ComboFix 09-08-09.04 - abramo 10/08/2009 14.36.55.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1014.504 [GMT 2:00]
Eseguito da: c:\documents and settings\abramo\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {0015C208-EE10-0012-360A-927CBF010000}
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000000-0000-0000-2303-927C0000FD7F}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000000-0012-0014-00DC-FD7F00000802}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000000-0012-0014-00EC-FD7F00000802}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000000-0012-0014-00FC-FD7F00000802}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {001300D4-0000-0000-1000-00007454927C}
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated) {438021EB-0000-0000-0000-0000E4041500}
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {00000000-F0B8-0012-18EE-917C3807927C}
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {0057005C-F0B8-0012-18EE-917C3807927C}
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {00C100C0-00C2-00C3-C400-C500C600C700}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
ADS - WINDOWS: deleted 24 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\abramo\Menu Avvio\Programmi\Videos.url
c:\documents and settings\abramo\Preferiti\Videos.url
c:\recycler\S-1-5-21-1732920463-409091003-733348575-1003
c:\recycler\S-1-5-21-3438051912-2674372776-1388501132-1003
c:\recycler\S-1-5-21-484763869-1960408961-682003330-1003
c:\windows\Installer\11c4055.msp
c:\windows\Installer\1a23121.msp
c:\windows\Installer\291bc.msi
c:\windows\Installer\41b28.msi
c:\windows\Installer\96d9cf.msi
c:\windows\system32\bKnnWvut.ini
c:\windows\system32\bKnnWvut.ini2
c:\windows\system32\bveaasva.ini
c:\windows\system32\dvcvdrmo.ini
c:\windows\system32\eiletwec.ini
c:\windows\system32\lnauowfq.ini
c:\windows\system32\uakltxkw.ini
c:\windows\system32\xvutwdip.ini
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Creati Da 2009-07-10 al 2009-08-10 )))))))))))))))))))))))))))))))))))
.
2009-08-10 11:20 . 2009-08-10 11:20 -------- d--h--w- c:\windows\PIF
2009-08-07 10:16 . 2009-08-07 10:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CyberLink
2009-08-07 10:15 . 2009-08-07 10:16 -------- d-----w- c:\documents and settings\abramo\Dati applicazioni\CyberLink
2009-08-07 10:11 . 2009-08-07 10:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SmartSound Software Inc
2009-08-07 10:11 . 2009-08-07 10:11 -------- d-----w- c:\programmi\SmartSound Software
2009-08-07 10:07 . 2009-08-07 10:07 -------- d-----w- c:\documents and settings\abramo\Impostazioni locali\Dati applicazioni\Apple
2009-08-07 10:07 . 2009-08-07 10:07 -------- d-----w- c:\programmi\Apple Software Update
2009-08-07 10:07 . 2009-08-07 10:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple
2009-08-07 10:02 . 2009-08-07 10:04 -------- d-----w- c:\programmi\CyberLink
2009-08-07 10:01 . 2009-08-07 10:00 36864 ----a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2009-08-05 12:05 . 2004-03-29 14:23 90112 ----a-w- c:\windows\unvise32.exe
2009-08-05 12:05 . 2009-08-05 12:12 -------- d-----w- c:\programmi\TomTom HOME
2009-08-04 22:26 . 2009-08-04 22:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Comodo
2009-08-04 22:26 . 2009-08-05 11:16 179792 ----a-w- c:\windows\system32\guard32.dll
2009-08-04 22:26 . 2009-08-05 11:16 86976 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-08-04 22:26 . 2009-08-05 11:16 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-08-04 22:26 . 2009-08-05 11:16 132040 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-08-04 15:26 . 2009-08-04 15:26 -------- d-----w- c:\documents and settings\abramo\Dati applicazioni\MAGIX
2009-08-04 15:16 . 2009-08-04 16:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MAGIX
2009-08-04 15:15 . 2009-08-04 16:08 -------- d-----w- c:\programmi\MAGIX
2009-08-04 15:15 . 2007-04-27 07:43 120200 ----a-w- c:\windows\system32\DLLDEV32i.dll
2009-08-04 15:14 . 2009-08-04 16:08 -------- d-----w- c:\windows\system32\MAGIX
2009-08-04 15:14 . 2008-04-15 13:14 700416 ----a-w- c:\windows\system32\mgxoschk.dll
2009-08-01 12:07 . 2009-08-01 12:07 -------- d-----w- c:\documents and settings\abramo\Impostazioni locali\Dati applicazioni\WMTools Downloaded Files
2009-07-30 18:52 . 2009-08-09 20:39 -------- d-----w- c:\documents and settings\abramo\Dati applicazioni\vlc
2009-07-30 15:14 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-30 15:14 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-07-30 15:14 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-07-30 11:08 . 2009-07-30 14:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-07-22 15:10 . 2009-07-22 15:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Ahead
2009-07-22 14:22 . 2009-07-22 14:46 -------- d-----w- C:\JOSHUA
2009-07-22 13:56 . 2009-07-22 13:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SlySoft
2009-07-22 13:50 . 2009-07-22 13:50 -------- d-----w- c:\programmi\SlySoft
2009-07-21 17:14 . 2009-07-22 14:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DVD Shrink
2009-07-21 17:14 . 2009-07-21 17:14 -------- d-----w- c:\programmi\DVD Shrink
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-10 12:49 . 2009-04-18 13:54 -------- d-----w- c:\documents and settings\abramo\Dati applicazioni\Orbit
2009-08-10 12:28 . 2009-04-18 13:54 -------- d-----w- c:\programmi\Orbitdownloader
2009-08-10 12:25 . 2008-11-17 14:39 -------- d-----w- c:\documents and settings\abramo\Dati applicazioni\CallingID
2009-08-10 11:22 . 2008-07-22 14:49 -------- d-----w- c:\documents and settings\abramo\Dati applicazioni\BitTorrent
2009-08-09 19:11 . 2009-03-18 10:12 117760 ----a-w- c:\documents and settings\abramo\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-09 19:10 . 2008-10-17 10:55 -------- d-----w- c:\programmi\SUPERAntiSpyware
2009-08-09 11:55 . 2009-02-07 13:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-08-07 10:16 . 2008-07-21 17:15 88440 ----a-w- c:\documents and settings\abramo\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-08-07 10:14 . 2005-01-03 11:57 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-08-07 10:09 . 2008-08-19 11:50 -------- d-----w- c:\programmi\QuickTime
2009-08-07 10:09 . 2008-08-19 11:48 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2009-08-07 10:01 . 2008-10-28 18:49 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-08-04 22:26 . 2008-07-23 11:34 -------- d-----w- c:\programmi\COMODO
2009-08-04 15:20 . 2009-08-04 15:20 -------- d-----w- c:\programmi\File comuni\MAGIX Shared
2009-08-03 10:15 . 2008-07-21 23:50 -------- d-----w- c:\documents and settings\abramo\Dati applicazioni\LimeWire
2009-08-01 11:54 . 2008-07-21 22:17 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-07-30 14:59 . 2008-09-29 11:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2009-07-30 11:21 . 2005-01-03 10:52 83032 ----a-w- c:\windows\system32\perfc010.dat
2009-07-30 11:21 . 2005-01-03 10:52 486484 ----a-w- c:\windows\system32\perfh010.dat
2009-07-25 10:32 . 2009-06-03 15:42 -------- d-----w- c:\documents and settings\abramo\Dati applicazioni\dvdcss
2009-07-15 19:19 . 2008-07-21 18:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-06-29 15:55 . 2005-01-03 10:51 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:55 . 2005-01-03 10:51 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:54 . 2005-01-03 10:51 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-23 10:15 . 2008-10-21 17:00 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-06-23 10:13 . 2008-10-24 11:30 3561743 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-23 10:10 . 2008-09-21 19:45 -------- d-----w- c:\programmi\Pivot Stickfigure Animator
2009-06-23 10:09 . 2008-07-21 22:33 -------- d-----w- c:\programmi\Google
2009-06-22 21:04 . 2008-08-10 14:09 -------- d-----w- c:\programmi\Avidemux 2.4
2009-06-17 09:27 . 2008-10-21 17:00 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2008-10-21 17:00 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-16 14:36 . 2005-01-03 10:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-01-03 10:51 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-11 20:33 . 2009-06-11 20:33 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-06-03 19:09 . 2005-01-03 10:51 1296384 ----a-w- c:\windows\system32\quartz.dll
2009-05-25 12:01 . 2009-05-25 12:01 89256 ----a-w- c:\windows\system32\ElbyCDIO.dll
2008-08-12 15:08 . 2008-08-12 15:08 7888896 -c--a-w- c:\programmi\File comuni\iHabbix.exe
2008-07-21 08:34 . 2008-07-21 08:34 635 -c--a-w- c:\programmi\File comuni\iHabbix.exe.manifest
2002-12-20 12:02 . 2002-12-20 12:02 1077336 -c--a-w- c:\programmi\File comuni\MSCOMCTL.OCX
1998-06-23 22:00 . 1998-06-23 22:00 209192 -c--a-w- c:\programmi\File comuni\TABCTL32.OCX
1998-06-23 22:00 . 1998-06-23 22:00 140096 -c--a-w- c:\programmi\File comuni\COMDLG32.OCX
1998-06-23 22:00 . 1998-06-23 22:00 115016 -c--a-w- c:\programmi\File comuni\MSINET.OCX
1998-06-23 22:00 . 1998-06-23 22:00 108336 -c--a-w- c:\programmi\File comuni\MSWINSCK.OCX
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\programmi\opera\program\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\programmi\opera\program\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\programmi\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-15 65536]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programmi\Apoint2K\Apoint.exe" [2004-03-23 196608]
"AGRSMMSG"="c:\windows\AGRSMMSG.exe" [2004-10-28 88363]
"CeEKEY"="c:\programmi\TOSHIBA\E-KEY\CeEKey.exe" [2004-11-29 667648]
"TPNF"="c:\programmi\TOSHIBA\TouchPad\TPTray.exe" [2004-11-29 53248]
"Tvs"="c:\programmi\TOSHIBA\Tvs\TvsTray.exe" [2004-11-12 73728]
"Zooming"="c:\windows\system32\ZoomingHook.exe" [2004-07-14 24576]
"SmoothView"="c:\programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-12-21 118784]
"HWSetup"="c:\programmi\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-12-23 28672]
"TPSMain"="c:\windows\system32\TPSMain.exe" [2004-12-23 266240]
"TCtryIOHook"="c:\windows\system32\TCtrlIOHook.exe" [2005-01-03 28672]
"TOSHIBA Accessibility"="c:\programmi\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-12-07 24576]
"SVPWUTIL"="c:\programmi\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-12-27 61440]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-01-19 221184]
"LogitechVideoRepair"="c:\programmi\Logitech\Video\ISStart.exe" [2005-01-19 458752]
"LogitechVideoTray"="c:\programmi\Logitech\Video\LogiTray.exe" [2005-01-19 217088]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"COMODO Internet Security"="c:\programmi\COMODO\COMODO Internet Security\cfp.exe" [2009-08-05 1793808]
"UpdatePDRShortCut"="c:\programmi\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 172032]
"NDSTray.exe"="NDSTray.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
c:\documents and settings\abramo\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
TomTom HOME.lnk - c:\programmi\TomTom HOME\TomTomHOME.exe [2006-5-15 4815016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-07 17:34 356352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Orbit.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Orbit.lnk
backup=c:\windows\pss\Orbit.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitdm.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitnet.exe"=
"c:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [05/08/2009 0.26.47 132040]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [05/08/2009 0.26.47 25160]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\SASDIFSV.SYS [17/11/2008 16.11.06 9968]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [17/11/2008 16.11.04 55024]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\programmi\Avira\AntiVir Desktop\avmailc.exe [30/07/2009 17.14.21 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\programmi\Avira\AntiVir Desktop\sched.exe [30/07/2009 17.14.22 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\programmi\Avira\AntiVir Desktop\avwebgrd.exe [30/07/2009 17.14.21 434945]
S2 gupdate1c98926eb75ec0a;Google Update Service (gupdate1c98926eb75ec0a);c:\programmi\Google\Update\GoogleUpdate.exe [07/02/2009 15.20.58 133104]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\programmi\MAGIX\Common\Database\bin\fbserver.exe [04/08/2009 17.22.31 1527900]
S3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [17/11/2008 16.11.08 7408]
.
Contenuto della cartella 'Scheduled Tasks'
2009-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
2009-08-10 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-07 11:55]
2009-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-07 13:20]
2009-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-07 13:20]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{96EA7110-C0E2-44BF-94B1-03133A29521C} - (no file)
BHO-{A6B0797A-F20A-41DB-9156-90ED3EA0A577} - (no file)
BHO-{d9c1b07b-f26d-4432-80d8-aeacedac4c53} - (no file)
ShellExecuteHooks-{96EA7110-C0E2-44BF-94B1-03133A29521C} - (no file)
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://search.orbitdownloader.commStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &Download by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/204
IE: Crawler Search - tbr:iemenu
IE: Do&wnload selected by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/202
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\programmi\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: internet
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\programmi\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\abramo\Dati applicazioni\Mozilla\Firefox\Profiles\rfp1e8nn.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - component: c:\programmi\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\All Users\Dati applicazioni\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\programmi\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\programmi\Opera\program\plugins\nporbit.dll
FF - plugin: c:\programmi\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\programmi\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-10 14:49
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3628)
c:\windows\system32\WININET.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\COMODO\COMODO Internet Security\cmdagent.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\programmi\CyberLink\Shared files\RichVideo.exe
c:\programmi\TOSHIBA\ConfigFree\NDSTray.exe
c:\programmi\Logitech\Video\FxSvr2.exe
c:\programmi\Apoint2K\ApntEx.exe
c:\programmi\Orbitdownloader\orbitdm.exe
c:\windows\system32\RAMASST.exe
c:\programmi\Orbitdownloader\orbitnet.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2009-08-10 14.55.18 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-08-10 12:55
Pre-Run: 106.615.390.208 byte disponibili
Post-Run: 106.669.449.216 byte disponibili
WindowsXP-KB310994-SP2-Home-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
356 --- E O F --- 2009-07-31 19:00