ComboFix 09-05-02.4 - Giovanni 02/05/2009 12.16.56.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1262.846 [GMT 2:00]
Eseguito da: c:\documents and settings\Giovanni\Desktop\cf.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-04-02 al 2009-05-02 )))))))))))))))))))))))))))))))))))
.
2009-05-02 09:21 . 2009-05-02 09:21 -------- d-----w c:\documents and settings\Giovanni\Dati applicazioni\Malwarebytes
2009-05-02 09:21 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-02 09:21 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-02 09:21 . 2009-05-02 09:21 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-05-02 09:21 . 2009-05-02 09:21 -------- d-----w c:\programmi\Malwarebytes' Anti-Malware
2009-04-30 20:54 . 2009-03-24 14:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-04-30 20:54 . 2009-04-30 20:54 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Avira
2009-04-26 15:07 . 2009-04-26 15:07 -------- d-----w c:\programmi\Trend Micro
2009-04-26 14:55 . 2009-04-30 20:27 -------- d--h--w c:\documents and settings\Giovanni\Dati applicazioni\drivers
2009-04-26 14:47 . 2009-04-30 20:27 -------- d--h--w c:\documents and settings\Francesca\Dati applicazioni\drivers
2009-04-26 13:08 . 2009-04-26 13:45 -------- d-----w c:\programmi\emule0.49c-Xtreme7.2
2009-04-20 20:00 . 2009-04-26 13:05 -------- d-----w c:\documents and settings\Francesca\Impostazioni locali\Dati applicazioni\SpookyManor
2009-04-19 09:26 . 2009-04-19 16:52 -------- d-----w c:\windows\system32\Adobe
2009-04-18 20:04 . 2009-04-18 20:04 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\Trymedia
2009-04-18 09:28 . 2009-04-18 09:31 -------- d-----w c:\documents and settings\All Users\Dati applicazioni\AutoPowerOn
2009-04-17 12:30 . 2008-04-21 21:14 219136 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-17 12:30 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-17 12:30 . 2009-03-06 14:19 286208 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-17 12:30 . 2009-02-09 11:22 111104 ------w c:\windows\system32\dllcache\services.exe
2009-04-17 12:30 . 2009-02-09 10:51 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-17 12:30 . 2009-02-09 10:51 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-17 12:30 . 2009-02-09 10:51 683520 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-17 12:30 . 2009-02-09 10:51 734720 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-17 12:30 . 2009-02-09 10:51 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-17 12:30 . 2009-02-09 10:51 736256 ------w c:\windows\system32\dllcache\ntdll.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-02 10:16 . 2003-05-30 14:21 6 ---ha-w c:\windows\Tasks\SA.DAT
2009-05-02 10:09 . 2008-03-30 19:26 -------- d-----w c:\programmi\Mozilla Thunderbird
2009-05-02 08:22 . 2009-01-08 21:55 -------- d-----w c:\programmi\Alice Mobile
2009-04-30 21:12 . 2008-04-03 19:12 -------- d-----w c:\programmi\Avira
2009-04-30 20:28 . 2008-04-02 20:55 -------- d-----w c:\programmi\Spybot - Search & Destroy
2009-04-01 20:57 . 2008-04-03 17:42 -------- d-----w c:\programmi\Java
2009-04-01 20:57 . 1979-12-31 23:00 65070 ----a-w c:\windows\system32\perfc010.dat
2009-04-01 20:57 . 1979-12-31 23:00 429776 ----a-w c:\windows\system32\perfh010.dat
2009-03-17 13:01 . 2008-03-29 21:40 98824 ----a-w c:\documents and settings\Francesca\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-03-09 03:19 . 2008-12-14 14:05 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-07 09:38 . 2009-01-11 14:42 98824 ----a-w c:\documents and settings\Giovanni\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-03-06 14:19 . 1979-12-31 23:00 286208 ----a-w c:\windows\system32\pdh.dll
2009-03-03 22:03 . 2009-03-03 21:50 -------- d-----w c:\programmi\File comuni\Autodesk Shared
2009-03-03 22:03 . 2009-03-03 21:50 -------- d-----w c:\programmi\AutoCAD 2004
2009-03-03 21:53 . 2009-03-03 21:53 -------- d-----w c:\programmi\Autodesk
2009-03-03 21:53 . 2009-03-03 21:53 -------- d-----w c:\programmi\File comuni\Macrovision Shared
2009-03-03 21:53 . 2009-03-03 21:53 12464 ----a-w c:\windows\system32\drivers\CDAC15BA.SYS
2009-03-03 21:53 . 2009-03-03 21:53 54784 ----a-w c:\windows\system32\drivers\CDAC11BA.EXE
2009-03-03 21:52 . 2009-03-03 21:52 -------- d-----w c:\programmi\AnswerWorks 4.0
2009-03-03 00:03 . 1979-12-31 23:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 17:08 . 2004-08-19 22:39 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-10 17:02 . 2002-09-09 12:34 2069760 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 14:04 . 1979-12-31 23:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:23 . 1979-12-31 23:00 2192768 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:22 . 1979-12-31 23:00 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 1979-12-31 23:00 734720 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2008-03-29 16:08 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 1979-12-31 23:00 683520 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 1979-12-31 23:00 736256 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 1979-12-31 23:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:57 . 1979-12-31 23:00 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-30_20.28.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 00:19 . 2007-11-07 00:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 04:07 . 2008-07-29 04:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 04:07 . 2008-07-29 04:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2009-05-02 10:08 . 2009-05-02 10:08 16384 c:\windows\Temp\Perflib_Perfdata_6b8.dat
+ 2008-04-03 19:12 . 2009-02-13 10:50 28376 c:\windows\system32\drivers\ssmdrv.sys
+ 2009-04-30 20:54 . 2009-03-30 08:33 96104 c:\windows\system32\drivers\avipbb.sys
+ 2009-04-30 20:54 . 2009-02-13 10:29 22360 c:\windows\system32\drivers\avgntmgr.sys
+ 2009-04-30 20:54 . 2009-02-13 10:17 45416 c:\windows\system32\drivers\avgntdd.sys
+ 2008-07-29 06:05 . 2008-07-29 06:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 01:54 . 2008-07-29 01:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2009-04-30 21:22 . 2009-04-30 21:22 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-800000000003}\ARPPRODUCTICON.exe
+ 2008-07-29 06:05 . 2008-07-29 06:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="LaunApp" [X]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-06 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-06 114688]
"LaunchAp"="c:\programmi\Launch Manager\LaunchAp.exe" [2003-05-12 32768]
"PowerKey"="c:\programmi\Launch Manager\PowerKey.exe" [2002-08-30 94208]
"LManager"="c:\programmi\Launch Manager\HotkeyApp.exe" [2003-05-19 45056]
"CtrlVol"="c:\programmi\Launch Manager\CtrlVol.exe" [2003-05-12 167936]
"Wbutton"="c:\programmi\Launch Manager\Wbutton.exe" [2003-05-28 53248]
"NeroFilterCheck"="c:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"EPSON Stylus C64 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2003-05-27 99840]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Thunderbird"="c:\programmi\Mozilla Thunderbird\thunderbird.exe" [2009-03-21 8500328]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-02-14 88107]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-13 561213]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=
"c:\\Programmi\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\emule0.49c-Xtreme7.2\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 mailKmd;mailKmd; [x]
R1 Wbutton;Wbutton; [x]
R3 PRISM;IEEE 802.11 Wireless NIC Driver;c:\windows\system32\DRIVERS\EXPRESS.sys [2002-11-15 614912]
S1 Hotkey;Hotkey; [x]
S2 acernbm;acernbm;c:\windows\system32\drivers\acernbm.sys [2003-03-05 6570]
S2 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\SupportAppXL\cdrom_mon.exe [2008-04-19 81920]
S2 sbbotdi;sbbotdi;c:\progra~1\SPEEDB~1\sbbotdi.sys [2008-04-02 35584]
S2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe [2008-04-02 284280]
S3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\DRIVERS\ONDAusbmdm6k.sys [2008-04-23 104960]
S3 ONDAusbnet;ONDA USB-NDIS miniport;c:\windows\system32\DRIVERS\ONDAusbnet.sys [2008-04-23 110080]
S3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\DRIVERS\ONDAusbnmea.sys [2008-04-23 104960]
S3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\DRIVERS\ONDAusbser6k.sys [2008-04-23 104960]
S3 POWERKEY;POWERKEY;c:\programmi\Launch Manager\POWERKEY.sys [2000-12-19 2343]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ec61300-0449-11de-9393-000ae44bd656}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68541470-0365-11de-9392-000ae44bd656}]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a181eeb1-16c8-11de-93b8-000ae44bd656}]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4702241-0758-11de-9398-000ae44bd656}]
\Shell\AutoRun\command - I:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aed57bb2-e7bb-11dd-9354-000ae44bd656}]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e836df90-1e2d-11de-93c2-000ae44bd656}]
\Shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fbc29950-df74-11dd-9340-000ae44bd656}]
\Shell\AutoRun\command - G:\AutoRun.exe
.
Contenuto della cartella 'Scheduled Tasks'
2008-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.repubblica.it/IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {87255EDD-D14F-40C0-A2C0-67D233BCA22E} = 192.168.1.1,151.99.125.1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-02 12:18
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
c:\windows\TEMP\pkwkmbqv.TMP 616448 bytes
Scansione completata con successo
Files nascosti: 1
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\igfx.CUITestConfig.1\CLSID]
@DACL=(02 0000)
@SACL=
@="c"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{C8DA3399-8196-4CB3-ADD9-30280DCC1A2F}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{53B18F72-9271-47BD-9B9C-17E0E8F25007}"
"Version"="6.5.17"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\ProxyStubClsid]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\ProxyStubClsid32]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{CA8A9783-280D-11CF-A24D-444553540000}"
"Version"="1.3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\ProxyStubClsid]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\ProxyStubClsid32]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{CA8A9783-280D-11CF-A24D-444553540000}"
"Version"="1.3"
[HKEY_LOCAL_MACHINE\software\CyberLink\PowerDVD\BuildInfo]
@DACL=(02 0000)
@SACL=
"SR_No"="DVD030423-04"
"Skin"="2420"
"iPower"="030407"
"UG"="1510"
"Setup"="030421"
"Help"="2416"
"RC"="030414"
"Readme"="2416"
"Kernel"="v2834_DS(Acer)"
"UI"="v2824_DDVS_DS(Acer)"
"Filter"="v2834_DS(Acer)"
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\REALTEK Semiconductor Corp.\Realtek RTL8139/810x Fast Ethernet NIC Driver Setup]
@DACL=(02 0000)
@SACL=
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(352)
c:\windows\system32\btmmhook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\Audiodev.dll
c:\windows\system32\WMVCore.DLL
c:\windows\system32\WMASF.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
.
Ora fine scansione: 2009-05-02 12.21.00
ComboFix-quarantined-files.txt 2009-05-02 10:20
ComboFix2.txt 2009-04-30 20:30
Pre-Run: 7.507.210.240 byte disponibili
Post-Run: 7.525.806.080 byte disponibili
269 --- E O F --- 2009-04-17 13:02