ComboFix 09-07-29.04 - SYSTEM 01/08/2009 11.29.13.1.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.39.1040.18.3069.2665 [GMT 2:00]
Eseguito da: c:\windows\system32\config\systemprofile\Desktop\Combo2.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
PEV Error: AppFile
PEV Error: AppFolder
PEV Error: DesktopFile
PEV Error: DesktopFolder
PEV Error: FavFile
PEV Error: LocalAppDataFile
PEV Error: LocalAppDataFolder
PEV Error: LocalSettingsFile
PEV Error: MenuFile
PEV Error: MenuFolder
PEV Error: PersonalFile
PEV Error: PersonalFolder
PEV Error: ProgramsFile
PEV Error: ProgramsFolder
PEV Error: StartUpFile
PEV Error: UserFile
PEV Error: UserFolder
/wow section non completata
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_111111S1RO1S1A
-------\Service_111111s1ro1s1a
((((((((((((((((((((((((( Files Creati Da 2009-07-01 al 2009-08-01 )))))))))))))))))))))))))))))))))))
.
2009-07-31 13:29 . 2009-07-31 13:29 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\645672.exe
2009-07-31 13:29 . 2009-07-31 13:29 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\644596.exe
2009-07-31 13:29 . 2009-07-31 13:29 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\643145.exe
2009-07-31 13:28 . 2009-07-31 13:28 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\634253.exe
2009-07-31 13:28 . 2009-07-31 13:28 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\633582.exe
2009-07-31 13:28 . 2009-07-31 13:28 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\632740.exe
2009-07-31 13:28 . 2009-07-31 13:28 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\591352.exe
2009-07-31 13:28 . 2009-07-31 13:28 99332 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\588357.exe
2009-07-31 13:27 . 2009-07-31 13:27 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\529966.exe
2009-07-31 13:27 . 2009-07-31 13:27 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\529701.exe
2009-07-31 13:27 . 2009-07-31 13:27 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\528359.exe
2009-07-31 13:25 . 2009-07-31 13:25 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\412029.exe
2009-07-31 13:24 . 2009-07-31 13:24 61440 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\359348.exe
2009-07-31 13:24 . 2009-07-31 13:24 1445 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\357351.exe
2009-07-31 13:17 . 2009-07-31 13:17 10286 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\624784.exe
2009-07-31 13:17 . 2009-07-31 13:17 10286 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\624160.exe
2009-07-31 13:17 . 2009-07-31 13:17 10286 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\623348.exe
2009-07-31 13:17 . 2009-07-31 13:17 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\619183.exe
2009-07-31 13:17 . 2009-07-31 13:17 766 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\618356.exe
2009-07-31 13:17 . 2009-07-31 13:17 766 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\617888.exe
2009-07-31 13:17 . 2009-07-31 13:17 766 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\616125.exe
2009-07-31 13:17 . 2009-07-31 13:17 5124 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\614706.exe
2009-07-31 13:16 . 2009-07-31 13:16 488 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\608513.exe
2009-07-31 13:16 . 2009-07-31 13:16 488 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\607623.exe
2009-07-31 13:16 . 2009-07-31 13:16 185 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\601181.exe
2009-07-31 13:16 . 2009-07-31 13:16 185 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\600323.exe
2009-07-31 13:16 . 2009-07-31 13:16 185 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\597546.exe
2009-07-31 13:16 . 2009-07-31 13:16 3252 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\595892.exe
2009-07-31 13:16 . 2009-07-31 13:16 3252 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\595081.exe
2009-07-31 13:16 . 2009-07-31 13:16 3252 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\591025.exe
2009-07-31 13:16 . 2009-07-31 13:16 10340 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\563756.exe
2009-07-31 13:16 . 2009-07-31 13:16 10340 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\559575.exe
2009-07-31 13:16 . 2009-07-31 13:16 10340 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\555987.exe
2009-07-31 13:13 . 2009-07-31 13:13 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\426241.exe
2009-07-31 13:13 . 2009-07-31 13:13 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\425648.exe
2009-07-31 13:13 . 2009-07-31 13:13 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\424884.exe
2009-07-31 13:13 . 2009-07-31 13:13 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\407162.exe
2009-07-31 13:13 . 2009-07-31 13:13 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\406117.exe
2009-07-31 13:13 . 2009-07-31 13:13 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\405072.exe
2009-07-31 13:13 . 2009-07-31 13:13 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\370798.exe
2009-07-31 13:12 . 2009-07-31 13:12 99332 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\365900.exe
2009-07-31 13:12 . 2009-07-31 13:12 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\329115.exe
2009-07-31 13:12 . 2009-07-31 13:12 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\328740.exe
2009-07-31 13:12 . 2009-07-31 13:12 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\327867.exe
2009-07-31 13:11 . 2009-07-31 13:11 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\284280.exe
2009-07-31 13:11 . 2009-07-31 13:11 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\268165.exe
2009-07-31 13:10 . 2009-07-31 13:10 99332 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\201631.exe
2009-07-31 11:35 . 2009-07-31 11:35 488 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\1070806.exe
2009-07-31 11:35 . 2009-07-31 11:35 488 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\1070026.exe
2009-07-31 11:35 . 2009-07-31 11:35 3601 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\1069574.exe
2009-07-31 11:35 . 2009-07-31 11:35 3601 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\1069433.exe
2009-07-31 11:35 . 2009-07-31 11:35 3601 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\1068388.exe
2009-07-31 11:34 . 2009-07-31 11:34 10322 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\1048030.exe
2009-07-31 11:34 . 2009-07-31 11:34 10322 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\1046844.exe
2009-07-31 11:34 . 2009-07-31 11:34 10322 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\1046002.exe
2009-07-31 11:33 . 2009-07-31 11:33 306 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\972385.exe
2009-07-31 11:33 . 2009-07-31 11:33 306 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\972369.exe
2009-07-31 11:33 . 2009-07-31 11:33 306 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\972042.exe
2009-07-31 11:33 . 2009-07-31 11:33 10313 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\955630.exe
2009-07-31 11:33 . 2009-07-31 11:33 10313 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\954944.exe
2009-07-31 11:33 . 2009-07-31 11:33 10313 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\954211.exe
2009-07-31 11:31 . 2009-07-31 11:31 610820 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\834371.exe
2009-07-31 11:31 . 2009-07-31 11:31 10286 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\824356.exe
2009-07-31 11:31 . 2009-07-31 11:31 10286 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\823841.exe
2009-07-31 11:31 . 2009-07-31 11:31 10286 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\819988.exe
2009-07-31 11:31 . 2009-07-31 11:31 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\818896.exe
2009-07-31 11:31 . 2009-07-31 11:31 766 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\817897.exe
2009-07-31 11:31 . 2009-07-31 11:31 766 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\817211.exe
2009-07-31 11:31 . 2009-07-31 11:31 766 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\815370.exe
2009-07-31 11:30 . 2009-07-31 11:30 488 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\808428.exe
2009-07-31 11:30 . 2009-07-31 11:30 488 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\807601.exe
2009-07-31 11:30 . 2009-07-31 11:30 185 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\801829.exe
2009-07-31 11:30 . 2009-07-31 11:30 185 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\800924.exe
2009-07-31 11:30 . 2009-07-31 11:30 185 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\798147.exe
2009-07-31 11:30 . 2009-07-31 11:30 3252 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\796899.exe
2009-07-31 11:30 . 2009-07-31 11:30 3252 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\795979.exe
2009-07-31 11:30 . 2009-07-31 11:30 3252 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\794747.exe
2009-07-31 11:30 . 2009-07-31 11:30 10340 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\786541.exe
2009-07-31 11:30 . 2009-07-31 11:30 10340 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\786291.exe
2009-07-31 11:30 . 2009-07-31 11:30 10340 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\785480.exe
2009-07-31 11:28 . 2009-07-31 11:28 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\641897.exe
2009-07-31 11:28 . 2009-07-31 11:28 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\641538.exe
2009-07-31 11:28 . 2009-07-31 11:28 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\640493.exe
2009-07-31 11:27 . 2009-07-31 11:27 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\603911.exe
2009-07-31 11:27 . 2009-07-31 11:27 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\602959.exe
2009-07-31 11:27 . 2009-07-31 11:27 10301 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\601773.exe
2009-07-31 11:27 . 2009-07-31 11:27 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\572976.exe
2009-07-31 11:27 . 2009-07-31 11:27 10250 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\570355.exe
2009-07-31 11:26 . 2009-07-31 11:26 99332 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\565222.exe
2009-07-31 11:26 . 2009-07-31 11:26 61440 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\485194.exe
2009-07-31 11:24 . 2009-07-31 11:24 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\421920.exe
2009-07-31 11:24 . 2009-07-31 11:24 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\421514.exe
2009-07-31 11:24 . 2009-07-31 11:24 10349 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\419237.exe
2009-07-31 11:23 . 2009-07-31 11:23 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\381438.exe
2009-07-31 11:23 . 2009-07-31 11:23 71684 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\360565.exe
2009-07-31 11:22 . 2009-08-01 09:16 -------- d--h--w- c:\users\Alessia\AppData\Roaming\m
2009-07-31 11:22 . 2009-07-31 13:28 99332 ------w- c:\users\Alessia\AppData\Roaming\m\flec006.exe
2009-07-31 11:22 . 2009-07-31 11:22 99332 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\326525.exe
2009-07-31 09:44 . 2009-08-01 09:23 -------- d-----w- c:\program files\FindyKill
2009-07-29 09:54 . 2009-07-29 09:54 1445 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\261498953.exe
2009-07-29 09:54 . 2009-07-29 09:54 99332 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\261497346.exe
2009-07-29 09:54 . 2009-07-29 09:54 99332 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\downld\261495443.exe
2009-07-29 09:54 . 2009-08-01 09:06 114959 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\111wfs1intwq.sys
2009-07-29 09:54 . 2009-08-01 09:06 7168 ----a-w- c:\users\Alessia\AppData\Roaming\drivers\11s11ro1s1a2.sys
2009-07-29 09:54 . 2004-05-19 08:05 856064 ------w- c:\users\Alessia\AppData\Roaming\drivers\winupgro.exe
2009-07-29 09:53 . 2009-07-29 09:54 -------- d--h--w- c:\users\Alessia\AppData\Roaming\drivers
2009-07-29 09:26 . 2009-07-29 09:37 -------- d-----w- c:\users\Alessia\AppData\Roaming\GetRightToGo
2009-07-26 09:42 . 2009-07-26 09:42 -------- d-----w- c:\users\Alessia\AppData\Roaming\Stellarium
2009-07-26 09:41 . 2009-07-26 09:42 -------- d-----w- c:\program files\Stellarium
2009-07-22 17:35 . 2009-07-22 17:35 -------- d-----w- c:\users\Alessia\AppData\Roaming\MonkeyJam
2009-07-22 17:35 . 2009-07-22 17:35 -------- d-----w- c:\program files\MonkeyJam
2009-07-22 16:35 . 2009-07-22 16:35 -------- d-----w- c:\program files\LuckyTender
2009-07-22 15:50 . 2009-07-22 15:50 -------- d-----w- c:\users\Alessia\AppData\Roaming\NeroDigital(TM)
2009-07-21 11:17 . 2009-07-21 11:17 -------- d-----w- c:\windows\system32\Adobe
2009-07-17 18:06 . 2009-07-17 18:06 -------- d-----w- c:\program files\Jufsoft
2009-07-17 17:37 . 2009-07-17 18:44 -------- d-----w- c:\program files\Runtime Software
2009-07-15 11:18 . 2009-06-15 15:24 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-15 11:18 . 2009-06-15 15:20 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-15 11:18 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-15 11:18 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-14 11:01 . 2009-07-14 11:01 -------- d-----w- c:\users\Alessia\AppData\Local\Hewlett-Packard
2009-07-09 11:54 . 2009-07-09 11:59 -------- d-----w- C:\audiograbber
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-01 09:37 . 2009-03-10 21:06 -------- d-----w- c:\progra~2\VMware
2009-08-01 09:33 . 2007-11-27 07:24 664544 ----a-w- c:\windows\system32\perfh010.dat
2009-08-01 09:33 . 2007-11-27 07:24 120952 ----a-w- c:\windows\system32\perfc010.dat
2009-08-01 09:25 . 2008-11-07 19:43 12 ----a-w- c:\windows\bthservsdp.dat
2009-07-31 13:18 . 2008-11-13 15:04 -------- d-----w- c:\program files\ESET
2009-07-31 08:43 . 2009-03-10 21:16 -------- d-----w- c:\users\Alessia\AppData\Roaming\VMware
2009-07-29 09:59 . 2008-05-27 00:45 -------- d-----w- c:\progra~2\NVIDIA
2009-07-29 09:53 . 2008-10-15 18:15 -------- d-----w- c:\program files\Common Files\LightScribe
2009-07-26 16:04 . 2008-05-27 00:41 -------- d-----w- c:\progra~2\WildTangent
2009-07-26 11:18 . 2008-08-10 18:34 27525 ----a-w- c:\users\Alessia\AppData\Roaming\nvModes.dat
2009-07-24 09:29 . 2009-02-27 18:09 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-16 13:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-16 13:20 . 2007-11-27 00:19 -------- d-----w- c:\progra~2\Microsoft Help
2009-07-15 15:17 . 2008-09-27 14:04 -------- d-----w- c:\program files\Foxit Software
2009-06-27 14:33 . 2009-06-27 14:33 -------- d-----w- c:\program files\Free iPod Video Converter
2009-06-27 14:21 . 2009-06-27 14:21 -------- d-----w- c:\program files\AviSynth 2.5
2009-06-27 14:11 . 2008-10-13 14:18 -------- d-----w- c:\progra~2\Nero
2009-06-26 14:50 . 2009-06-26 14:50 -------- d-----w- c:\program files\QUAD Utilities
2009-06-26 14:14 . 2009-04-21 17:28 -------- d-----w- c:\program files\OrCAD_Demo
2009-06-26 14:12 . 2008-08-10 13:37 117448 ----a-w- c:\users\Alessia\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-15 20:58 . 2009-06-15 20:58 -------- d-----w- c:\users\Alessia\AppData\Roaming\Uniblue
2009-06-10 05:48 . 2007-11-27 00:07 -------- d-----w- c:\program files\Microsoft Works
2009-06-09 19:51 . 2008-09-24 17:20 -------- d-----w- c:\users\Alessia\AppData\Roaming\Skype
2009-06-09 19:27 . 2008-09-24 17:22 -------- d-----w- c:\users\Alessia\AppData\Roaming\skypePM
2009-06-08 16:47 . 2009-06-08 16:47 -------- d-----w- c:\users\Alessia\AppData\Roaming\SharePod
2009-05-17 10:14 . 2008-09-29 16:56 7592 ----a-w- c:\users\Alessia\AppData\Local\d3d9caps.dat
2009-05-09 05:50 . 2009-06-26 13:55 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-26 13:55 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-05-03 17:00 . 2008-09-05 14:22 96 ----a-w- c:\users\Alessia\AppData\Roaming\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 1783136]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-11 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-25 174616]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2008-09-18 84528]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-08-17 4702208]
c:\users\Alessia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Sitecom Wireless Utility.lnk - c:\program files\Sitecom Europe BV\Common\SitecomUI.exe [2009-3-15 1572864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3104564014-82589701-1229868536-1000]
"EnableNotificationsRef"=dword:0000000a
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5DBB0C4D-969D-459E-A788-A31354634EC3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{DD521377-4A4F-4CED-AEA5-6A924730F285}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{09C2B2D1-0D75-4E60-AC02-ED58D3C8B862}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{1696ECB7-2E9A-42D2-9A56-2896720A8441}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{2A32C354-4AD9-42C2-99EA-7C1966AC3CFF}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{C3CFAB5E-10BC-410D-8852-C2E7DC655F99}"= UDP:c:\program files\eMule\emule.exe:eMule
"{6BB6D1D2-851F-4FA2-B2FA-04743F48AA25}"= TCP:c:\program files\eMule\emule.exe:eMule
"{5C2E6546-EA47-4E5F-A9EE-57F727C47C33}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{F6388495-ABD1-4EC1-AF4B-5DA7D8369766}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{DEFADB62-9810-4553-B03A-A99DA85005B0}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{0DAE7107-3642-40E5-8EFF-CC43F1343FF0}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3B1B8A94-A323-4F75-99E2-421566092112}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{9CD47C5A-7E85-4ACE-A353-F12BC444AD34}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{D9F24F6A-0702-443C-8FAA-FD833B9EAA2A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{E564024D-4564-473D-97F0-158B01C11E79}"= UDP:c:\program files\VMware\VMware Workstation\vmware-authd.exe:VMware Authd
"{2AA03A04-6208-4923-A13A-9EB004576960}"= TCP:c:\program files\VMware\VMware Workstation\vmware-authd.exe:VMware Authd
"{E3AA6B66-B7BF-4916-8F70-74F54E8F5965}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{7A4F8BC9-B9B3-43D6-AE94-828AC182EF9A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\System32\drivers\netr28u.sys [15/03/2009 19.12.52 599040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.libero.it/mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptopuInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar Cerca - c:\program files\aol\aol toolbar 5.0\resources\it-it\local\search.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\program files\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
Trusted Zone: mikeshinoda.com\www
.
**************************************************************************
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti:
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'Explorer.exe'(908)
c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\System32\audiodg.exe
c:\windows\System32\wlanext.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\oraclexe\app\oracle\product\10.2.0\server\BIN\oracle.exe
c:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE
c:\program files\Hp\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\Sitecom Europe BV\Common\RalinkRegistryWriter.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Photodex\ProShowGold\scsiaccess.exe
c:\windows\System32\vmnat.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\VMware\VMware Workstation\vmware-authd.exe
c:\windows\System32\vmnetdhcp.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\conime.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Ora fine scansione: 2009-08-01 11.44.58 - Il pc è stato riavviato [Alessia]
ComboFix-quarantined-files.txt 2009-08-01 09:44
Pre-Run: 97.301.610.496 byte disponibili
Post-Run: 94.040.915.968 byte disponibili
333 --- E O F --- 2009-07-23 17:48