = Software di base della periferica HP Deskjet 3050 J610 series
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}" = Cisco Systems VPN Client 5.0.07.0440
"{615C9088-E58C-448A-B5F3-AB5F51F29082}" = 64 Bit HP CIO Components Installer
"{67154CF5-2C33-41C2-A9F2-A4FBC29482AD}" = Wave Infrastructure Installer
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7244B345-B413-408B-9D04-F55BE1CC93FA}" = Autodesk Inventor Content Center Libraries 2011 (Desktop Content)
"{7B7D73E7-79D5-4133-AB7A-E27BB5F64725}" = Dell Control Point 64
"{7F4DD591-1564-0409-0000-7107D70F3DB4}" = Autodesk Inventor Professional 2011
"{7F4DD591-1564-0409-0001-7107D70F3DB4}" = Autodesk Inventor Professional 2011 Language Pack - Italiano
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8E80AF23-17B4-4611-B28E-68A114B23488}" = Dell ControlVault Host Components Installer 64Bit
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0410-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Italian) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A4F53D2C-1FED-4CDF-9D83-4AED82CD0436}" = Gemalto
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{ACF9459F-3585-487A-A84E-B1A3A0D12165}" = Autodesk Vault 2011 (Client)
"{ACF9459F-3585-487F-A84E-B1A3A0D12165}" = Language Pack per Autodesk Vault 2011(Client) - Italiano
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{AF7E4468-E364-4991-BC2A-6E8293E1055B}" = BioAPI Framework
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BB93D30B-B395-44BB-A9ED-A0E057F07E53}" = NTRU TCG Software Stack
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DDD6BE8C-9AFA-48F1-A6AE-3BD596E2EB0B}" = Trusted Drive Manager
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"72A50F48CC5601190B9C4E74D81161693133E7F7" = Pacchetto driver Windows - Nokia Modem (02/25/2011 7.01.0.9)
"9512AA21B791B05A54E27065C45BBC417AB282DF" = Pacchetto driver Windows - Dell Inc. PBADRV System (09/11/2009 1.0.1.6)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"AutoCAD Mechanical 2011" = AutoCAD Mechanical 2011
"Autodesk Inventor Professional 2011" = Autodesk Inventor Professional 2011 Italiano
"CCleaner" = CCleaner
"DWG TrueView 2011" = DWG TrueView 2011
"E0AC723A3DE3A04256288CADBBB011B112AED454" = Pacchetto driver Windows - Nokia Modem (02/25/2011 4.7)
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Pacchetto driver Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile ITA Language Pack" = Microsoft .NET Framework 4 Client Profile - Language Pack (ITA)
"PROSet" = Intel(R) Network Connections Drivers
"WinRAR archiver" = WinRAR 4.00 beta 4 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{051EC556-DA07-413A-ADF3-3D8D76D8CF95}" = Qualcomm Gobi 2000 Package for Dell
"{0711500B-9912-4D60-9A49-C577B4503D42}" = Nero Recode Help
"{07FF7593-9DEA-40B5-9F87-F557E65BBF60}" = Nero Recode
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1122AAC4-AAAA-43BF-B2D4-3C8C12378952}" = Nero InfoTool
"{11A84FCA-C3C7-4AFD-A797-111DB8569DBC}" = Nero BurningROM
"{12345674-DE9A-677A-CCEE-666356D89777}" = Nero BurnRights
"{14D08502-FEE4-40E5-90D3-8A967A1D8BA2}" = Readiris Pro 10
"{150C6C87-D187-4105-BF7A-090378D7AE2A}" = Nokia Ovi Suite
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B040683-C390-4711-ABC7-DA8D85E470E7}" = NeroBurningROM
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 29
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{2B818257-E6C7-4841-8C29-C5C9A982BCE5}" = RICOH Media Driver ver.2.11.01.02
"{2D3455A8-3B15-41A8-99F8-0D4215746463}" = Nero StartSmart
"{2FA28330-2028-4033-BD10-425C87EB4D54}" = Nokia Software Updater
"{3097B151-1F61-4211-A4CC-D70127B226AE}" = SoundTrax
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3EADFC7D-2F98-5E84-768A-6DB1E8884B14}" = SpatialAnalyzer Roadmap
"{3F30CC51-0788-487B-AA83-7214A239C0C0}" = Nero Disc Copy Gadget Help
"{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack
"{41313863-5170-4D7E-AD60-3CDF4DEBA81F}" = Nokia PC Suite
"{42B74521-4706-412A-9A27-AED12B83E886}" = Nokia Ovi Application Installer
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{497A1721-088F-41EF-8876-B43C9DA5528B}" = ArcSoft Software Suite
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
"{4D42353B-533F-4306-AD0B-7FEF292ADE04}" = Nero CoverDesigner Help
"{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{548F99E0-14CC-4D53-A7D6-4A62A5F2C748}" = Nero PhotoSnap
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5545EEE8-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.3)
"{56BE5CC9-95E6-4128-ABEA-968414CA9C80}" = DolbyFiles
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5A62A775-A29A-4CE1-BBC2-4A9CD0B211EF}" = Nero Live Help
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5C2E8A0F-80E2-4C68-8CC0-D8D16E7196BF}" = Nero RescueAgent Help
"{5C42EAB8-54F9-423A-948C-1CBEF25F8DB4}" = Nero PhotoSnap Help
"{5C9BB0B3-E830-4814-BBA4-D93535E1C7B9}" = Nero Live
"{5ED7C471-EB6F-4136-BF29-E27BCDBBB46B}_is1" = LaCie SAFE Hard Drive Configuration 1.1
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6442DEDF-AC2F-4CBA-85DE-42E459C5006C}" = Nokia Ovi Content Copier
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6E8AFC13-F7B8-41D8-88AB-F1D0CFC56305}" = Windows Live Messenger
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common
"{7527CD9F-894E-47B3-9AFB-3E680E007051}" = HP Proactive Services
"{75321954-2589-11DC-DDCC-E98356D81493}" = Nero DriveSpeed
"{753973C4-B961-43BF-B2D4-3C8C92F7216E}" = Nero DriveSpeed
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78523651-D8B1-11DC-CCEE-741589645873}" = Nero DiscSpeed
"{7B1AA2AB-ACD2-45C7-B1B1-364BEA40615F}" = Sentinel Protection Installer 7.6.1
"{7f087ff7-b1cb-42a0-993b-1e552c1c1133}" = Nero 9
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C654BD0-1949-43DE-84F2-EC2A1ABB0CB4}" = Nero ShowTime
"{8D20B4D7-3422-4099-9332-39F27E617A6F}" = Autodesk Design Review 2011
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90120000-0015-0410-0000-0000000FF1CE}" = Microsoft Office Access MUI (Italian) 2007
"{90120000-0015-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0410-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Italian) 2007
"{90120000-0016-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0410-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Italian) 2007
"{90120000-0018-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0410-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Italian) 2007
"{90120000-0019-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0410-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Italian) 2007
"{90120000-001A-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0410-0000-0000000FF1CE}" = Microsoft Office Word MUI (Italian) 2007
"{90120000-001B-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0410-1000-0000000FF1CE}_ENTERPRISE_{C0C7E58F-D0A1-4102-855B-0B7AA2E8F1C1}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0410-0000-0000000FF1CE}" = Microsoft Office Proofing (Italian) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0410-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Italian) 2007
"{90120000-0044-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0410-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Italian) 2007
"{90120000-006E-0410-0000-0000000FF1CE}_ENTERPRISE_{C0C7E58F-D0A1-4102-855B-0B7AA2E8F1C1}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0410-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Italian) 2007
"{90120000-00A1-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0410-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Italian) 2007
"{90120000-00BA-0410-0000-0000000FF1CE}_ENTERPRISE_{7F40286D-09A7-4DC0-A2A4-AA18D026D369}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90F1943D-EA4A-4460-B59F-30023F3BA69A}" = SmarThru 4
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources
"{943CC0C0-2253-4FE0-9493-DD386F7857FD}" = Nero Express
"{948FFAAE-C57F-447B-9B07-3721E950BFDC}" = Nero ShowTime
"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58
"{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9A9DBEBC-C800-4776-A970-D76D6AA405B1}" = PHOTOfunSTUDIO
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011
"{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center
"{A11E8E1D-EAE0-4907-B196-989E80471F10}" = Reader 2.1
"{A42199DD-BD4D-4776-8C22-888C4D4CE9A7}" = IntelPNM
"{A73BEC3C-40A0-480E-87EF-EFCD33629088}" = NeroExpress
"{A8399F58-234A-48C6-BA55-30C15738BF3C}" = Nero CoverDesigner
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAA12554-2589-11DC-92EF-E98356D81493}" = Nero InfoTool
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AABBCC54-D8B1-11DC-92EF-E98356D81493}" = Nero DiscSpeed
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B2C12C8D-65DC-40BD-B309-5ADB0C6C8D8F}" = Nero WaveEditor
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{B96C2601-52F5-4D5D-816A-63469EA311EF}" = "Nero SoundTrax Help
"{BCD82AB5-670D-4242-90FA-1F97103C16CD}" = Movie Templates - Starter Kit
"{C7CDB2AC-A0AB-4D83-B046-187E24D9EA68}" = Nokia Ovi System Utilities
"{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}" = Menu Templates - Starter Kit
"{CD1826A5-CFCC-4C6E-9F9D-E181876162EA}" = Nero Rescue Agent
"{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D7C206B6-1A63-4389-A8B1-8F607D0BFF1F}" = Nero StartSmart Help
"{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials
"{DF95F1EE-9ECA-45C1-B02B-F56DDB8A3E83}" = PC Connectivity Solution
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E4A8DD87-A746-4443-BF25-CAF99CED6767}" = Nero Disc Copy Gadget
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E86156E5-9859-440D-8876-26CED1349802}" = Nero WaveEditor Help
"{EA9FFE54-D8B1-11DC-92EF-E98356D81493}" = Nero BurnRights
"{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F4487649-7368-4217-AEA3-1E04DB3E2C5C}" = Dell ControlPoint Security Manager
"{F53F6769-AC46-49E3-ABE3-2C8AFD39D0DD}" = Nero Vision
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series ?
"{FF1DDCF4-3A28-4F7F-96D8-E3F4BD1C1702}" = Dell Security Device Driver Pack
"{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker
"1.2EBB9893DB8829B767CCCC6A81CEC0019380C826.1" = SpatialAnalyzer Roadmap
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.1.4 Professional
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Autodesk Design Review 2011" = Autodesk Design Review 2011
"Autodesk Vault 2011 (Client)" = Autodesk Vault 2011 (Client)
"BitTorrent" = BitTorrent
"eMule" = eMule
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FormatFactory" = FormatFactory 2.80
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.13.1123
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{131A2659-99A9-4A89-B012-22A898EAE9DA}" = EMBASSY Security Center Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versione 1.60.0.1800
"Nokia Ovi Application Installer" = Nokia Ovi Application Installer 6.85.3011
"Nokia Ovi Content Copier" = Nokia Ovi Content Copier 6.85.3011
"Nokia Ovi System Utilities" = Nokia Ovi System Utilities 6.85.3014
"Nokia PC Suite" = Nokia PC Suite
"Reader2.1" = Reader 2.1
"Samsung CLX-3170 Series" = Samsung CLX-3170 Series
"SmarThru PC Fax" = SmarThru PC Fax
"SpatialAnalyzer 2011.03.18" = SpatialAnalyzer 2011.03.18 (remove only)
"Surround MP4 Tool" = Surround MP4 Tool 3.7.0
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"WinLiveSuite" = Windows Live Essentials

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3815140021-4139662573-755630772-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 17/01/2012 18:26:22 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 18:53:19 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 18:53:19 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 18:53:19 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 18:53:19 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 18:53:19 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 18:53:19 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 18:53:19 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 18:53:19 | Computer Name = PcMarco2 | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Impossibile estrarre l'elenco radice di terze parti dal file CAB di
aggiornamento automatico in <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
a causa dell'errore seguente: Dati non validi. .

Error - 17/01/2012 19:18:48 | Computer Name = PcMarco2 | Source = Application Error | ID = 1000
Description = Nome dell'applicazione che ha generato l'errore: TdmNotify.exe, versione:
3.3.3.104, timestamp: 0x4bb10672 Nome del modulo che ha generato l'errore: unknown,
versione: 0.0.0.0, timestamp: 0x00000000 Codice eccezione: 0xc0000005 Offset errore
0x0000016300000022 ID processo che ha generato l'errore: 0xf08 Ora di avvio dell'applicazione
che ha generato l'errore: 0x01ccd566fe00e174 Percorso dell'applicazione che ha generato
l'errore: C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe
Percorso
del modulo che ha generato l'errore: unknown ID segnalazione: 9b7f0587-4161-11e1-9ca4-5cac4cfeed25

[ System Events ]
Error - 14/01/2012 19:09:39 | Computer Name = PcMarco2 | Source = Service Control Manager | ID = 7001
Description = Il servizio NTRU TSS v1.2.1.29 TCS dipende dal servizio Servizi di
base TPM che non è stato avviato per il seguente errore: %%0

Error - 14/01/2012 19:09:55 | Computer Name = PcMarco2 | Source = Service Control Manager | ID = 7026
Description = All'avvio non è stato possibile caricare i seguenti driver: SASDIFSV
SASKUTIL

Error - 15/01/2012 13:08:46 | Computer Name = PcMarco2 | Source = Service Control Manager | ID = 7001
Description = Il servizio NTRU TSS v1.2.1.29 TCS dipende dal servizio Servizi di
base TPM che non è stato avviato per il seguente errore: %%0

Error - 17/01/2012 04:52:59 | Computer Name = PcMarco2 | Source = volsnap | ID = 393245
Description = Le copie shadow del volume C: sono state interrotte durante il rilevamento.

Error - 17/01/2012 04:53:28 | Computer Name = PcMarco2 | Source = EventLog | ID = 6008
Description = Precedente arresto del sistema inatteso a 21:41:31 su ?15/?01/?2012.

Error - 17/01/2012 04:53:31 | Computer Name = PcMarco2 | Source = Service Control Manager | ID = 7001
Description = Il servizio NTRU TSS v1.2.1.29 TCS dipende dal servizio Servizi di
base TPM che non è stato avviato per il seguente errore: %%0

Error - 17/01/2012 18:20:23 | Computer Name = PcMarco2 | Source = Service Control Manager | ID = 7001
Description = Il servizio NTRU TSS v1.2.1.29 TCS dipende dal servizio Servizi di
base TPM che non è stato avviato per il seguente errore: %%0

Error - 17/01/2012 18:25:45 | Computer Name = PcMarco2 | Source = EventLog | ID = 6008
Description = Precedente arresto del sistema inatteso a 23:24:38 su ?17/?01/?2012.

Error - 17/01/2012 18:25:48 | Computer Name = PcMarco2 | Source = Service Control Manager | ID = 7001
Description = Il servizio NTRU TSS v1.2.1.29 TCS dipende dal servizio Servizi di
base TPM che non è stato avviato per il seguente errore: %%0

Error - 17/01/2012 19:23:56 | Computer Name = PcMarco2 | Source = Service Control Manager | ID = 7030
Description = Il servizio PEVSystemStart è contrassegnato come interattivo. Il sistema
non è configurato per consentire servizi interattivi. Questo servizio potrà non
funzionare correttamente.


< End of report >
Ultima modifica di The Doctor il mer gen 18, 2012 8:42 am, modificato 1 volta in totale.
Motivazione: Inserito TAG MEMO
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda hashcat » mer gen 18, 2012 2:22 pm

Ok, mentre controllo con attenzione i log posta anche il log OTL.txt (Non extra) e quello di di DDS. A prima vista sembrerebbe che la modalità provvisoria sia ora funzionante.

Oltre al malfunzionamento di Sophos il tuo computer mostra ulteriori comportamenti sospetti?
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Re: virus!!!

Messaggioda pmarco66 » mer gen 18, 2012 2:38 pm

la modalita' provvisoria si avvia ma al momento dell'apertura di wondows il pc riparte in modalita' normale; sophos ancora disabilitato;
i disci di boot di avira e kaspersky ( che moltre volte mi hanno aiutato) si avviano ma prima della scansione si bloccano
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda pmarco66 » mer gen 18, 2012 2:44 pm

dds non si avvia
otl.txt l'ho postato ieri con mediafire
Avatar utente
pmarco66
Aficionado
Aficionado
 
Messaggi: 132
Iscritto il: mer ago 20, 2008 1:21 pm

Re: virus!!!

Messaggioda hashcat » mer gen 18, 2012 3:05 pm

pmarco66 ha scritto:otl.txt l'ho postato ieri con mediafire

Purtroppo non riesco a trovarlo, potresti postarlo nuovamente (non extra).

[grazie]
<<Intelligence is the ability to avoid doing work, yet getting the work done.>>
Linus Torvalds

EX [MLI] Power User.
Avatar utente
hashcat
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 2285
Iscritto il: lun ott 25, 2010 1:26 pm

Prossimo

Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 2 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising