ComboFix 10-07-26.04 - Leandro 28/07/2010 0.42.53.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1279.850 [GMT 2:00]
Eseguito da: c:\documents and settings\Leandro\Desktop\FOTO VIAGGIO D'ISTRUZIONE A BERLINO\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Leandro\Dati applicazioni\A2FCB06279BC659B125E7912519E56AC
c:\documents and settings\Leandro\Dati applicazioni\A2FCB06279BC659B125E7912519E56AC\enemies-names.txt
c:\documents and settings\Leandro\Dati applicazioni\A2FCB06279BC659B125E7912519E56AC\local.ini
c:\documents and settings\Leandro\Menu Avvio\Programmi\Antimalware Doctor
c:\documents and settings\Leandro\Menu Avvio\Programmi\Antimalware Doctor\Antimalware Doctor.lnk
c:\documents and settings\Leandro\Menu Avvio\Programmi\Antimalware Doctor\Uninstall.lnk
C:\PIPPO.TMP
c:\programmi\SpeedBit Video Downloader\Toolbar\tbhelper.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\Temp
c:\windows\system32\Temp\Kara_K5V.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
((((((((((((((((((((((((( Files Creati Da 2010-06-27 al 2010-07-27 )))))))))))))))))))))))))))))))))))
.
2010-07-27 21:05 . 2010-07-27 21:05 -------- d-----w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Adobe
2010-07-27 20:58 . 2010-07-27 20:58 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-07-27 20:43 . 2010-07-27 20:43 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-07-27 20:16 . 2010-07-27 21:44 -------- d-----w- c:\documents and settings\Leandro\Impostazioni locali\Dati applicazioni\tffovctuh
2010-07-27 19:40 . 2004-12-19 22:04 13824 ----a-w- C:\dmg2iso.exe
2010-07-27 14:00 . 2010-07-27 14:00 -------- d-----w- c:\windows\nvidia icons
2010-07-27 13:59 . 2008-05-03 03:46 442368 ----a-w- c:\windows\system32\nvudisp.exe
2010-07-27 13:58 . 2008-04-30 15:27 442368 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-07-24 08:56 . 2010-07-24 08:56 -------- d-----w- c:\documents and settings\Leandro\Dati applicazioni\Malwarebytes
2010-07-24 08:56 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-24 08:56 . 2010-07-24 08:56 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-07-24 08:56 . 2010-07-24 08:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-07-24 08:56 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-11 14:41 . 2008-04-10 10:08 71184 ----a-r- c:\windows\system32\drivers\DefragFS.sys
2010-07-11 14:41 . 2010-07-11 14:41 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Raxco
2010-07-11 14:40 . 2010-07-11 14:41 -------- d-----w- c:\programmi\Raxco
2010-07-08 09:46 . 2007-06-27 12:42 207488 ----a-r- c:\windows\system32\drivers\vinyl97.sys
2010-07-08 09:45 . 2010-07-08 09:46 -------- d-----w- c:\programmi\VIA
2010-07-08 09:45 . 2007-04-11 13:35 331184 ------w- c:\windows\system32\difxapi.dll
2010-07-07 20:09 . 2010-07-27 08:26 -------- d-----w- c:\programmi\SpeedFan
2010-07-07 20:03 . 2010-07-07 20:03 -------- d-----w- c:\programmi\Lavalys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-27 22:50 . 2010-01-09 14:19 -------- d-----w- c:\programmi\File comuni\Akamai
2010-07-27 22:48 . 2009-02-24 18:17 24 ----a-w- c:\windows\system32\DVCStateBkp-{00000000-00000000-00000008-00001102-00000002-80271102}.dat
2010-07-27 22:48 . 2009-02-24 18:17 24 ----a-w- c:\windows\system32\DVCState-{00000000-00000000-00000008-00001102-00000002-80271102}.dat
2010-07-27 22:48 . 2010-01-11 23:18 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-27 20:33 . 2009-02-25 12:03 -------- d-----w- c:\documents and settings\Leandro\Dati applicazioni\Orbit
2010-07-26 23:18 . 2009-04-15 16:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2010-07-24 10:57 . 2009-02-23 12:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee
2010-07-24 08:53 . 2009-03-09 16:49 -------- d-----w- c:\programmi\Google
2010-07-16 10:03 . 2009-04-17 15:55 -------- d-----w- c:\documents and settings\Leandro\Dati applicazioni\Media Player Classic
2010-07-15 15:11 . 2009-03-17 17:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-07-15 14:19 . 2009-02-19 16:10 122408 ----a-w- c:\documents and settings\Leandro\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-07-11 14:20 . 2009-03-30 08:05 -------- d-----w- c:\programmi\Avid
2010-07-11 14:17 . 2010-01-11 19:49 -------- d-----w- c:\programmi\Uninstall Tool
2010-07-11 14:16 . 2009-04-27 18:11 -------- d-----w- c:\programmi\Powerpoint-PPT to AVI-GIF Converter
2010-07-11 14:15 . 2010-04-12 12:09 -------- d-----w- c:\programmi\MemoriesOnTV4
2010-07-11 14:15 . 2009-04-30 14:26 -------- d-----w- c:\programmi\MAGIX
2010-07-11 14:15 . 2009-04-30 14:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MAGIX
2010-07-11 14:11 . 2010-04-09 19:25 -------- d-----w- c:\programmi\m.objects
2010-07-11 14:10 . 2009-04-27 18:42 -------- d-----w- c:\programmi\E.M. PowerPoint Video Converter
2010-07-11 14:09 . 2009-04-15 16:24 -------- d-----w- c:\programmi\CdCoverCreator
2010-07-11 14:07 . 2009-02-23 11:09 -------- d-----w- c:\programmi\File comuni\Adobe
2010-07-11 13:57 . 2009-02-23 13:05 -------- d-----w- c:\programmi\CCleaner
2010-07-09 22:41 . 2010-06-06 21:39 -------- d-----w- c:\documents and settings\Leandro\Dati applicazioni\uTorrent
2010-07-01 09:36 . 2003-04-08 11:00 48568 ----a-w- c:\windows\system32\perfc010.dat
2010-07-01 09:36 . 2003-04-08 11:00 347866 ----a-w- c:\windows\system32\perfh010.dat
2010-06-14 14:31 . 2009-02-19 16:02 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-06 21:43 . 2010-06-06 21:43 -------- d-----w- c:\programmi\uTorrent
2010-06-05 11:08 . 2009-07-16 21:14 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-06-03 12:37 . 2010-06-03 12:37 503808 ----a-w- c:\documents and settings\Leandro\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-41312316-n\msvcp71.dll
2010-06-03 12:37 . 2010-06-03 12:37 499712 ----a-w- c:\documents and settings\Leandro\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-41312316-n\jmc.dll
2010-06-03 12:37 . 2010-06-03 12:37 348160 ----a-w- c:\documents and settings\Leandro\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-41312316-n\msvcr71.dll
2010-06-03 12:37 . 2010-06-03 12:37 61440 ----a-w- c:\documents and settings\Leandro\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3c3ddc32-n\decora-sse.dll
2010-06-03 12:37 . 2010-06-03 12:37 12800 ----a-w- c:\documents and settings\Leandro\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3c3ddc32-n\decora-d3d.dll
2010-06-02 14:58 . 2010-06-02 14:58 1 ----a-w- c:\documents and settings\Leandro\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-02 14:58 . 2010-06-02 14:58 -------- d-----w- c:\documents and settings\Leandro\Dati applicazioni\OpenOffice.org
2010-06-02 14:55 . 2010-06-02 14:55 -------- d-----w- c:\programmi\JRE
2010-06-02 14:55 . 2010-06-02 14:55 -------- d-----w- c:\programmi\OpenOffice.org 3
2010-06-02 14:55 . 2010-06-02 14:55 -------- d-----w- c:\programmi\File comuni\Java
2010-06-02 14:54 . 2009-11-16 21:13 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-06-02 14:54 . 2010-06-02 14:54 -------- d-----w- c:\programmi\Java
2010-05-06 10:32 . 2008-04-13 17:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:06 . 2008-04-13 16:50 1851264 ----a-w- c:\windows\system32\win32k.sys
2006-05-03 10:06 . 2009-05-12 14:54 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2009-05-12 14:54 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2009-05-12 14:54 216064 --sh--r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3017FB3E-9A77-4396-88C5-0EC9548FB42F}]
2010-02-08 20:07 2447360 ----a-w- c:\programmi\SpeedBit Video Downloader\Toolbar\tbcore3.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedBitVideoAccelerator"="c:\programmi\SpeedBit Video Accelerator\VideoAccelerator.exe" [2010-02-08 1611368]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-09 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DSLSTATEXE"="c:\program files\Hamlet\Adsl\dslstat.exe" [2005-10-24 344064]
"DSLAGENTEXE"="c:\program files\Hamlet\Adsl\dslagent.exe" [2005-08-25 65536]
"avgnt"="c:\programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"Jet Detection"="c:\programmi\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 110592]
"Disc Detector"="c:\programmi\Creative\ShareDLL\CtNotify.exe" [2001-12-26 191488]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"AudioDeck"="c:\programmi\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-08-09 528384]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKLM\~\startupfolder\C:^Documents and Settings^Leandro^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma.lnk]
path=c:\documents and settings\Leandro\Menu Avvio\Programmi\Esecuzione automatica\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Leandro^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\Leandro\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 15:10 35696 ----a-w- c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2006-11-12 10:48 157592 ----a-w- c:\programmi\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-06-30 08:21 133104 ----atw- c:\documents and settings\Leandro\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NexusServer]
2007-03-26 15:45 389120 ----a-w- c:\programmi\File comuni\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-05-03 03:46 1630208 ----a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 14:18 413696 ----a-w- c:\programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 13:21 246504 ----a-w- c:\programmi\File comuni\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-03-09 16:50 39408 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2008-05-02 04:15 15872 ----a-w- c:\programmi\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 00:00 90112 ------w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch]
2002-07-02 16:56 24576 ----a-w- c:\windows\system32\CTHELPER.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitdm.exe"=
"c:\\Programmi\\Orbitdownloader\\orbitnet.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
"c:\\Programmi\\File comuni\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\hasplms.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\WINWORD.EXE"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [13/04/2008 19.14.22 14336]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [30/03/2009 10.08.47 16400]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run
c:\windows\system32\hasplms.exe -run
R2 PD91Agent;PD91Agent;c:\programmi\Raxco\PerfectDisk2008\PD91Agent.exe [16/04/2008 13.00.10 689416]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe -start -scm
c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe -start -scm
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [28/06/2009 18.02.45 17792]
S2 gupdate1c9bde4792687f2;Servizio di Google Update (gupdate1c9bde4792687f2);c:\programmi\Google\Update\GoogleUpdate.exe [15/04/2009 18.08.52 133104]
S3 PAC207;Look 110;c:\windows\system32\drivers\PFC027.SYS [26/06/2009 16.23.21 507264]
S3 PD91Engine;PD91Engine;c:\programmi\Raxco\PerfectDisk2008\PD91Engine.exe [16/04/2008 13.00.12 894216]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28/03/2009 17.14.12 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contenuto della cartella 'Scheduled Tasks'
2010-07-27 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-09 16:05]
2010-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-04-15 16:08]
2010-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-04-15 16:08]
2010-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-329068152-764733703-1417001333-1004Core.job
- c:\documents and settings\Leandro\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-11-02 08:21]
2010-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-329068152-764733703-1417001333-1004UA.job
- c:\documents and settings\Leandro\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-11-02 08:21]
2010-07-27 c:\windows\Tasks\User_Feed_Synchronization-{C1E840DE-AAB5-4615-8982-CD6428D1E3FC}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.com/uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/204
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: Apri in nuova scheda in primo piano - c:\programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?15957414014a414b9e56934c7c780d22
IE: Apri in nuova scheda in secondo piano - c:\programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?15957414014a414b9e56934c7c780d22
IE: Do&wnload selected by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\programmi\Orbitdownloader\orbitmxt.dll/202
IE: E&sporta in Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Image Converter 2 ??? - c:\programmi\Sony\Image Converter 2\menu.htm
IE: Sothink SWF Catcher - c:\programmi\File comuni\SourceTec\SWF Catcher\InternetExplorer.htm
IE: Trasferimento con Image Converter 2 - c:\programmi\Sony\Image Converter 2\menu.htm
LSP: c:\progra~1\SPEEDB~2\sblsp.dll
FF - ProfilePath - c:\documents and settings\Leandro\Dati applicazioni\Mozilla\Firefox\Profiles\k4rzzh4b.default\
FF - plugin: c:\documents and settings\Leandro\Impostazioni locali\Dati applicazioni\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-AdobeBridge - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-28 00:52
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = c:\programmi\Creative\ShareDLL\CtNotify.exe?` ??X???R???????????????E?@?Disc Detector?A????? ?A?@ ????B?e!@???@???@?? C?????E?@?????????@?B???A????? ?A?? ????B???@?????P?????@?` ??????~?:~??????????@???????????????????B?????? ??????????????????????????r?B
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-329068152-764733703-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{31A97C01-D1CE-345B-9C37-79C4C7D7CEAA}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jaondabjdmmoennacafj"=hex:62,61,63,6d,00,00
"jaondabjdmmoennacabj"=hex:62,61,6a,6a,00,00
"iaocpdacfhnnoaalfe"=hex:6b,61,62,6d,70,6e,6b,6e,62,61,69,70,64,69,70,61,61,6b,
65,65,68,70,00,00
"haeejdmepdgmlmgi"=hex:6b,61,62,6d,70,6e,6e,6e,6e,63,69,62,61,70,62,62,6b,70,
67,61,65,6a,00,00
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'lsass.exe'(780)
c:\progra~1\SPEEDB~2\sblsp.dll
c:\programmi\SpeedBit Video Accelerator\Accelerator.dll
c:\windows\system32\WININET.dll
c:\programmi\SpeedBit Video Accelerator\Collector.dll
- - - - - - - > 'explorer.exe'(1976)
c:\windows\system32\WININET.dll
c:\programmi\Windows Media Player\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\system32\CTsvcCDA.exe
c:\programmi\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\windows\system32\hasplms.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\programmi\Creative\ShareDLL\Mediadet.exe
c:\progra~1\SPEEDB~2\VideoAcceleratorEngine.exe
.
**************************************************************************
.
Ora fine scansione: 2010-07-28 00:59:30 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-07-27 22:59
Pre-Run: 9.217.429.504 byte disponibili
Post-Run: 17.927.655.424 byte disponibili
WindowsXP-KB310994-SP2-Home-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - C1096D950805D69C25D7938C632EEDE1