SECONDA PARTE DEL LOG DI COMBOFIX
***************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-04 16:04
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SM_ml1600_FUService]
"ImagePath"="\"c:\programmi\Samsung ML-2010 Series\CommonSM\ssmsrvc /Service"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kmgkbt]
"ServiceDll"="c:\windows\system32\jbvqsf.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\svmfpnfo]
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\EN]
@DACL=(02 0000)
"OnLineServicesDirName"="Online Services"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\FR]
@DACL=(02 0000)
"OnLineServicesDirName"="Services en ligne"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\MX]
@DACL=(02 0000)
"OnLineServicesDirName"="Servicios en línea"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\NL]
@DACL=(02 0000)
"OnLineServicesDirName"="Online Services"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\NW]
@DACL=(02 0000)
"OnLineServicesDirName"="Online tjenster"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\SP]
@DACL=(02 0000)
"OnLineServicesDirName"="Servicios en línea"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\SW]
@DACL=(02 0000)
"OnLineServicesDirName"="Online tjänster"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\UK]
@DACL=(02 0000)
"OnLineServicesDirName"="Online services"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\HP\US]
@DACL=(02 0000)
"OnLineServicesDirName"="Online Services"
[HKEY_USERS\S-1-5-21-3186247095-2005263365-367709424-1007\Software\Microsoft\Windows\Shell\Bags\1]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{094A7308-158D-3A11-95DF-D37DE4675CAE}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.NativeLib"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0AC383AA-48DD-3BA3-89AD-1E03A84C2AC0}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.VendorPreferences"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0B09B097-CF1A-3470-A1C5-EFE7C18EB40A}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.diagnostics.OSInfo"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{13DBC185-8E37-383E-A1EA-6365964DB78B}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.StringArraySorter+StringComparer"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1BB2E9A9-BBCD-3CBC-BC2B-3E97964C886A}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.pluginmgr.PluginConfigProperties"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1BEC0849-64A7-3089-B825-C38063CB939C}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.HtmlUtil"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{222F1997-5DA5-3822-ACE9-1BC5E623ADCA}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.pluginmgr.Main"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2D9A09FD-BBEE-3631-AA80-5004FC15B5CD}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.HelpSessionUrls"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{39361D65-C190-3681-A6E7-01C95CD0F25A}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.PrintBuffer"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3CA743AC-A5D8-377A-9CF1-519EB466DCAD}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.incidentmgr.IncidentManager"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3CF4B98F-5D45-3900-8306-50742080215B}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.IncidentType"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{493079DA-3D61-371B-9CC3-B4784F4EDDD4}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.server.notifications.NotificationHandlerResult"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{495B4F27-2C53-3A61-9C19-564A882BF719}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.COPYDATASTRUCT"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4FE17AF3-4D49-3AB4-B696-04EC20A11DF7}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.ResourceUtil"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{57B8A9C4-E1CB-347B-AA4D-EEC33E96DE39}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.ZipUtil"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{57DC7713-0CB3-3B03-8491-855DB7BD0686}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.server.notifications.ServerMessageTypes"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{59A3CBF8-3291-343E-AD34-25527B2EB2AF}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.StringArraySorter"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{66CA6984-132B-3685-B73B-D541C234AF15}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.ui.UIServices"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{68C44009-86E1-3CFE-A2CA-BD41F10B9A12}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.MapFileNames"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6A00AFFE-067B-3A1F-A004-6C9D96DD988E}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.Properties"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{707CEE46-3567-35FF-B470-C5E64C06FB58}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.mapsmgr.MapsManager"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{76CB67EC-2B56-37D8-8AE2-62A41800495E}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.Timestamp"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{785BD594-0C49-306C-8A17-A4AA58D5DD74}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.COPYDATASTRUCT+COPYDATASTRUCTHelper"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7A04BBA4-AD4B-3A48-BA81-4DB56DF41C7B}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.mapsmgr.MapDownloadServices"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7A9A29B7-585D-3C66-A01D-215121DF4C6C}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.RunMapResults"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7F686E71-CDF0-33DC-B4BD-017BDC89FC42}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.WinVerifyTrust"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{81AC1E9C-6C20-3986-9D98-18F34F037142}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.ArraySorter"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{829270EF-C856-3AE6-BB70-A14F77BC00C8}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.IO"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{85B7E85D-DBCE-37D8-A99E-8D569D655752}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.LongArraySorter+LongComparer"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{861D4BFC-4F47-3EE8-B79D-5EFE672736E8}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.CabUtil"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8811C83D-ED69-3EDA-BC64-5158F2C8F882}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.MMapVerifyTrust"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{928F1BEB-109B-30DA-8007-E656ADA03C99}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.MapSubTypes"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A6C3F67A-E4F0-316D-AEF5-8E112F5E4F83}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.ui.ErrorMessageCode"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AD0B0744-DDA8-3D66-A77F-2AA30C5B24BA}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.XmlFileHelper"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADCA84E9-DAF6-3AB1-B56D-A6EA46562FA4}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.Log"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B720606E-AC5A-3448-8A3C-D5023D1AB99C}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.server.notifications.NotificationsMgr"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BDA4A89D-C64A-393A-A0DA-BBD521483334}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.I18NStringResIDs"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C4E8E044-FFEB-36C3-AFC7-D7D3E0399886}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.pluginmgr.InitVendorPreferences"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C917B4A7-27C3-366B-985F-CCB3D5D162E5}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.pluginmgr.Version"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CBE23923-D7A0-3350-A48E-8CD9BDFBFAA4}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.server.notifications.SoapMsgParser"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CCADF3B4-8239-31C4-BECC-2A43602460B6}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.MapTOC"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D00B5680-C89B-39A9-AE23-717BED2D82BD}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.server.methods.Refresh"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D8DBCDF5-6213-3415-947F-55E249F6D880}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.mapsmgr.MapArchiveServices"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE96868C-5A83-374B-BB75-C2D7D1A0E530}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.OSInfo"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ECB3FF27-F399-3FBD-9BD3-1B9909E7ED0B}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.pluginmgr.PluginMgr"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F70821E0-4EDF-38D6-8DA9-6C0099E681DF}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.model.MapTypes"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FE6A5C87-644A-3D33-834A-A6553BE0B2E3}\InprocServer32\1.0.1494.6995]
@DACL=(02 0000)
@SACL=
"Class"="com.motive.plugin.lib.LongArraySorter"
"Assembly"="pchealthplugin, Version=1.0.1494.6995, Culture=neutral, PublicKeyToken=822b6df6f89a141f"
"RuntimeVersion"="v1.0.3705"
"CodeBase"="file:///C:/PROGRA~1/HELPAN~1/Presario/XPHWWRF4/plugin/bin/pchealthplugin.DLL"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{02BF25D3-8C17-4B23-BC80-D3488ABDDC6B}\ProxyStubClsid]
@DACL=(02 0000)
@SACL=
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{02BF25D3-8C17-4B23-BC80-D3488ABDDC6B}\ProxyStubClsid32]
@DACL=(02 0000)
@SACL=
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{02BF25D3-8C17-4B23-BC80-D3488ABDDC6B}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{02BF25D2-8C17-4B23-BC80-D3488ABDDC6B}"
"Version"="2.0"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{02BF25D4-8C17-4B23-BC80-D3488ABDDC6B}\ProxyStubClsid]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{02BF25D4-8C17-4B23-BC80-D3488ABDDC6B}\ProxyStubClsid32]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{02BF25D4-8C17-4B23-BC80-D3488ABDDC6B}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{02BF25D2-8C17-4B23-BC80-D3488ABDDC6B}"
"Version"="2.0"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\ProxyStubClsid]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\ProxyStubClsid32]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9781-280D-11CF-A24D-444553540000}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{CA8A9783-280D-11CF-A24D-444553540000}"
"Version"="1.3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\ProxyStubClsid]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\ProxyStubClsid32]
@DACL=(02 0000)
@SACL=
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CA8A9782-280D-11CF-A24D-444553540000}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{CA8A9783-280D-11CF-A24D-444553540000}"
"Version"="1.3"
[HKEY_LOCAL_MACHINE\software\Clients\Media\QuickTime Player\DefaultIcon]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Clients\Media\QuickTime Player\shell]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
@DACL=(02 0000)
@SACL=
@="Microsoft VM"
"ComponentID"="JAVAVM"
"IsInstalled"=hex:01,00,00,00
"KeyFileName"="c:\\WINDOWS\\system32\\msjava.dll"
"Version"="5,0,3810,0"
"Locale"="IT"
[HKEY_LOCAL_MACHINE\software\Microsoft\Active Setup\Installed Components\{8b15971b-5355-4c82-8c07-7e181ea07608}]
@DACL=(02 0000)
@SACL=
@="Fax"
"ComponentID"="Fax"
"IsInstalled"=dword:00000001
"DontAsk"=dword:00000002
"Version"="5.1"
"Locale"="EN"
"StubPath"="rundll32.exe advpack.dll,LaunchINFSection c:\\WINDOWS\\INF\\fxsocm.inf,Fax.Install.PerUser"
[HKEY_LOCAL_MACHINE\software\Microsoft\Active Setup\Installed Components\{94de52c8-2d59-4f1b-883e-79663d2d9a8c}]
@DACL=(02 0000)
@SACL=
@="Provider fax"
"ComponentID"="Fax Provider"
"IsInstalled"=dword:00000001
"DontAsk"=dword:00000002
"Version"="5.1"
"Locale"="EN"
"StubPath"=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Code Store Database]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Direct3D\MostRecentApplication]
@DACL=(02 0000)
@SACL=
"Name"="atiptaxx.exe"
[HKEY_LOCAL_MACHINE\software\Microsoft\DirectDraw\MostRecentApplication]
@DACL=(02 0000)
@SACL=
"ID"=dword:41107b81
"Name"="iexplore.exe"
[HKEY_LOCAL_MACHINE\software\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\ESENT\Process\Explorer]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Exchange]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Fax]
@DACL=(02 0000)
@SACL=
"Retries"=dword:00000003
"Retry Delay"=dword:0000000a
"QueueState"=dword:00000000
"NextJobNumber"=dword:00000003
"Branding"=dword:00000001
"UseDeviceTsid"=dword:00000001
"Inbound Profile"=""
"ServerCoverPageOnly"=dword:00000000
"LastUniqueLineId"=dword:00010001
"CfgWzdrDevice"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Fax\Devices]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Fax\Logging]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Fax\Outbound Routing\Groups]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Fax\Outbound Routing\Rules]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Fax\Security]
@DACL=(02 0000)
"Descriptor"=hex:01,00,04,80,5c,00,00,00,6c,00,00,00,00,00,00,00,14,00,00,00,
02,00,48,00,03,00,00,00,00,00,18,00,ff,07,08,00,01,02,00,00,00,00,00,05,20,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.aif]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.aifc]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.aiff]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.au]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.m1v]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.mid]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.midi]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.mp2]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.mpa]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.mpeg]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.mpg]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.snd]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\EmbedExtnToClsidMappings\.wav]
@DACL=(02 0000)
@SACL=
@="clsid:05589fa1-c356-11ce-bf01-00aa0055595a"
"MPlayer2.BAK"="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B"
"MPlayer2.Set"="yes"
[HKEY_LOCAL_MACHINE\software\Microsoft\RAS AutoDial]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Sysprep]
@DACL=(02 0000)
@SACL=
"SidsGenerated"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\SystemCertificates\ROOT\Certificates\74CDD21C2F1D104F8940DFFE7E6F035756E2F5D0]
@DACL=(02 0000)
@SACL=
"Blob"=hex:14,00,00,00,01,00,00,00,14,00,00,00,d9,cf,ea,0f,a4,af,d8,0b,23,67,
95,bf,ea,dd,d6,35,5f,e7,75,6e,04,00,00,00,01,00,00,00,10,00,00,00,0c,19,2a,\
[HKEY_LOCAL_MACHINE\software\Microsoft\SystemCertificates\TrustedPublisher]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Updates]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP OOB\SP10\KB835221WXP\Filelist]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\ISPSignup.exe]
@DACL=(02 0000)
@SACL=
@="c:\\Programmi\\Easy Internet signup\\ISPSignup.exe"
"Path"="c:\\Programmi\\Easy Internet signup\\"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Controls Folder\Keyboard]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Controls Folder\PowerCfg\PowerPolicies\6]
@DACL=(02 0000)
@SACL=
"Policies"=hex:01,00,00,00,02,00,00,00,04,00,00,00,02,00,00,00,02,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,07,00,02,00,00,00,04,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Controls Folder\PowerCfg\ProcessorPolicies\6]
@DACL=(02 0000)
@SACL=
"Policies"=hex:01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,a0,
86,01,00,a0,86,01,00,a0,86,01,00,28,32,00,00,02,00,00,00,a0,86,01,00,a0,86,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\c]
@DACL=(02 0000)
@SACL=
"VolumeSerialNumber"=dword:88e3b4c9
"IsUnicode"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Extensions]
@DACL=(02 0000)
@SACL=
".ini"="notepad.exe ^.ini"
".txt"="notepad.exe ^.txt"
".wtx"="notepad.exe ^.wtx"
".PDS"="c:\\PSDWIN\\PSDWIN.EXE ^.PDS"
".PDB"="c:\\PSDWIN\\PSDWIN.EXE ^.PDB"
".PDC"="c:\\PSDWIN\\PSDWIN.EXE ^.PDC"
".PDG"="c:\\PSDWIN\\PSDWIN.EXE ^.PDG"
".PDL"="c:\\PSDWIN\\PSDWIN.EXE ^.PDL"
".PDA"="c:\\PSDWIN\\PSDWIN.EXE ^.PDA"
".PCC"="c:\\PSDWIN\\PSDWIN.EXE ^.PCC"
".PCB"="c:\\PSDWIN\\PSDWIN.EXE ^.PCB"
".PCE"="c:\\PSDWIN\\PSDWIN.EXE ^.PCE"
".PCP"="c:\\PSDWIN\\PSDWIN.EXE ^.PCP"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
@Allowed: (Read) (Administrators)
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\OemStartMenuData]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\OptionalComponents\SwFlash]
@DACL=(02 0000)
@SACL=
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield Uninstall Information]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}]
@DACL=(02 0000)
@SACL=
"LogFile"="c:\\Programmi\\InstallShield Installation Information\\{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}\\Setup.ilg"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\ShockwaveFlash]
@DACL=(02 0000)
@SACL=
"QuietDisplayName"="Shockwave Flash"
"QuietUninstallString"="RunDll32 advpack.dll,LaunchINFSection c:\\WINDOWS\\INF\\swflash.inf,DefaultUninstall,5"
"DisplayName"="Adobe Flash Player 9 ActiveX"
"UninstallString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil9b.exe -uninstallDelete"
"RequiresIESysFile"="4.70.0.1155"
"Publisher"="Adobe Systems"
"DisplayVersion"="9"
"VersionMajor"="9"
"VersionMinor"="0"
"HelpLink"="http://www.adobe.com/go/flashplayer_support/"
"URLUpdateInfo"="http://www.adobe.com/go/flashplayer/"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}]
@DACL=(02 0000)
@SACL=
"DisplayIcon"="c:\\Programmi\\PC-Doctor for Windows\\Pcdrw32.exe"
"UninstallString"="RunDll32 c:\\PROGRA~1\\FILECO~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"c:\\Programmi\\InstallShield Installation Information\\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\\Setup.exe\" "
"DisplayName"="PC-Doctor per Windows"
"LogFile"="c:\\Programmi\\InstallShield Installation Information\\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\\setup.ilg"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{39DA87A1-0B26-4562-A70C-2A6147366E47}]
@DACL=(02 0000)
@SACL=
"UninstallString"="RunDll32 c:\\PROGRA~1\\FILECO~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"c:\\Programmi\\InstallShield Installation Information\\{39DA87A1-0B26-4562-A70C-2A6147366E47}\\Setup.exe\" "
"LogFile"="c:\\Programmi\\InstallShield Installation Information\\{39DA87A1-0B26-4562-A70C-2A6147366E47}\\setup.ilg"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}]
@DACL=(02 0000)
@SACL=
"UninstallString"="RunDll32 c:\\PROGRA~1\\FILECO~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"c:\\Programmi\\InstallShield Installation Information\\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\\Setup.exe\" "
"LogFile"="c:\\Programmi\\InstallShield Installation Information\\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\\setup.ilg"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{BAD59025-5B73-4E12-B789-0028C5A573C2}]
@DACL=(02 0000)
@SACL=
"UninstallString"="RunDll32 c:\\PROGRA~1\\FILECO~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"c:\\Programmi\\InstallShield Installation Information\\{BAD59025-5B73-4E12-B789-0028C5A573C2}\\Setup.exe\" "
"LogFile"="c:\\Programmi\\InstallShield Installation Information\\{BAD59025-5B73-4E12-B789-0028C5A573C2}\\setup.ilg"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Shell]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB835221WXP]
@DACL=(02 0000)
@SACL=
"Installed"=dword:00000001
"Comments"="High Definition Audio Driver - KB835221"
"Backup Dir"=""
"Fix Description"="High Definition Audio Driver - KB835221"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:0000000a
"Valid"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers]
@DACL=(02 0000)
@SACL=
"viagfx"="vticd.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax]
@DACL=(02 0000)
@SACL=
"ChangeID"=dword:0029f824
"Status"=dword:00000180
"Name"="Fax"
"Share Name"=""
"Print Processor"="WinPrint"
"Datatype"="RAW"
"Parameters"=""
"Action"=dword:00000000
"ObjectGUID"=""
"DsKeyUpdate"=dword:00000000
"DsKeyUpdateForeground"=dword:00000000
"Description"=""
"Printer Driver"="Microsoft Shared Fax Driver"
"Default DevMode"=hex:46,00,61,00,78,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"Priority"=dword:00000001
"Default Priority"=dword:00000000
"StartTime"=dword:00000000
"UntilTime"=dword:00000000
"Separator File"=""
"Location"=""
"Attributes"=dword:00004040
"txTimeout"=dword:0000afc8
"dnsTimeout"=dword:00003a98
"Security"=hex:01,00,04,80,c0,00,00,00,dc,00,00,00,00,00,00,00,14,00,00,00,02,
00,ac,00,06,00,00,00,00,0a,14,00,00,00,02,00,01,01,00,00,00,00,00,03,00,00,\
"SpoolDirectory"=""
"Port"="SHRFAX:"
[HKEY_LOCAL_MACHINE\software\Swearware\backup\winsock2]
@DACL=(02 0000)
@SACL=
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(940)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(996)
c:\windows\system32\imon.dll
- - - - - - - > 'explorer.exe'(3332)
c:\progra~1\ALICET~1\SMARTB~1\SBHook.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\WgaTray.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Software Bluetooth\bin\btwdins.exe
c:\programmi\File comuni\EPSON\EBAPI\SAgent2.exe
c:\progra~1\FILECO~1\MICROW~1\Agent\MWASER.EXE
c:\progra~1\FILECO~1\MICROW~1\Agent\MWAgent.exe
c:\programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
c:\programmi\File comuni\PCSuite\Services\ServiceLayer.exe
c:\progra~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~1.EXE
c:\programmi\Alice ti aiuta\bin\mpbtn.exe
.
**************************************************************************
.
Ora fine scansione: 2010-08-04 16:12:13 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-08-04 14:12
Pre-Run: 2.733.133.824 byte disponibili
Post-Run: 2.624.704.512 byte disponibili
- - End Of File - - D31DAB81CBC7A7DA9832C8B1AF0CA41C
Mi auguro di non aver commesso errori nel copia - incolla, perchè il log è lunghissimo.
Grazie ancora a tutti.