Ecco il log di combofix.
Solo un chiarimento, ma adesso il pc sembra funzionare regolarmente, le scansioni fatte con Norton Antivirus non danno allarmi ( ma questo anche prima ma le pagine web si aprivano in continuazione)per dire accanendosi ancora rischio di incorrere nella disinstallazione di driver che mi porterebbero a dover reinstallre Vista?
ecco il log
Auguri a tutti
ComboFix 08-12-29.02 - Domenico & Consuelo 2008-12-30 23:31:38.1 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1040.18.3069.1816 [GMT 1:00]
Eseguito da: c:\users\Domenico & Consuelo\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Domenico & Consuelo\AppData\Local\uqoucwq.dat
c:\users\Domenico & Consuelo\AppData\Local\uqoucwq.exe
c:\users\Domenico & Consuelo\AppData\Local\uqoucwq_nav.dat
c:\users\Domenico & Consuelo\AppData\Local\uqoucwq_navps.dat
c:\windows\system32\KBL.LOG
.
((((((((((((((((((((((((( Files Creati Da 2008-11-28 al 2008-12-30 )))))))))))))))))))))))))))))))))))
.
2008-12-30 16:24 . 2008-12-30 16:24 <DIR> d-------- c:\windows\LastGood
2008-12-30 16:23 . 2008-12-30 16:23 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\InstallShield
2008-12-30 16:23 . 2008-12-30 16:23 <DIR> d-------- C:\Intel
2008-12-30 16:23 . 2008-09-12 13:32 327,192 --a------ c:\windows\System32\drivers\iaStor.sys
2008-12-30 16:16 . 2008-12-30 16:16 289,634,547 --a------ c:\windows\MEMORY.DMP
2008-12-30 15:28 . 2008-12-30 15:36 <DIR> d-------- c:\users\Domenico & Consuelo\.housecall6.6
2008-12-30 15:19 . 2008-12-30 15:19 <DIR> d-------- c:\program files\Trend Micro
2008-12-25 23:20 . 2008-12-25 23:20 <DIR> d-------- c:\users\Domenico & Consuelo\Contacts - Copia (1)
2008-12-25 18:36 . 2008-12-25 18:36 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-12-16 23:41 . 2008-12-16 23:41 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-12-11 23:10 . 2008-10-22 02:22 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-11 09:34 . 2008-11-01 02:21 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-11 09:34 . 2008-10-29 07:29 2,927,104 --a------ c:\windows\explorer.exe
2008-12-11 09:34 . 2008-10-21 06:25 296,960 --a------ c:\windows\System32\gdi32.dll
2008-12-11 09:34 . 2008-11-01 04:44 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2008-12-11 09:33 . 2008-06-23 02:59 2,868,736 --a------ c:\windows\System32\mf.dll
2008-12-11 09:33 . 2008-06-23 02:59 996,352 --a------ c:\windows\System32\WMNetMgr.dll
2008-12-11 09:33 . 2008-10-16 05:47 827,392 --a------ c:\windows\System32\wininet.dll
2008-12-11 09:33 . 2008-06-23 02:58 94,720 --a------ c:\windows\System32\logagent.exe
2008-12-09 23:43 . 2008-12-09 23:43 <DIR> d-------- c:\users\All Users\wmp
2008-12-09 23:43 . 2008-12-09 23:43 <DIR> d-------- c:\programdata\wmp
2008-12-09 21:52 . 2008-12-09 21:52 410,984 --a------ c:\windows\System32\deploytk.dll
2008-12-09 13:46 . 2008-12-09 13:46 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\GrabPro
2008-12-09 13:46 . 2008-12-14 21:39 <DIR> d-------- C:\downloads
2008-12-09 13:42 . 2008-12-15 00:43 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\Orbit
2008-11-29 22:39 . 2008-11-29 22:39 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\dvdcss
2008-11-28 21:59 . 2008-11-28 21:59 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-11-27 19:23 . 2008-11-27 19:25 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\Canon
2008-11-27 19:21 . 2008-11-27 19:21 <DIR> d-------- c:\program files\Canon
2008-11-27 19:13 . 2008-11-27 19:13 <DIR> d--h----- C:\CanoScan
2008-11-27 19:13 . 2005-06-23 22:17 352,256 --a------ c:\windows\System32\CNQL1213.DLL
2008-11-27 19:13 . 2005-02-28 13:20 57,344 --a------ c:\windows\System32\CNQU110.DLL
2008-11-26 18:24 . 2008-11-26 18:24 <DIR> d-------- c:\users\All Users\Nokia
2008-11-26 18:24 . 2008-11-26 18:24 <DIR> d-------- c:\programdata\Nokia
2008-11-26 16:28 . 2008-11-26 16:28 0 --ah----- c:\windows\System32\drivers\Msft_User_PCCSWpdDriver_01_05_00.Wdf
2008-11-26 16:28 . 2008-11-26 16:28 0 --ah----- c:\windows\System32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-11-25 22:14 . 2008-10-21 06:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-25 22:14 . 2008-08-28 04:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-25 22:14 . 2008-08-28 04:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-25 22:14 . 2008-08-28 04:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-25 22:14 . 2008-10-22 04:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-24 10:17 . 2008-11-24 10:17 <DIR> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-24 10:17 . 2008-11-24 10:17 <DIR> d-------- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-24 10:17 . 2008-11-24 10:17 <DIR> d-------- c:\program files\iTunes
2008-11-24 10:17 . 2008-11-24 10:17 <DIR> d-------- c:\program files\iPod
2008-11-24 10:15 . 2008-11-24 10:16 <DIR> d-------- c:\program files\QuickTime
2008-11-24 10:15 . 2008-04-26 09:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2008-11-24 02:23 . 2008-11-24 02:23 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\Template
2008-11-24 02:23 . 2008-11-24 02:24 192 --a------ c:\users\Domenico & Consuelo\AppData\Roaming\wklnhst.dat
2008-11-24 01:22 . 2008-11-24 01:22 <DIR> d-------- C:\PerfLogs
2008-11-23 02:47 . 2008-01-19 08:38 4,595,712 --a------ c:\windows\System32\AuthFWSnapin.dll
2008-11-23 02:46 . 2008-01-19 08:33 8,139,264 --a------ c:\windows\System32\ssBranded.scr
2008-11-23 02:45 . 2008-01-19 08:33 2,585,088 --a------ c:\windows\System32\FirewallControlPanel.exe
2008-11-23 02:44 . 2008-01-19 08:35 3,072,000 --a------ c:\windows\System32\networkmap.dll
2008-11-23 02:43 . 2008-01-19 08:32 1,370,624 --a------ c:\windows\System32\Aurora.scr
2008-11-23 02:42 . 2008-01-19 08:32 5,714,432 --a------ c:\windows\System32\logon.scr
2008-11-23 02:41 . 2008-01-19 07:06 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2008-11-23 02:40 . 2008-01-19 08:33 599,552 --a------ c:\windows\System32\vsp1cln.exe
2008-11-23 02:40 . 2008-01-05 12:31 145,455 --a------ c:\windows\System32\perfmon.msc
2008-11-23 02:40 . 2008-01-05 12:22 144,909 --a------ c:\windows\System32\fsmgmt.msc
2008-11-23 02:40 . 2008-01-05 12:34 15,181 --a------ c:\windows\System32\gatherWirelessInfo.vbs
2008-11-23 02:40 . 2008-01-05 12:21 12,198 --a------ c:\windows\System32\gatherWiredInfo.vbs
2008-11-23 02:40 . 2008-01-05 12:31 3 --a------ c:\windows\System32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf
2008-11-23 02:38 . 2006-11-02 10:46 151,552 --a------ c:\windows\System32\WpdMtp.dll
2008-11-23 02:36 . 2008-01-19 08:36 357,888 --a------ c:\windows\System32\wbemcomn.dll
2008-11-23 02:35 . 2008-01-19 08:36 704,512 --a------ c:\windows\System32\SmiEngine.dll
2008-11-23 02:35 . 2008-01-19 08:36 218,624 --a------ c:\windows\System32\wdscore.dll
2008-11-23 02:35 . 2008-01-19 08:36 139,264 --a------ c:\windows\System32\SmiInstaller.dll
2008-11-23 02:35 . 2008-01-19 08:33 130,560 --a------ c:\windows\System32\PkgMgr.exe
2008-11-23 02:35 . 2008-01-19 08:36 129,536 --a------ c:\windows\System32\sqmapi.dll
2008-11-23 02:33 . 2008-01-19 08:34 305,152 --a------ c:\windows\System32\msdelta.dll
2008-11-23 02:33 . 2008-01-19 08:34 258,560 --a------ c:\windows\System32\dpx.dll
2008-11-23 02:33 . 2008-01-19 08:34 246,784 --a------ c:\windows\System32\drvstore.dll
2008-11-23 02:33 . 2008-01-19 08:35 35,328 --a------ c:\windows\System32\mspatcha.dll
2008-11-21 13:27 . 2008-11-21 13:27 <DIR> d-------- c:\program files\Common Files\PCSuite
2008-11-21 13:27 . 2008-11-26 17:14 <DIR> d-------- c:\program files\Common Files\Nokia
2008-11-21 00:55 . 2008-11-26 16:28 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\PC Suite
2008-11-21 00:55 . 2008-12-15 01:10 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\Nokia
2008-11-21 00:55 . 2008-11-26 16:28 <DIR> d-------- c:\users\All Users\PC Suite
2008-11-21 00:55 . 2008-11-26 16:28 <DIR> d-------- c:\programdata\PC Suite
2008-11-21 00:51 . 2008-11-21 00:51 <DIR> d-------- c:\program files\DIFX
2008-11-21 00:51 . 2007-09-17 15:53 21,632 --a------ c:\windows\System32\drivers\pccsmcfd.sys
2008-11-21 00:49 . 2008-11-21 00:49 <DIR> d-------- c:\program files\PC Connectivity Solution
2008-11-21 00:46 . 2008-11-26 17:08 <DIR> d-------- c:\users\All Users\Installations
2008-11-21 00:46 . 2008-11-26 17:08 <DIR> d-------- c:\programdata\Installations
2008-11-21 00:46 . 2008-11-26 17:38 <DIR> d-------- c:\program files\Nokia
2008-11-21 00:46 . 2008-02-01 16:17 90,624 --a------ c:\windows\System32\nmwcdcls.dll
2008-11-20 08:50 . 2008-11-20 08:50 269,312 --a------ c:\windows\System32\es.dll
2008-11-19 11:33 . 2008-12-30 16:03 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\skypePM
2008-11-19 11:33 . 2008-11-19 11:33 56 --ah----- c:\users\All Users\ezsidmv.dat
2008-11-19 11:33 . 2008-11-19 11:33 56 --ah----- c:\programdata\ezsidmv.dat
2008-11-19 10:50 . 2008-11-19 10:50 <DIR> d-------- c:\users\All Users\Office Genuine Advantage
2008-11-19 10:50 . 2008-11-19 10:50 <DIR> d-------- c:\programdata\Office Genuine Advantage
2008-11-19 01:14 . 2008-12-30 23:20 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\Skype
2008-11-19 00:45 . 2008-11-19 00:45 <DIR> d-------- c:\users\All Users\Google
2008-11-19 00:44 . 2008-11-19 00:45 <DIR> d-------- c:\program files\Google
2008-11-19 00:43 . 2008-11-19 00:43 <DIR> d-------- c:\users\All Users\Skype
2008-11-19 00:43 . 2008-11-19 00:43 <DIR> d-------- c:\programdata\Skype
2008-11-19 00:43 . 2008-11-19 00:43 <DIR> d-------- c:\program files\Skype
2008-11-19 00:43 . 2008-11-19 00:43 <DIR> d-------- c:\program files\Common Files\Skype
2008-11-18 22:59 . 2008-11-18 22:59 361,984 --a------ c:\windows\System32\IPSECSVC.DLL
2008-11-18 22:59 . 2008-11-18 22:59 272,896 --a------ c:\windows\System32\polstore.dll
2008-11-18 22:59 . 2008-11-18 22:59 61,440 --a------ c:\windows\System32\winipsec.dll
2008-11-18 22:59 . 2008-11-18 22:59 28,672 --a------ c:\windows\System32\FwRemoteSvr.dll
2008-11-18 22:58 . 2008-11-18 22:58 1,695,744 --a------ c:\windows\System32\gameux.dll
2008-11-18 22:53 . 2008-11-18 22:53 <DIR> d-------- c:\users\Domenico & Consuelo\AppData\Roaming\GTek
2008-11-18 22:52 . 2008-11-18 22:52 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-18 22:51 . 2008-11-18 22:51 2,032,640 --a------ c:\windows\System32\win32k.sys
2008-11-18 22:51 . 2008-11-18 22:51 303,616 --a------ c:\windows\System32\wmpeffects.dll
2008-11-18 22:50 . 2008-11-18 22:50 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-18 22:50 . 2008-11-18 22:50 2,048 --a------ c:\windows\System32\msxml3r.dll
2008-11-18 22:46 . 2008-11-18 22:49 <DIR> d-------- c:\users\All Users\eMule
2008-11-18 22:46 . 2008-11-18 22:49 <DIR> d-------- c:\programdata\eMule
2008-11-18 22:46 . 2008-11-18 22:46 <DIR> d-------- c:\program files\eMule
2008-11-18 22:46 . 2008-11-18 22:46 988,216 --a------ c:\windows\System32\winload.exe
2008-11-18 22:46 . 2008-11-18 22:46 927,288 --a------ c:\windows\System32\winresume.exe
2008-11-18 22:46 . 2008-11-18 22:46 615,992 --a------ c:\windows\System32\ci.dll
2008-11-18 22:46 . 2008-11-18 22:46 378,368 --a------ c:\windows\System32\srcore.dll
2008-11-18 22:46 . 2008-11-18 22:46 318,464 --a------ c:\windows\System32\rstrui.exe
2008-11-18 22:46 . 2008-11-18 22:46 46,592 --a------ c:\windows\System32\setbcdlocale.dll
2008-11-18 22:46 . 2008-11-18 22:46 40,960 --a------ c:\windows\System32\srclient.dll
2008-11-18 22:46 . 2008-11-18 22:46 19,000 --a------ c:\windows\System32\kd1394.dll
2008-11-18 22:46 . 2008-11-18 22:46 14,848 --a------ c:\windows\System32\srdelayed.exe
2008-11-18 22:46 . 2008-11-18 22:46 6,656 --a------ c:\windows\System32\kbd106n.dll
2008-11-18 22:44 . 2008-11-18 22:44 443,392 --a------ c:\windows\System32\win32spl.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 17:05 --------- d-----w c:\programdata\Symantec
2008-12-30 15:23 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-12 10:37 --------- d-----w c:\program files\Windows Mail
2008-12-11 22:13 --------- d-----w c:\programdata\Microsoft Help
2008-12-09 20:52 --------- d-----w c:\program files\Java
2008-11-24 00:33 174 --sha-w c:\program files\desktop.ini
2008-11-24 00:25 --------- d-----w c:\program files\Windows Sidebar
2008-11-24 00:25 --------- d-----w c:\program files\Windows Photo Gallery
2008-11-24 00:25 --------- d-----w c:\program files\Windows Journal
2008-11-24 00:25 --------- d-----w c:\program files\Windows Defender
2008-11-24 00:25 --------- d-----w c:\program files\Windows Collaboration
2008-11-24 00:25 --------- d-----w c:\program files\Windows Calendar
2008-11-24 00:18 --------- d-----w c:\programdata\NVIDIA
2008-11-24 00:06 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-11-24 00:06 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-11-18 21:59 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-11-18 21:53 --------- d-----w c:\program files\Hp
2008-11-18 21:53 --------- d-----w c:\program files\Hewlett-Packard
2008-11-17 23:20 --------- d-----w c:\programdata\CyberLink
2008-11-17 18:16 --------- d-----w c:\program files\Norton Internet Security
2008-11-17 18:16 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-17 18:09 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-11-17 18:09 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-11-17 18:09 10,671 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-17 18:09 --------- d-----w c:\program files\Symantec
2008-11-17 16:56 --------- d-----w c:\programdata\Hewlett-Packard
2008-11-17 16:43 --------- d-----w c:\program files\HPQ
2008-11-17 16:34 --------- d-sh--w c:\programdata\Preferiti
2008-11-17 16:34 --------- d-sh--w c:\programdata\Modelli
2008-11-17 16:34 --------- d-sh--w c:\programdata\Menu Avvio
2008-11-17 16:34 --------- d-sh--w c:\programdata\Documenti
2008-11-17 16:34 --------- d-sh--w c:\programdata\Desktop
2008-11-17 16:34 --------- d-sh--w c:\programdata\Dati applicazioni
2008-11-17 16:34 --------- d-sh--w c:\program files\File comuni
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-23 16:46 245,408 ----a-w c:\windows\System32\unicows.dll
2008-09-18 04:56 147,456 ----a-w c:\windows\System32\Faultrep.dll
2008-09-18 04:56 125,952 ----a-w c:\windows\System32\wersvc.dll
2008-09-03 03:59 468,992 ----a-w c:\windows\System32\newdev.dll
2008-09-03 03:58 74,752 ----a-w c:\windows\System32\newdev.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 1783136]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-11-19 171448]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-10-02 1124352]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-09 136600]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{50FE1639-2277-423A-9FFB-A9E65BB7474C}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{AFAAC25D-2240-47B4-BABB-B3C1AE76B327}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5DBB0C4D-969D-459E-A788-A31354634EC3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{DD521377-4A4F-4CED-AEA5-6A924730F285}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{4D7D39C6-43EA-49CB-908E-AB3ED64848DD}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{D5308FAD-6E91-4707-BA48-7EC2C478E700}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{CF9AEBB0-16A1-4D6B-97A6-DFDDAEDCF983}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F123929F-2614-468E-A872-7E05D7706B37}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{71A916B7-0527-4C75-945C-5EA7C9D029FF}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{828CBE4C-17E5-42DC-9788-D4033DEBB1BE}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{445BD503-4E24-48FF-9CDA-46695B3600B6}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;\??\c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20081220.001\IDSvix86.sys [2008-12-20 270384]
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-11-17 149352]
R3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2007-05-29 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-11-17 99376]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\Drivers\SYMNDISV.SYS [2008-06-13 41008]
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'
2008-11-17 c:\windows\Tasks\Norton Internet Security - Scansione completa sistema - Domenico & Consuelo.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]
.
- - - - ORFÃOS REMOVIDOS - - - -
HKCU-Run-uqoucwq - c:\users\domenico & consuelo\appdata\local\uqoucwq.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-30 23:34:25
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-12-30 23:54:31
ComboFix-quarantined-files.txt 2008-12-30 22:54:28
Pre-Run: 150,339,055,616 byte disponibili
Post-Run: 152,041,594,880 byte disponibili
288 --- E O F --- 2008-12-30 14:22:38