- - - - CHIAVI ORFANE RIMOSSE - - - -
.
BHO-{c72938b5-d27f-4376-aefd-604664464f8b} - (no file)
Toolbar-10 - (no file)
HKCU-Run-fdvnfgw - c:\documents and settings\silvio\impostazioni locali\dati applicazioni\fdvnfgw.exe
HKCU-Run-SUPERAntiSpyware - c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKCU-Run-SpybotSD TeaTimer - c:\programmi\Spybot - Search & Destroy\TeaTimer.exe
HKCU-Run-PeerGuardian - c:\programmi\PeerGuardian2\pg2.exe
HKCU-Run-MsnMsgr - c:\programmi\Windows Live\Messenger\MsnMsgr.Exe
HKCU-Run-batshow - c:\docume~1\silvio\DATIAP~1\BITSON~1\gpl stupid.exe
HKCU-Run-AliceMessenger - c:\programmi\Alice Messenger\alicemessenger.exe
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
HKLM-Run-EPSON Stylus C46 Series - c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
HKLM-Run-Automatico EPSON Stylus C46 Series su ACER-C7A2D63CB5 - c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
HKLM-Run-Automatico EPSON Stylus C46 Series su ACER-0CE7F6DC47 - c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
HKLM-Run-EPSON Stylus Photo R240 Series - c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE
HKLM-Run-CPMc7cedf78 - c:\windows\system32\nakizeju.dll
HKLM-Run-c4fdece4 - c:\windows\system32\dadutiwo.dll
HKLM-Run-zerapamoti - c:\windows\system32\zitosaba.dll
HKLM-Run-WinampAgent - c:\programmi\Winamp\winampa.exe
HKLM-Run-SunJavaUpdateSched - c:\programmi\Java\jre1.5.0_04\bin\jusched.exe
HKLM-Run-SMSERIAL - c:\programmi\Motorola\SMSERIAL\sm56hlpr.exe
HKLM-Run-Share-to-Web Namespace Daemon - c:\programmi\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
HKU-Default-Run-msnmsgr - c:\programmi\MSN Messenger\msnmsgr.exe
Notify-WgaLogon - (no file)
AddRemove-Dynamic Toolbar_is1 - c:\programmi\Dynamic Toolbar\unins000.exe
AddRemove-fdvnfgw - c:\documents and settings\silvio\impostazioni locali\dati applicazioni\fdvnfgw.exe
AddRemove-Microsoft Interactive Training - c:\windows\IsUn0410.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-10-25 14:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
"ImagePath"="\"c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe\"\00\00\00\00\02\00\00\00\00
[%\00«Ô’|\00\00\00\00\00\00\00\00\00\00\00\00(\00\00\00\00\00/\03pè\13\00pè\13\00\18î"
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-2064341827-335126699-2364305210-1006\Software\Skype\Phone\UI]
@DACL=(02 0000)
@SACL=
"Version"=dword:02000249
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4E7BD74F-2B8D-469E-A0E8-EB65B685FA7D}\ProgID]
@DACL=(02 0000)
@SACL=
@="pbitv2.PBITV2"
.
[HKEY_LOCAL_MACHINE\software\Classes\ThumbnailObj\CLSID]
@DACL=(02 0000)
@SACL=
@="{6AA1F5E0-106A-11CE-B9DA-00001B003195}"
.
[HKEY_LOCAL_MACHINE\software\Classes\ThumbnailObj\DefaultIcon]
@DACL=(02 0000)
@SACL=
@="c:\\Programmi\\Ulead Systems\\Ulead PhotoImpact 10 SE\\ABMRES.DLL,1"
.
[HKEY_LOCAL_MACHINE\software\Classes\ThumbnailObj\Insertable]
@DACL=(02 0000)
@SACL=
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\ThumbnailObj\protocol]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\ThumbnailObj\shell]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\WMSServer.Server\CLSID]
@DACL=(02 0000)
@SACL=
@="{845FB959-4279-11D2-BF23-00805FBE84A6}"
.
[HKEY_LOCAL_MACHINE\software\Classes\WMSServer.Server\CurVer]
@DACL=(02 0000)
@SACL=
@="WMSServer.Server.9"
.
[HKEY_LOCAL_MACHINE\software\Classes\WMSServer.Server.9\CLSID]
@DACL=(02 0000)
@SACL=
@="{845FB959-4279-11D2-BF23-00805FBE84A6}"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]
@DACL=(02 0000)
@SACL=
"WMPlayer.exe"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]
@DACL=(02 0000)
@SACL=
"WMPlayer.exe"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]
@DACL=(02 0000)
@SACL=
"WMPlayer.exe"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]
@DACL=(02 0000)
@SACL=
"WMPlayer.exe"=dword:00000001
"msimn.exe"=dword:00000001
"winmail.exe"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]
@DACL=(02 0000)
@SACL=
"WMPlayer.exe"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]
@DACL=(02 0000)
@SACL=
"WMPlayer.exe"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]
@DACL=(02 0000)
@SACL=
"WMPlayer.exe"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\10.0]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\services]
@DACL=(02 0000)
@SACL=
"NoServices"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Settings]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{077ACEC7-979C-40AB-9835-435BA1511E0D}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{077ACEC7-979C-40AB-9835-435BA1511E0D}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{077ACEC7-979C-40AB-9835-435BA1511E0D}\\MPPRE10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{077ACEC7-979C-40AB-9835-435BA1511E0D}\\mppre10.cat"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{30C7234B-6482-4A55-A11D-ECD9030313F2}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{30C7234B-6482-4A55-A11D-ECD9030313F2}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{30C7234B-6482-4A55-A11D-ECD9030313F2}\\WMDM10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{30C7234B-6482-4A55-A11D-ECD9030313F2}\\wmdm10.cat"
.