ComboFix 09-10-19.04 - SS-Black_Jaguar-SS 20/10/2009 20.53.35.1.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.3070.1780 [GMT 2:00]
Eseguito da: c:\users\SS-Black_Jaguar-SS\Downloads\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {002D35B8-077F-0000-0000-000000002D00}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00310034-0034-0034-6300-630066003100}
SP: AntiVir Desktop *disabled* (Outdated) {002D35B8-077F-0000-0000-000000002D00}
SP: AntiVir Desktop *enabled* (Updated) {00310034-0034-0034-6300-630066003100}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\progra~1\GOOGLE~1\8GOOgl~1.dll
c:\program files\GooglePlusVideos
c:\program files\GooglePlusVideos\8.GooglePlusVideos.dll
c:\program files\GooglePlusVideos\DeploymentHelper.exe
c:\program files\GooglePlusVideos\FFExt\chrome.manifest
c:\program files\GooglePlusVideos\FFExt\chrome\content\googleplusvideos.xul
c:\program files\GooglePlusVideos\FFExt\chrome\content\script-injector.js
c:\program files\GooglePlusVideos\FFExt\install.rdf
c:\program files\GooglePlusVideos\GooglePlusVideosLicense.txt
c:\program files\GooglePlusVideos\GVConfig.ini
c:\program files\GooglePlusVideos\MFC42U.DLL
c:\program files\GooglePlusVideos\Uninstall.bat
.
((((((((((((((((((((((((( Files Creati Da 2009-09-20 al 2009-10-20 )))))))))))))))))))))))))))))))))))
.
2009-10-20 18:59 . 2009-10-20 18:59 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Local\temp
2009-10-20 18:59 . 2009-10-20 18:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-20 11:47 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-20 11:47 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-20 11:47 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-20 11:47 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-20 11:45 . 2009-08-06 17:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-20 11:45 . 2009-08-06 16:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-19 22:06 . 2009-10-19 22:37 -------- d-----w- C:\FindyKill
2009-10-19 21:37 . 2009-10-19 21:37 -------- d-----w- c:\windows\system32\dllcache
2009-10-18 00:11 . 2003-03-28 11:56 147456 ------w- c:\windows\system32\ncPopup2.dll
2009-10-18 00:11 . 2003-03-27 08:03 40960 ------w- c:\windows\system32\ncSSTimer2.dll
2009-10-18 00:11 . 2002-11-25 10:31 155648 ------w- c:\windows\system32\DartCertificate.dll
2009-10-16 01:26 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-16 01:25 . 2009-08-27 12:40 834048 ----a-w- c:\windows\system32\wininet.dll
2009-10-16 01:25 . 2009-08-27 13:29 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-16 01:25 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-16 01:25 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-16 01:25 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-16 01:25 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-16 01:25 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-15 21:42 . 2009-10-15 21:42 -------- d-----w- c:\program files\BurnAware Free
2009-10-15 18:25 . 2009-10-15 18:25 -------- d-----w- c:\program files\InfraRecorder
2009-10-15 18:08 . 2009-10-15 18:08 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\StarBurn
2009-10-15 18:06 . 2009-03-02 13:00 95592 ----a-w- c:\windows\system32\drivers\StarPortLite.sys
2009-10-15 18:04 . 2009-10-16 06:30 -------- d-----w- c:\program files\Feurio
2009-10-15 17:51 . 2009-10-15 17:51 -------- d-----w- c:\program files\Jookz
2009-10-15 17:51 . 2009-10-19 16:06 -------- d-----w- c:\programdata\Zwunzi
2009-10-15 17:51 . 2009-10-19 16:06 -------- d-----w- c:\program files\Zwunzi
2009-10-15 17:51 . 2009-10-15 17:51 -------- d-----w- c:\programdata\MessengerDiscovery 2
2009-10-15 12:43 . 2009-10-15 12:43 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\InfraRecorder
2009-10-13 10:29 . 2009-10-13 10:29 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Local\BVRP Software
2009-10-13 10:28 . 2009-10-13 10:30 -------- d-----w- c:\program files\Avanquest update
2009-10-13 10:25 . 2009-10-13 10:49 -------- d-----w- c:\programdata\BVRP Software
2009-10-13 10:25 . 2009-10-13 10:48 -------- d-----w- c:\program files\Motorola Phone Tools
2009-10-13 10:16 . 2009-10-13 10:16 -------- d-----w- c:\users\SS-Black_Jaguar-SS\{eda9c682-fa5c-4cd0-9ccc-9b5c1a0874ac}
2009-10-13 10:03 . 2009-10-13 10:03 -------- d-----w- c:\users\SS-Black_Jaguar-SS\{d8280039-aa23-4950-a9e3-c0ac23e19ff5}
2009-10-13 09:12 . 2009-10-13 09:12 -------- d-----w- c:\users\SS-Black_Jaguar-SS\{30f421a4-0ccd-4279-9c09-0183b5825da0}
2009-10-13 08:11 . 2009-10-13 08:11 -------- d-----w- c:\program files\Common Files\Motorola Shared
2009-10-10 16:05 . 2009-10-10 16:05 -------- d-----w- c:\programdata\Minnetonka Audio Software
2009-10-10 09:58 . 2009-10-18 11:53 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\vlc
2009-10-08 05:01 . 2009-10-08 18:00 -------- d-sh--w- c:\users\SS-Black_Jaguar-SS\Phone Browser
2009-10-06 18:25 . 2009-10-06 18:25 -------- d-----w- c:\program files\Winstep
2009-10-06 18:25 . 1997-07-19 14:55 1347344 ----a-w- c:\windows\system32\msvbvm50.dll
2009-10-06 08:45 . 2009-10-06 08:45 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Local\Scansoft
2009-10-04 10:16 . 2009-10-04 10:16 -------- d-----w- c:\programdata\InstallShield
2009-10-04 10:16 . 2009-10-04 10:16 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Nuance
2009-10-04 10:13 . 2009-10-04 10:13 -------- d-----w- c:\programdata\ScanSoft
2009-10-04 10:13 . 2009-10-04 10:13 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2009-10-04 10:13 . 2009-10-04 10:13 -------- d-----w- c:\program files\Common Files\Nuance
2009-10-04 10:12 . 2009-10-04 10:12 -------- d-----w- c:\programdata\Nuance
2009-10-04 10:12 . 2009-10-04 10:12 -------- d-----w- c:\program files\Nuance
2009-10-03 10:05 . 2009-10-03 10:05 -------- d-----w- c:\programdata\SSScanAppDataDir
2009-10-03 10:05 . 2009-10-03 10:05 -------- d-----w- c:\programdata\MSScanAppDataDir
2009-10-02 21:50 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-01 06:47 . 1998-10-02 17:00 327168 ----a-w- c:\windows\IsUninst.exe
2009-09-30 11:44 . 2009-09-30 11:44 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\dvdcss
2009-09-28 10:44 . 2009-09-28 10:44 -------- d-----w- c:\program files\iPod
2009-09-28 10:43 . 2009-10-17 22:07 -------- d-----w- c:\program files\iTunes
2009-09-27 20:40 . 2009-09-27 20:40 -------- d-----w- c:\program files\Toshiba
2009-09-27 17:19 . 2009-09-27 17:19 -------- d-----w- c:\program files\Recuva
2009-09-25 23:19 . 2009-09-25 23:03 11448 ----a-w- c:\windows\system32\drivers\AsUpIO.sys
2009-09-25 10:40 . 2009-09-25 10:40 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-09-23 21:44 . 2009-09-23 21:44 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Nseries
2009-09-22 10:47 . 2009-09-22 10:47 -------- d-----w- c:\program files\RADVideo
2009-09-22 08:51 . 2009-09-22 08:51 -------- d-----w- c:\windows\system32\xlive
2009-09-22 08:51 . 2009-09-22 08:52 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-09-22 08:50 . 2009-09-22 08:50 -------- d-----w- c:\windows\system32\AGEIA
2009-09-22 08:50 . 2009-09-22 08:50 -------- d-----w- c:\program files\AGEIA Technologies
2009-09-22 08:48 . 2009-09-22 08:49 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-22 08:48 . 2008-10-10 02:52 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2009-09-22 08:48 . 2008-10-10 02:52 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2009-09-22 08:48 . 2008-10-10 02:52 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2009-09-22 08:48 . 2008-10-27 08:04 514384 ----a-w- c:\windows\system32\XAudio2_3.dll
2009-09-22 08:48 . 2008-10-27 08:04 235856 ----a-w- c:\windows\system32\xactengine3_3.dll
2009-09-22 08:48 . 2008-10-27 08:04 70992 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2009-09-22 08:48 . 2008-10-27 08:04 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2009-09-22 08:14 . 2009-09-22 08:14 -------- d-----w- c:\program files\Eidos
2009-09-20 22:23 . 2009-09-20 22:23 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Subversion
2009-09-20 22:02 . 2009-09-20 22:02 -------- d-----w- c:\users\Public\Roaming
2009-09-20 22:02 . 2009-09-20 22:02 -------- d-----w- c:\users\SS-Black_Jaguar-SS\Library
2009-09-20 22:02 . 2009-09-20 22:02 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\com.adobe.ExMan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-20 18:28 . 2006-11-06 01:52 706428 ----a-w- c:\windows\system32\perfc010.dat
2009-10-20 18:28 . 2006-11-06 01:52 2345666 ----a-w- c:\windows\system32\perfh010.dat
2009-10-20 18:24 . 2009-08-25 08:22 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Skype
2009-10-20 09:20 . 2009-09-19 10:47 12 ----a-w- c:\windows\bthservsdp.dat
2009-10-19 21:49 . 2009-08-15 21:11 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-19 15:21 . 2009-08-14 15:25 139632 ----a-w- c:\users\SS-Black_Jaguar-SS\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-19 13:04 . 2009-08-25 23:00 -------- d-----w- c:\program files\AVS4YOU
2009-10-19 06:18 . 2009-08-16 18:41 -------- d-----w- c:\programdata\Nero
2009-10-18 12:27 . 2009-08-15 01:17 -------- d-----w- c:\program files\JetAudio
2009-10-18 12:27 . 2009-08-15 01:17 -------- d-----w- c:\program files\Common Files\COWON
2009-10-18 00:10 . 2009-10-18 00:10 -------- d-----w- c:\program files\nanoCom Corporation
2009-10-18 00:10 . 2009-08-14 15:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-17 22:10 . 2009-08-16 16:50 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Apple Computer
2009-10-16 06:28 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-16 06:21 . 2009-08-16 16:31 -------- d-----w- c:\programdata\Microsoft Help
2009-10-15 21:41 . 2009-08-25 23:02 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\AVS4YOU
2009-10-15 18:08 . 2009-08-15 00:34 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-10-15 18:00 . 2009-08-28 11:57 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\MessengerDiscovery 2
2009-10-15 17:51 . 2009-08-31 23:03 -------- d-----w- c:\program files\MessengerDiscovery 2
2009-10-15 12:41 . 2009-08-31 22:41 -------- d-----w- c:\programdata\NCH Swift Sound
2009-10-15 12:41 . 2009-08-31 22:41 -------- d-----w- c:\program files\NCH Swift Sound
2009-10-13 10:54 . 2009-08-31 22:04 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\BitTorrent
2009-10-13 10:49 . 2009-10-13 10:49 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-10-13 10:34 . 2009-08-18 17:06 9232 ----a-w- c:\users\SS-Black_Jaguar-SS\mqdmmdfl.sys
2009-10-13 10:34 . 2009-08-18 17:06 92064 ----a-w- c:\users\SS-Black_Jaguar-SS\mqdmmdm.sys
2009-10-13 10:34 . 2009-08-18 17:06 79328 ----a-w- c:\users\SS-Black_Jaguar-SS\mqdmserd.sys
2009-10-13 10:34 . 2009-08-18 17:06 5936 ----a-w- c:\users\SS-Black_Jaguar-SS\mqdmwhnt.sys
2009-10-13 10:34 . 2009-08-18 17:06 4048 ----a-w- c:\users\SS-Black_Jaguar-SS\mqdmcr.sys
2009-10-13 10:34 . 2009-08-18 17:06 66656 ----a-w- c:\users\SS-Black_Jaguar-SS\mqdmbus.sys
2009-10-13 10:34 . 2009-08-18 17:06 6208 ----a-w- c:\users\SS-Black_Jaguar-SS\mqdmcmnt.sys
2009-10-13 10:34 . 2009-08-18 17:06 25600 ----a-w- c:\users\SS-Black_Jaguar-SS\usbsermptxp.sys
2009-10-13 10:34 . 2009-08-18 17:06 22768 ----a-w- c:\users\SS-Black_Jaguar-SS\usbsermpt.sys
2009-10-13 08:39 . 2009-08-18 17:06 25600 ----a-w- c:\windows\system32\drivers\usbsermptxp.sys
2009-10-04 11:15 . 2009-10-04 11:15 2913 ----a-w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\SAS7_000.DAT
2009-10-04 10:13 . 2009-08-14 15:39 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-02 18:28 . 2009-08-15 22:56 -------- d-----w- c:\program files\Microsoft
2009-10-01 06:50 . 2009-08-15 20:47 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-01 06:50 . 2009-09-10 09:47 -------- d-----w- c:\program files\Common Files\Real
2009-09-28 10:44 . 2009-08-16 17:23 -------- d-----w- c:\program files\Common Files\Apple
2009-09-28 06:27 . 2009-08-14 15:39 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Winamp
2009-09-26 20:02 . 2009-08-22 21:47 -------- d-----w- c:\program files\Google
2009-09-25 23:19 . 2009-08-14 15:45 -------- d-----w- c:\program files\ASUS
2009-09-25 23:03 . 2009-08-14 16:10 12400 ----a-w- c:\windows\system32\drivers\AsIO.sys
2009-09-25 14:59 . 2009-09-19 10:13 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Toshiba
2009-09-25 10:51 . 2009-08-14 15:25 1356 ----a-w- c:\users\SS-Black_Jaguar-SS\AppData\Local\d3d9caps.dat
2009-09-25 10:43 . 2009-08-14 23:29 -------- d-----w- c:\program files\Common Files\Nokia
2009-09-25 10:40 . 2009-08-14 23:23 -------- d-----w- c:\program files\Nokia
2009-09-24 06:04 . 2009-08-15 22:33 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\skypePM
2009-09-20 17:38 . 2009-08-14 16:04 -------- d-----w- c:\program files\Realtek
2009-09-20 13:44 . 2009-08-20 22:20 -------- d--h--w- c:\program files\Temp
2009-09-20 13:26 . 2009-09-20 13:35 1933312 ----a-w- c:\windows\system32\MaxxAudioEQ.dll
2009-09-20 13:26 . 2009-09-20 13:35 306176 ----a-w- c:\windows\system32\MaxxAudioAPO20.dll
2009-09-20 13:26 . 2009-09-20 13:35 126976 ----a-w- c:\windows\system32\MaxxAudioAPO.dll
2009-09-20 13:26 . 2009-09-20 13:35 267264 ----a-w- c:\windows\system32\FMAPO.dll
2009-09-20 13:26 . 2009-09-20 13:35 142848 ----a-w- c:\windows\system32\AERTACap.dll
2009-09-20 13:26 . 2009-09-20 13:35 125952 ----a-w- c:\windows\system32\AERTARen.dll
2009-09-20 13:26 . 2009-09-20 13:35 831488 ----a-w- c:\windows\RtlExUpd.dll
2009-09-17 16:53 . 2009-09-17 15:53 -------- d-----w- c:\program files\WinAVI MP4 Converter
2009-09-14 11:08 . 2009-09-14 11:08 -------- d-----w- c:\program files\Utility Configurazione iPhone
2009-09-14 11:07 . 2009-09-14 11:06 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-14 11:05 . 2009-09-14 11:04 -------- d-----w- c:\program files\QuickTime
2009-09-12 11:37 . 2009-08-31 10:14 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\ooVoo Details
2009-09-12 11:36 . 2009-08-31 10:14 -------- d-----w- c:\program files\ooVoo
2009-09-11 08:11 . 2009-09-10 09:53 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\SoundSpectrum
2009-09-10 09:48 . 2009-08-14 15:39 -------- d-----w- c:\program files\Winamp
2009-09-09 09:44 . 2009-08-16 07:28 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-09 00:15 . 2009-09-06 04:02 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Camfrog
2009-09-06 17:06 . 2009-09-06 15:17 -------- d-----w- c:\program files\JDownloader 0.8
2009-09-06 04:01 . 2009-09-06 04:01 -------- d-----w- c:\program files\Camfrog
2009-09-05 09:32 . 2009-09-05 07:19 -------- d-----w- c:\programdata\AQ
2009-09-04 12:00 . 2009-09-04 12:00 -------- d-----w- c:\program files\Free Audio Pack
2009-09-03 12:43 . 2009-09-03 12:43 -------- d-----w- c:\program files\Western Digital Corporation
2009-09-02 09:31 . 2009-09-02 09:31 -------- d-----w- c:\program files\VideoLAN
2009-08-31 22:56 . 2009-08-31 22:56 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Recordpad
2009-08-31 22:42 . 2009-08-31 22:41 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\NCH Swift Sound
2009-08-31 22:41 . 2009-08-31 22:41 -------- d-----w- c:\program files\NCH Software
2009-08-31 22:38 . 2009-08-31 22:38 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Canneverbe_Limited
2009-08-31 22:38 . 2009-08-31 22:38 -------- d-----w- c:\programdata\Canneverbe Limited
2009-08-31 22:04 . 2009-08-31 22:04 -------- d-----w- c:\program files\BitTorrent
2009-08-30 21:59 . 2009-08-30 21:59 -------- d-----w- c:\program files\Trend Micro
2009-08-30 01:17 . 2009-08-30 01:17 -------- d-----w- c:\programdata\Messenger Plus!
2009-08-29 21:52 . 2009-08-29 11:43 -------- d-----w- c:\program files\Unlocker
2009-08-29 00:27 . 2009-09-02 11:16 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-02 11:16 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 17:42 . 2009-08-28 17:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 17:42 . 2009-08-28 17:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 12:10 . 2009-08-28 12:10 -------- d-----w- c:\program files\Defraggler
2009-08-28 12:01 . 2009-08-28 12:01 -------- d-----w- c:\program files\Messenger Plus! Live
2009-08-28 09:37 . 2009-08-28 09:37 -------- d-----w- c:\program files\VirtualDubMod_1_5_10_2_b2542
2009-08-26 16:08 . 2009-08-15 22:16 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Autodesk
2009-08-26 16:08 . 2009-08-15 21:57 -------- d-----w- c:\programdata\Autodesk
2009-08-26 16:06 . 2009-08-15 22:06 -------- d-----w- c:\programdata\FLEXnet
2009-08-26 14:22 . 2009-08-26 14:22 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-08-26 08:36 . 2009-08-14 23:32 -------- d-----w- c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Nokia
2009-08-25 23:02 . 2009-08-25 23:02 -------- d-----w- c:\programdata\AVS4YOU
2009-08-25 23:02 . 2009-08-25 23:01 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-08-25 17:03 . 2009-08-25 17:03 13824 ----a-w- c:\windows\system32\drivers\splitcam.sys
2009-08-25 17:03 . 2009-08-25 17:03 -------- d-----w- c:\program files\SplitCam
2009-08-25 14:09 . 2009-08-25 14:07 -------- d-----w- c:\program files\Total Video Converter
2009-08-25 11:59 . 2009-08-25 11:59 -------- d-----w- c:\programdata\TechSmith
2009-04-07 18:52 . 2009-04-07 18:52 28672 ----a-w- c:\program files\mozilla firefox\components\GooglePlusVideosXPCOM.dll
2009-08-09 21:14 . 2009-08-09 21:14 49152 ----a-w- c:\program files\mozilla firefox\components\SuperSearchXPCOM.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2009-01-04 743936]
"SplitCam"="c:\program files\SplitCam\SplitCam.exe" [2006-09-09 990208]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="c:\users\SS-Black_Jaguar-SS\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-08-20 133104]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Camtasia Recorder"="c:\program files\TechSmith\Camtasia Studio 6\CamRecorder.exe" [2008-10-10 2678104]
"Camfrog"="c:\program files\Camfrog\Camfrog Video Chat\CamfrogNet.exe" [2009-06-16 41800]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2009-02-22 5668864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-09-20 7739936]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-19 149280]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2008-7-23 427336]
jetAudio.lnk - c:\program files\JetAudio\JetAudio.exe [2009-8-15 3008512]
Trillian.lnk - c:\program files\Trillian\trillian.exe [2009-7-16 1873272]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"UacDisableNotify"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):35,62,8d,43,3b,1d,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-534440758-3768623821-1441760294-1000]
"EnableNotificationsRef"=dword:00000001
R1 AsUpIO;AsUpIO;c:\windows\System32\drivers\AsUpIO.sys [26/09/2009 1.19.08 11448]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\System32\drivers\StarPortLite.sys [15/10/2009 20.06.40 95592]
R2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe -k bthaudiosvc [15/08/2009 0.24.21 21504]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [27/08/2009 17.05.04 92008]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [16/08/2009 2.43.28 208144]
R2 Winstep Xtreme Service;Winstep Xtreme Service;c:\program files\Winstep\WsxService

c:\program files\Winstep\WsxService
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max Design 2010 32-bit 32-bit;c:\program files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [12/03/2009 17.36.24 86016]
S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30/03/2009 16.28.36 1533808]
S3 BthAudioHF;Servizio Audio vivavoce Bluetooth;c:\windows\System32\drivers\BthAudioHF.sys [10/07/2008 15.44.12 30208]
S3 BthAvrcp;Profilo Bluetooth AVRCP;c:\windows\System32\drivers\BthAvrcp.sys [10/07/2008 15.43.32 15872]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\System32\drivers\nmwcdnsu.sys [19/03/2009 14.48.18 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\System32\drivers\nmwcdnsuc.sys [19/03/2009 14.48.12 8320]
S4 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15/08/2008 5.46.20 284016]
S4 gupdate1ca23724714d2b8;Servizio di Google Update (gupdate1ca23724714d2b8);c:\program files\Google\Update\GoogleUpdate.exe [22/08/2009 23.48.25 133104]
S4 TwonkyMedia;TwonkyMedia;c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0

c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
bthaudiosvc REG_MULTI_SZ HFGService
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-22 21:47]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-22 21:48]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-22 21:48]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-534440758-3768623821-1441760294-1000Core.job
- c:\users\SS-Black_Jaguar-SS\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-20 10:36]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-534440758-3768623821-1441760294-1000UA.job
- c:\users\SS-Black_Jaguar-SS\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-20 10:36]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/mStart Page =
hxxp://www.europowersearch.com/Search.h ... rchLang=ITIE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: {EAC8D54E-57C3-46D6-9A2C-EFA2BE4B101E} = 85.37.17.57 85.38.28.80
FF - ProfilePath - c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Mozilla\Firefox\Profiles\rl0tibof.default\
FF - prefs.js: browser.search.selectedEngine - Google Search Community
FF - prefs.js: browser.startup.homepage -
hxxp://it.start3.mozilla.com/firefox?cl ... t:officialFF - component: c:\program files\Mozilla Firefox\components\GooglePlusVideosXPCOM.dll
FF - component: c:\program files\Mozilla Firefox\components\SuperSearchXPCOM.dll
FF - component: c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Mozilla\Firefox\Profiles\rl0tibof.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Mozilla\Firefox\Profiles\rl0tibof.default\extensions\piclens@cooliris.com\components\cooliris.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1691.8062\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\users\SS-Black_Jaguar-SS\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\users\SS-Black_Jaguar-SS\AppData\Roaming\Mozilla\Firefox\Profiles\rl0tibof.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti:
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winstep Xtreme Service]
"ImagePath"="c:\program files\Winstep\WsxService"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2009-10-20 21.01.01
ComboFix-quarantined-files.txt 2009-10-20 19:00
Pre-Run: 76.455.858.176 byte disponibili
Post-Run: 76.504.010.752 byte disponibili
- - End Of File - - 55C92696E026FB33D6D45CC225724457