ComboFix 10-11-27.01 - AMD-X3 27/11/2010 22:07:07.2.3 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.39.1040.18.3327.2568 [GMT 1:00]
Eseguito da: c:\users\AMD-X3\Desktop\pippo.exe.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.
((((((((((((((((((((((((( Files Creati Da 2010-10-27 al 2010-11-27 )))))))))))))))))))))))))))))))))))
.
2010-11-27 21:13 . 2010-11-27 21:13 -------- d-----w- c:\users\AMD-X3\AppData\Local\temp
2010-11-27 21:13 . 2010-11-27 21:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-11-27 11:35 . 2010-11-27 11:35 388096 ----a-r- c:\users\AMD-X3\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-25 16:40 . 2010-11-25 16:41 -------- d-----w- c:\users\AMD-X3\AppData\Local\Ahead
2010-11-24 12:09 . 2010-10-19 08:10 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-17 11:28 . 2010-11-17 11:28 -------- d-----w- c:\program files\XoftSpySE
2010-11-17 08:04 . 2010-11-17 08:04 -------- d-----w- c:\program files\TextBridge Pro Millennium
2010-11-17 08:04 . 2010-11-17 08:04 -------- d-----w- c:\windows\Pixtran
2010-11-17 08:04 . 2010-11-17 08:04 -------- d-----w- c:\programdata\TextBridge
2010-11-17 08:04 . 2010-11-17 08:04 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2010-11-16 16:56 . 2010-11-16 16:56 -------- d-----w- c:\users\AMD-X3\AppData\Local\Adobe
2010-11-11 19:23 . 2010-11-11 19:23 -------- d-----w- c:\programdata\Sports Interactive
2010-11-11 19:22 . 2010-11-16 11:04 -------- d-----w- c:\users\AMD-X3\AppData\Roaming\Sports Interactive
2010-11-11 19:22 . 2010-11-11 19:22 -------- d-----w- c:\users\AMD-X3\AppData\Local\Sports Interactive
2010-11-11 19:01 . 2010-11-11 19:02 -------- d--h--w- c:\program files\Zero G Registry
2010-11-11 19:01 . 2010-11-11 19:01 -------- d-----w- c:\program files\Sports Interactive
2010-11-11 19:00 . 2010-11-11 19:00 -------- d--h--w- c:\users\AMD-X3\InstallAnywhere
2010-11-07 18:07 . 2010-11-07 18:07 -------- d-----w- c:\program files\MiPony
2010-11-07 12:35 . 2010-11-07 12:35 -------- d-----w- c:\users\AMD-X3\AppData\Local\Quadriga Games
2010-11-07 12:15 . 2008-03-05 15:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll
2010-11-07 12:02 . 2010-11-07 12:02 -------- d-----w- c:\program files\Quadriga Games
2010-11-07 00:58 . 2010-11-07 00:58 -------- d-----w- c:\users\AMD-X3\AppData\Roaming\Media Player Classic
2010-11-07 00:56 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
2010-11-07 00:56 . 2010-11-07 00:57 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-11-06 10:37 . 2010-11-06 10:37 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-11-06 10:37 . 2010-11-06 10:37 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2010-11-05 14:27 . 2010-11-05 14:27 -------- d-----w- c:\users\AMD-X3\.idlerc
2010-11-05 14:22 . 2010-11-05 14:22 -------- d-----w- C:\Python27
2010-11-05 14:16 . 2010-11-05 14:16 -------- d-----w- c:\users\AMD-X3\AppData\Local\qBittorrent
2010-11-05 14:16 . 2010-11-05 14:37 -------- d-----w- c:\users\AMD-X3\AppData\Roaming\qBittorrent
2010-11-05 14:16 . 2010-11-05 14:16 -------- d-----w- c:\program files\qBittorrent
2010-11-03 18:36 . 2010-11-03 18:39 -------- d-----w- c:\program files\Windows Live Safety Center
2010-11-03 17:45 . 2010-11-03 17:48 -------- d-----w- c:\users\AMD-X3\AppData\Roaming\Runscanner.net
2010-11-03 17:08 . 2010-11-03 17:08 -------- d-----w- c:\users\AMD-X3\DoctorWeb
2010-10-31 17:43 . 2010-10-31 17:43 -------- d-----w- c:\users\AMD-X3\AppData\Roaming\Megaupload
2010-10-31 17:42 . 2010-10-31 17:42 -------- d-----w- c:\program files\Megaupload
2010-10-31 11:45 . 2010-10-31 11:45 -------- d-----w- c:\users\AMD-X3\AppData\Roaming\skypePM
2010-10-31 11:37 . 2010-10-31 11:37 -------- d-----w- c:\program files\Common Files\Skype
2010-10-31 11:37 . 2010-10-31 11:54 -------- d-----w- c:\users\AMD-X3\AppData\Roaming\Skype
2010-10-31 11:37 . 2010-10-31 11:37 -------- d-----w- c:\programdata\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 09:41 . 2010-09-05 00:28 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-14 00:36 . 2010-10-14 00:36 15451288 ----a-w- c:\windows\system32\xlive.dll
2010-10-14 00:36 . 2010-10-14 00:36 13642904 ----a-w- c:\windows\system32\xlivefnt.dll
2010-10-07 23:21 . 2010-10-26 14:56 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1EA08B80-0E00-4A22-AC46-0F955FC4937E}\mpengine.dll
2010-10-03 11:45 . 2010-10-02 19:06 5852 --sha-w- c:\programdata\KGyGaAvL.sys
2010-10-03 11:26 . 2010-10-02 20:17 88 --sh--r- c:\programdata\C339199FAF.sys
2010-09-24 15:48 . 2010-09-24 15:48 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2010-09-24 15:48 . 2010-09-24 15:48 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2010-09-22 22:47 . 2010-09-22 22:47 49016 ----a-w- c:\windows\system32\sirenacm.dll
2010-09-22 22:32 . 2010-09-22 22:32 301936 ----a-w- c:\windows\WLXPGSS.SCR
2010-09-21 12:03 . 2010-09-21 12:03 208768 ----a-w- c:\windows\system32\LIVESSP.DLL
2010-09-11 20:24 . 2010-09-11 20:24 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-08 04:30 . 2010-10-13 11:37 978432 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28 . 2010-10-13 11:37 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22 . 2010-10-13 11:37 386048 ----a-w- c:\windows\system32\html.iec
2010-09-08 02:48 . 2010-10-13 11:37 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-05 11:04 . 2010-09-05 11:04 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-01 04:23 . 2010-10-13 11:37 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-01 02:34 . 2010-10-13 11:37 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-08-31 04:32 . 2010-10-13 11:37 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 04:32 . 2010-10-13 11:37 954288 ----a-w- c:\windows\system32\mfc40u.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-09-22 4240760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-09-14 352976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2009-02-25 9728]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2009-02-25 3072]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-04 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 FSProFilter;FSPro File Filter;c:\windows\System32\Drivers\FSPFltd.sys [2008-06-05 43792]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-05 691696]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11352]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 22104]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [2010-01-06 142648]
S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-06-24 65856]
S2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2009-07-14 7168]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-08-24 92008]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
S3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [2007-12-20 1553896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contenuto della cartella 'Scheduled Tasks'
2010-11-27 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-07-13 07:43]
2010-11-17 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-07-13 07:43]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.msn.comIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Scarica con Mipony -
file://c:\program files\MiPony\Browser\IEContext.htm
TCP: {B775D120-5406-4BA4-8B76-C475EC6DD498} = 192.168.1.1,151.99.125.1
FF - ProfilePath - c:\users\AMD-X3\AppData\Roaming\Mozilla\Firefox\Profiles\lxybe5qm.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - component: c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - Extension: Anti-Banner:
KavAntiBanner@Kaspersky.ru - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Extension: Kaspersky URL Advisor:
linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: All-in-One Sidebar: {097d3191-e6fa-4728-9826-b533d755359d} - c:\users\AMD-X3\AppData\Roaming\Mozilla\Firefox\Profiles\lxybe5qm.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
FF - Extension: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
AddRemove-EASEUS Partition Master Unlimited Edition_is1 - c:\program files\EASEUS\EASEUS Partition Master 3.5 Unlimited Edition\unins000.exe
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2010-11-27 22:15:07
ComboFix-quarantined-files.txt 2010-11-27 21:15
Pre-Run: 62.360.268.800 byte disponibili
Post-Run: 62.507.806.720 byte disponibili
- - End Of File - - E0E410C220BF5BDA7B8818992FD88C34