JustPaste.it

ComboFix 13-01-05.01 - casa 05/01/2013 19:01:31.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.3958.2650 [GMT 1:00]
Eseguito da: c:\users\casa\Desktop\paranoia\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Creati Da 2012-12-05 al 2013-01-05 )))))))))))))))))))))))))))))))))))
.
.
2013-01-05 18:07 . 2013-01-05 18:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-05 15:28 . 2013-01-05 15:28 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C2CE73E1-4D4D-4A3E-AB38-5D2F94DA4289}\offreg.dll
2013-01-05 15:04 . 2013-01-05 15:04 -------- d-----w- c:\program files (x86)\VS Revo Group
2013-01-05 12:10 . 2013-01-05 12:10 -------- d-----w- C:\$WINDOWS.~BT
2013-01-05 07:52 . 2013-01-05 08:03 -------- d-----w- c:\users\casa\AppData\Roaming\ImgBurn
2013-01-05 07:48 . 2013-01-05 07:48 -------- d-----w- c:\program files (x86)\ImgBurn
2013-01-05 05:45 . 2013-01-05 05:45 65736 ----a-w- c:\windows\system32\drivers\pxrts.sys
2013-01-05 05:45 . 2013-01-05 05:45 -------- d-----w- c:\program files\Prevx
2013-01-05 05:44 . 2013-01-05 08:10 -------- d-----w- c:\programdata\PrevxCSI
2013-01-05 05:15 . 2013-01-05 05:15 -------- d-----w- C:\MGADiagToolOutput
2013-01-05 05:14 . 2013-01-05 05:14 -------- d-----w- c:\programdata\Office Genuine Advantage
2013-01-05 05:06 . 2012-11-19 00:01 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C2CE73E1-4D4D-4A3E-AB38-5D2F94DA4289}\mpengine.dll
2013-01-04 22:58 . 2013-01-05 04:46 -------- d-----w- c:\windows\system32\MpEngineStore
2013-01-04 17:01 . 2013-01-04 17:01 -------- d-----w- c:\users\casa\AppData\Roaming\Malwarebytes
2013-01-04 17:01 . 2013-01-04 17:01 -------- d-----w- c:\programdata\Malwarebytes
2013-01-04 15:33 . 2013-01-04 15:33 -------- d-----w- C:\7219ac651ca896f0e69961
2013-01-04 13:09 . 2013-01-04 13:09 -------- d-s---w- c:\windows\SysWow64\Microsoft
2013-01-04 12:35 . 2013-01-04 12:35 -------- d-----w- c:\users\casa\AppData\Local\Apps
2013-01-04 11:48 . 2013-01-04 11:54 -------- d-----w- C:\dfacb89c1a0c9800e5de2b0b202b76ef
2013-01-04 11:31 . 2013-01-04 11:33 -------- d-----w- C:\a8a3a0ee9c0d5a0373
2013-01-04 11:21 . 2013-01-04 11:25 -------- d-----w- C:\35b4de9e214c7761e194cf8632b9
2013-01-04 10:50 . 2013-01-04 11:20 -------- d-----w- C:\274b17ebfd442e44f9642bf88a76f51e
2013-01-04 08:12 . 2013-01-04 08:14 -------- d-----w- C:\b57d8fa071858f183b3c10442ced
2013-01-04 07:15 . 2013-01-04 07:16 -------- d-----w- C:\578da4eb8558fea4ef6e80a78acb8b06
2013-01-04 07:10 . 2013-01-04 07:11 -------- d-----w- C:\4dafaf290d4bc17bfbf1f28bed98
2013-01-04 06:55 . 2013-01-04 06:55 -------- d-----w- c:\users\casa\AppData\Local\Supremus Corporation
2013-01-04 06:46 . 2013-01-04 06:46 -------- d-----w- C:\RegBackup
2013-01-04 06:28 . 2013-01-04 06:48 -------- d-----w- C:\Tweaking.com_Windows_Repair_Logs
2013-01-03 19:52 . 2013-01-04 23:40 -------- d-----w- c:\program files\WinRAR
2013-01-03 19:49 . 2013-01-05 04:46 -------- d-----w- c:\users\casa\AppData\Roaming\uTorrent
2013-01-03 19:44 . 2013-01-04 22:58 -------- d-----w- c:\program files\Registry Easy
2013-01-03 18:21 . 2013-01-03 18:21 -------- d-----w- c:\users\casa\AppData\Roaming\FLEXnet
2013-01-03 17:54 . 2013-01-03 17:54 -------- d-----w- c:\users\casa\AppData\Roaming\Vodafone
2013-01-03 17:54 . 2013-01-03 17:54 -------- d-----w- c:\programdata\Vodafone
2013-01-03 17:54 . 2013-01-03 17:54 -------- d-----w- c:\program files (x86)\Vodafone
2013-01-03 10:09 . 2013-01-04 16:22 -------- d-----w- c:\program files (x86)\RegDefense
2013-01-03 08:32 . 2013-01-03 08:32 -------- d-----w- c:\windows\en
2013-01-03 08:32 . 2013-01-03 08:32 -------- d-----w- c:\windows\it
2013-01-03 08:30 . 2012-09-12 14:20 57856 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2013-01-03 08:29 . 2010-06-02 03:55 77656 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2013-01-03 08:29 . 2010-06-02 03:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2013-01-03 08:29 . 2010-06-02 03:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2013-01-03 08:29 . 2010-06-02 03:55 518488 ----a-w- c:\windows\system32\XAudio2_7.dll
2013-01-03 08:29 . 2010-05-26 10:41 276832 ----a-w- c:\windows\system32\d3dx11_43.dll
2013-01-03 08:29 . 2010-05-26 10:41 2526056 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2013-01-03 08:29 . 2010-05-26 10:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2013-01-03 08:29 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2013-01-03 08:28 . 2009-09-04 16:29 453456 ----a-w- c:\windows\SysWow64\d3dx10_42.dll
2013-01-03 08:28 . 2009-09-04 16:29 523088 ----a-w- c:\windows\system32\d3dx10_42.dll
2013-01-03 08:27 . 2013-01-03 08:27 -------- d-----w- c:\program files (x86)\Microsoft SkyDrive
2013-01-03 08:27 . 2013-01-03 08:27 -------- d-----r- c:\users\casa\SkyDrive
2013-01-03 08:27 . 2013-01-03 08:26 5659096 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\1282e8101cde98c05\skydrivesetup.exe
2013-01-03 08:27 . 2013-01-03 08:27 -------- d-----w- c:\programdata\Microsoft SkyDrive
2013-01-03 08:26 . 2013-01-03 08:26 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\ef1798f1cde98c04\DSETUP.dll
2013-01-03 08:26 . 2013-01-03 08:26 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\ef1798f1cde98c04\DXSETUP.exe
2013-01-03 08:26 . 2013-01-03 08:26 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\ef1798f1cde98c04\dsetup32.dll
2013-01-03 08:26 . 2013-01-03 08:26 -------- d-----w- c:\users\casa\AppData\Roaming\vlc
2013-01-03 08:26 . 2013-01-03 08:26 94040 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\9b0a32a1cde98c03\DSETUP.dll
2013-01-03 08:26 . 2013-01-03 08:26 525656 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\9b0a32a1cde98c03\DXSETUP.exe
2013-01-03 08:26 . 2013-01-03 08:26 1691480 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\9b0a32a1cde98c03\dsetup32.dll
2013-01-03 08:26 . 2013-01-03 08:26 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\33fe1681cde98c01\DSETUP.dll
2013-01-03 08:26 . 2013-01-03 08:26 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\33fe1681cde98c01\DXSETUP.exe
2013-01-03 08:26 . 2013-01-03 08:26 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\33fe1681cde98c01\dsetup32.dll
2013-01-03 08:23 . 2013-01-03 08:23 -------- d-----w- c:\program files (x86)\TeamViewer
2013-01-03 08:20 . 2013-01-03 08:20 -------- d-----w- c:\users\casa\AppData\Roaming\TeamViewer
2013-01-03 08:20 . 2012-08-21 12:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-01-03 08:19 . 2013-01-03 08:19 -------- d-----w- c:\program files\iPod
2013-01-03 08:19 . 2013-01-03 08:20 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-01-03 08:19 . 2013-01-03 08:20 -------- d-----w- c:\program files\iTunes
2013-01-03 08:19 . 2013-01-03 08:20 -------- d-----w- c:\program files (x86)\iTunes
2013-01-03 08:15 . 2013-01-03 08:15 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-01-03 08:14 . 2013-01-03 08:13 959976 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-03 08:14 . 2013-01-03 08:13 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-03 07:16 . 2013-01-03 07:16 -------- d-----w- c:\program files (x86)\VideoLAN
2013-01-03 07:16 . 2013-01-03 07:16 -------- d-----w- c:\program files (x86)\FileHippo.com
2013-01-03 06:56 . 2013-01-03 06:56 -------- d-----w- c:\users\casa\AppData\Local\CutePDF Writer
2013-01-03 06:56 . 2013-01-03 06:56 -------- d-----w- c:\program files (x86)\GPLGS
2013-01-03 06:54 . 2012-10-04 18:49 87152 ----a-w- c:\windows\system32\cpwmon64.dll
2013-01-03 06:54 . 2013-01-03 06:54 -------- d-----w- c:\program files (x86)\Acro Software
2013-01-03 05:13 . 2013-01-03 05:13 -------- d-----w- c:\program files (x86)\Emsisoft HiJackFree
2013-01-03 04:42 . 2013-01-03 04:42 -------- d-----w- c:\program files\CCleaner
2013-01-02 19:24 . 2013-01-05 16:19 -------- d-----w- c:\programdata\AVAST Software
2013-01-02 19:24 . 2013-01-02 19:24 -------- d-----w- c:\program files\AVAST Software
2013-01-02 19:17 . 2013-01-05 15:15 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-01-02 19:17 . 2009-01-25 11:14 17272 ----a-w- c:\windows\system32\sdnclean64.exe
2013-01-02 19:17 . 2013-01-05 15:16 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2013-01-02 19:16 . 2013-01-02 19:16 -------- d-----w- c:\users\casa\AppData\Local\Programs
2013-01-02 19:14 . 2013-01-02 19:14 -------- d-----w- c:\users\casa\AppData\Local\Google
2012-12-13 13:30 . 2012-12-13 13:30 5955856 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-03 08:09 . 2012-09-21 15:38 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-03 08:09 . 2011-05-18 17:09 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-14 03:52 . 2012-06-12 12:07 477168 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-11-14 03:52 . 2010-07-19 06:08 473072 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-10-25 02:12 . 2012-10-25 02:12 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-25 02:12 . 2012-10-25 02:12 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-01-03 08:27 220632 ----a-w- c:\users\casa\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-01-03 08:27 220632 ----a-w- c:\users\casa\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-01-03 08:27 220632 ----a-w- c:\users\casa\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-11-09 17877168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"<NO NAME>"=
.
R1 bqddppvj;bqddppvj;c:\windows\system32\drivers\bqddppvj.sys [x]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-12-13 3290896]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
R3 esihdrv;esihdrv;c:\users\casa\AppData\Local\Temp\esihdrv.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-05-10 22528]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-23 225280]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-19 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
S1 A2DDA;A2 Direct Disk Access Support Driver;c:\users\CASA\DESKTOP\PARANOIA\EMSISOFTEMERGENCYKIT\RUN\a2ddax64.sys [2013-01-03 23208]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-25 202752]
S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2011-03-14 11576]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-10-24 291328]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-10-16 11:49 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contenuto della cartella 'Scheduled Tasks'
.
2013-01-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-21 08:09]
.
2012-12-19 c:\windows\Tasks\HPCeeScheduleForcasa.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13 21:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-01-03 08:27 244696 ----a-w- c:\users\casa\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-01-03 08:27 244696 ----a-w- c:\users\casa\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-01-03 08:27 244696 ----a-w- c:\users\casa\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2009-12-22 5977600]
"RtkOSD"="c:\program files (x86)\Realtek\Audio\OSD\RtVOsd64.exe" [2009-10-13 995840]
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
Trusted Zone: privalia.com\it.secure
Trusted Zone: trenitalia.com\orario
TCP: Interfaces\{75822BEF-F019-409D-A8A6-23EA4D6A8FC2}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{8478AFF0-BAE3-40A5-9D7C-8BF6CA1C6F92}: NameServer = 212.216.112.112
FF - ProfilePath - c:\users\casa\AppData\Roaming\Mozilla\Firefox\Profiles\4o77m5pl.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - about:home
FF - ExtSQL: 2013-01-03 08:11; testpilot@labs.mozilla.com; c:\users\casa\AppData\Roaming\Mozilla\Firefox\Profiles\4o77m5pl.default\extensions\testpilot@labs.mozilla.com.xpi
FF - ExtSQL: 2013-01-03 08:41; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\casa\AppData\Roaming\Mozilla\Firefox\Profiles\4o77m5pl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-01-05 00:40; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - user.js: extensions.BabylonToolbar_i.id - f6d98a940000000000007ee4003af9af
FF - user.js: extensions.BabylonToolbar_i.hardId - f6d98a940000000000007ee4003af9af
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15403
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=f6d98a940000000000007ee4003af9af&q=
FF - user.js: extensions.BabylonToolbar.id - f6d98a940000000000007ee4003af9af
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15595
FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.9.12
FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.9.12
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.9.1217:04
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110823&tt=3712_4
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Notify-SDWinLogon - SDWinLogon.dll
SafeBoot-52145777.sys
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2013-01-05 19:09:24
ComboFix-quarantined-files.txt 2013-01-05 18:09
.
Pre-Run: 415.073.853.440 byte disponibili
Post-Run: 415.250.272.256 byte disponibili
.
- - End Of File - - 26DD96F842A823E1519949E859CA256A