ComboFix 09-11-25.01 - Robert 25/11/2009 21.49.17.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.2046.1497 [GMT 1:00]
Eseguito da: c:\documents and settings\Robert\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00200000-EE94-0012-94EE-120094EE1200}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-2C24-9E7C08000A00}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-3C24-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\EasySearch\BHO\4.SUpersearch.dll
c:\progra~1\GooglePlusVideos\17.Googleplusvideos.dll
c:\programmi\GooglePlusVideos
c:\programmi\GooglePlusVideos\17.GooglePlusVideos.dll
c:\programmi\GooglePlusVideos\DeploymentHelper.exe
c:\programmi\GooglePlusVideos\FFExt\chrome.manifest
c:\programmi\GooglePlusVideos\FFExt\chrome\content\googleplusvideos.xul
c:\programmi\GooglePlusVideos\FFExt\chrome\content\script-injector.js
c:\programmi\GooglePlusVideos\FFExt\install.rdf
c:\programmi\GooglePlusVideos\GooglePlusVideosLicense.txt
c:\programmi\GooglePlusVideos\GooglePlusVideosXPCOM.dll
c:\programmi\GooglePlusVideos\GVConfig.ini
c:\programmi\GooglePlusVideos\IGooglePlusVideosXPCOM.xpt
c:\programmi\GooglePlusVideos\MFC42U.DLL
c:\programmi\GooglePlusVideos\Uninstall.bat
.
((((((((((((((((((((((((( Files Creati Da 2009-10-25 al 2009-11-25 )))))))))))))))))))))))))))))))))))
.
2009-11-25 18:42 . 2009-11-25 18:42 -------- d-----w- c:\programmi\Trend Micro
2009-11-24 20:01 . 2009-11-24 20:01 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\Malwarebytes
2009-11-24 20:01 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-24 20:01 . 2009-11-24 20:01 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-11-24 20:01 . 2009-11-24 20:01 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-11-24 20:01 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-23 18:44 . 2009-11-23 18:44 -------- d-----w- c:\documents and settings\Robert\Impostazioni locali\Dati applicazioni\Threat Expert
2009-11-23 18:41 . 2009-10-08 10:31 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-11-23 18:41 . 2009-10-08 10:31 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-11-23 18:41 . 2009-10-08 10:31 1636304 ----a-w- c:\windows\PCTBDCore.dll
2009-11-23 18:41 . 2009-10-08 10:31 767952 ----a-w- c:\windows\BDTSupport.dll
2009-11-23 18:41 . 2009-10-02 13:19 1152470 ----a-w- c:\windows\UDB.zip
2009-11-23 18:41 . 2008-11-26 11:08 131 ----a-w- c:\windows\IDB.zip
2009-11-23 18:39 . 2009-09-24 07:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-23 18:39 . 2009-10-06 15:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-23 18:39 . 2009-09-23 15:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-23 18:39 . 2009-09-03 08:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-23 18:39 . 2009-11-23 18:41 -------- d-----w- c:\programmi\File comuni\PC Tools
2009-11-23 18:39 . 2009-11-25 20:49 -------- d-----w- c:\programmi\Spyware Doctor
2009-11-23 18:39 . 2009-11-23 18:39 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\PC Tools
2009-11-23 18:39 . 2009-11-23 18:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Tools
2009-11-23 18:39 . 2009-11-25 20:48 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-11-23 00:41 . 2009-11-24 23:33 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\vlc
2009-11-19 15:19 . 2009-11-19 15:19 -------- d-----w- c:\programmi\Electronic Arts
2009-11-18 17:22 . 2009-11-18 18:57 -------- d-----w- c:\windows\SxsCaPendDel
2009-11-18 16:59 . 2009-11-18 16:59 -------- d-----w- c:\documents and settings\Robert\Impostazioni locali\Dati applicazioni\Monte Cristo
2009-11-18 16:51 . 2009-11-18 16:51 -------- d-----w- c:\programmi\Monte Cristo
2009-11-17 19:14 . 2009-11-17 19:14 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\Convivea
2009-11-17 19:14 . 2009-04-10 17:40 118784 ----a-w- c:\documents and settings\Robert\Dati applicazioni\Convivea\Bit_Che\scripts\x.exe
2009-11-17 19:14 . 2008-03-28 09:07 20992 ----a-w- c:\documents and settings\Robert\Dati applicazioni\Convivea\Bit_Che\languages\compare.exe
2009-11-17 19:14 . 2008-03-28 09:02 60928 ----a-w- c:\documents and settings\Robert\Dati applicazioni\Convivea\Bit_Che\scripts\update.exe
2009-11-17 19:14 . 2003-08-19 04:06 80896 ----a-w- c:\documents and settings\Robert\Dati applicazioni\Convivea\Bit_Che\scripts\x.dll
2009-11-17 19:14 . 2009-11-17 19:14 -------- d-----w- c:\programmi\Bit Che
2009-11-13 14:44 . 2009-11-13 14:44 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\TeamViewer
2009-11-13 14:44 . 2009-11-13 14:44 -------- d-----w- c:\documents and settings\Robert\temp
2009-11-13 14:34 . 2009-11-13 14:49 -------- d-----w- C:\Documents
2009-11-13 13:09 . 2009-11-25 20:46 -------- d-----w- c:\programmi\Steam
2009-11-13 13:09 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-11-13 13:09 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-11-13 13:09 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-11-13 13:09 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-11-13 13:09 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-11-13 13:09 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-11-13 13:09 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-11-12 22:35 . 2009-11-19 23:40 -------- d-----w- C:\Downloads
2009-11-12 22:30 . 2009-11-25 20:42 -------- d-----w- c:\programmi\FlashGet
2009-11-09 21:48 . 2009-11-09 21:48 -------- d-----w- c:\programmi\EA Sports
2009-11-06 13:25 . 2009-11-06 13:25 -------- d-----w- c:\programmi\CAPCOM
2009-10-30 10:06 . 2009-10-30 10:06 -------- d-----w- c:\documents and settings\Robert\Impostazioni locali\Dati applicazioni\Risen
2009-10-30 10:05 . 2009-10-30 10:05 -------- d-----w- c:\windows\1C4551A64743409391E41477CD655043.TMP
2009-10-30 10:00 . 2009-10-30 10:00 -------- d-----w- c:\programmi\Deep Silver
2009-10-30 09:34 . 2009-10-30 09:34 73837 ----a-w- c:\documents and settings\Robert\Dati applicazioni\VuzeStream\uninstall.exe
2009-10-30 09:34 . 2009-10-30 09:34 74688 ----a-w- c:\documents and settings\Robert\Dati applicazioni\VuzeStream\NetscapePlugin1.0.2.9\RegisterVSNP.exe
2009-10-30 09:34 . 2009-10-30 09:34 62400 ----a-w- c:\documents and settings\Robert\Dati applicazioni\VuzeStream\RegisterVSAX.exe
2009-10-30 09:34 . 2009-10-30 09:34 293312 ----a-w- c:\documents and settings\Robert\Dati applicazioni\VuzeStream\VuzeATL1.0.2.0.dll
2009-10-30 09:34 . 2009-10-30 09:34 176608 ----a-w- c:\documents and settings\Robert\Dati applicazioni\VuzeStream\UpdateLauncher.exe
2009-10-30 09:34 . 2009-10-30 09:34 170432 ----a-w- c:\documents and settings\Robert\Dati applicazioni\VuzeStream\NetscapePlugin1.0.2.9\npVuzeStream.dll
2009-10-30 09:34 . 2009-10-30 09:34 174560 ----a-w- c:\documents and settings\Robert\Dati applicazioni\VuzeStream\VuzeStream.exe
2009-10-30 09:34 . 2009-10-30 09:34 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-10-30 09:34 . 2009-10-30 09:44 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\VuzeStream
2009-10-30 09:28 . 2009-10-30 09:28 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Azureus
2009-10-30 09:27 . 2009-11-12 13:41 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\Azureus
2009-10-30 09:27 . 2009-10-30 09:27 -------- d-----w- c:\programmi\Vuze
2009-10-29 23:35 . 2009-11-12 21:59 -------- d-----w- c:\programmi\JDownloader
2009-10-29 23:34 . 2009-10-29 23:34 -------- d-----w- c:\windows\Sun
2009-10-29 09:55 . 2009-10-29 09:55 -------- d-----w- c:\programmi\KONAMI
2009-10-29 09:55 . 2009-10-29 09:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\KONAMI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-25 20:46 . 2001-08-31 12:00 79292 ----a-w- c:\windows\system32\perfc010.dat
2009-11-25 20:46 . 2001-08-31 12:00 478808 ----a-w- c:\windows\system32\perfh010.dat
2009-11-25 19:49 . 2009-09-25 13:55 50496 ----a-w- c:\documents and settings\Robert\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-11-25 11:19 . 2009-09-25 14:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-11-19 14:44 . 2009-09-29 22:48 138064 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-19 14:43 . 2009-09-29 22:48 189184 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-11-13 19:11 . 2009-10-19 00:25 859304 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2009-11-13 15:00 . 2009-09-29 22:33 -------- d-----w- c:\programmi\Activision
2009-10-30 10:05 . 2009-09-25 14:11 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-10-30 10:00 . 2009-09-25 13:43 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-10-28 14:02 . 2009-09-25 23:34 -------- d-----w- c:\programmi\File comuni\Adobe
2009-10-21 14:26 . 2009-10-21 14:26 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\FUEL
2009-10-21 14:22 . 2009-10-21 14:21 -------- d-----w- c:\programmi\Microsoft Games for Windows - LIVE
2009-10-21 14:18 . 2009-10-21 14:18 -------- d-----w- c:\programmi\Codemasters
2009-10-20 13:04 . 2009-10-20 12:53 -------- d-----w- c:\programmi\EasySearch
2009-10-20 12:43 . 2009-10-20 12:42 -------- d-----w- c:\programmi\Windows Live Safety Center
2009-10-20 10:43 . 2009-10-20 10:43 -------- d-----w- c:\programmi\Microsoft.NET
2009-10-19 18:12 . 2006-06-22 20:43 360320 ----a-w- c:\windows\system32\drivers\TCPIP.SYS
2009-10-19 18:12 . 2009-10-19 18:12 360320 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-10-18 23:20 . 2009-10-18 23:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DriverScanner
2009-10-18 23:19 . 2009-10-18 23:19 -------- dc-h--w- c:\documents and settings\All Users\Dati applicazioni\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2009-10-18 23:19 . 2009-10-18 22:53 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\Uniblue
2009-10-18 23:19 . 2009-10-18 22:53 -------- d-----w- c:\programmi\Uniblue
2009-10-18 23:13 . 2009-10-18 23:13 -------- dc-h--w- c:\documents and settings\All Users\Dati applicazioni\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-10-15 09:48 . 2009-10-15 09:48 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\Ubisoft
2009-10-15 09:41 . 2009-10-15 09:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Tages
2009-10-15 09:36 . 2009-10-15 09:36 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-10-15 09:36 . 2009-10-15 09:36 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-10-15 09:31 . 2009-10-15 09:31 -------- d-----w- c:\programmi\Ubisoft
2009-10-14 16:22 . 2009-10-14 16:22 -------- d-----w- c:\programmi\Smart Projects
2009-10-08 16:01 . 2009-10-08 16:01 -------- d-----w- c:\programmi\File comuni\NewSoft
2009-10-08 16:01 . 2009-10-08 16:01 -------- d-----w- c:\programmi\NewSoft
2009-10-08 15:58 . 2009-10-08 15:58 -------- d-----w- c:\programmi\Dexxon
2009-10-08 15:49 . 2009-10-08 15:49 -------- d-----w- c:\programmi\MSBuild
2009-10-08 15:49 . 2009-10-08 15:49 -------- d-----w- c:\programmi\Reference Assemblies
2009-10-08 15:47 . 2009-10-08 15:47 -------- d-----w- c:\programmi\MSXML 6.0
2009-10-06 21:15 . 2009-10-06 21:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Drivers HeadQuarters
2009-10-01 12:25 . 2009-10-01 12:25 -------- d-----w- c:\programmi\VideoLAN
2009-09-30 18:40 . 2009-09-25 13:25 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-09-30 18:34 . 2009-09-30 18:34 -------- d-----w- c:\programmi\TVAnts
2009-09-30 12:52 . 2009-09-25 16:21 -------- d-----w- c:\programmi\Windows Media Connect 2
2009-09-30 12:44 . 2009-09-29 22:48 139152 ----a-w- c:\documents and settings\Robert\Dati applicazioni\PnkBstrK.sys
2009-09-30 12:44 . 2009-09-29 22:48 139152 ----a-w- c:\documents and settings\Robert\Dati applicazioni\PnkBstrK.sys
2009-09-30 12:44 . 2009-09-29 22:48 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-09-30 12:44 . 2009-09-30 12:44 794408 ----a-w- c:\windows\system32\pbsvc[1].exe
2009-09-30 12:21 . 2009-09-30 12:21 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2009-09-30 12:21 . 2009-09-30 12:21 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf
2009-09-30 12:20 . 2009-09-30 12:20 -------- d-----w- c:\programmi\Microsoft Xbox 360 Accessories
2009-09-30 10:54 . 2009-09-30 10:54 -------- d-----w- c:\documents and settings\Robert\Dati applicazioni\Leadertech
2009-09-29 22:48 . 2009-09-29 22:48 682280 ----a-w- c:\windows\system32\pbsvc.exe
2009-09-28 11:40 . 2009-09-28 11:40 -------- d-----w- c:\programmi\eMule
2009-09-28 09:31 . 2009-10-18 23:13 2838456 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}\speedupmypc2009.exe
2009-09-26 14:32 . 2009-09-26 14:32 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-09-26 12:34 . 2009-09-26 12:34 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-25 16:39 . 2009-09-25 16:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-25 16:39 . 2009-09-25 16:39 152576 ----a-w- c:\documents and settings\Robert\Dati applicazioni\Sun\Java\jre1.6.0_16\lzma.dll
2009-09-25 15:16 . 2009-09-25 15:16 10134 ----a-r- c:\documents and settings\Robert\Dati applicazioni\Microsoft\Installer\{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}\ARPPRODUCTICON.exe
2009-09-25 14:50 . 2009-09-25 14:50 1961720 ----a-w- c:\documents and settings\Robert\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-09-25 13:43 . 2009-09-25 13:43 315392 ----a-w- c:\windows\HideWin.exe
2009-09-25 13:22 . 2009-09-25 13:22 21840 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-04 16:44 . 2009-10-15 09:36 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
.
------- Sigcheck -------
[-] 2009-10-19 . 3C966F647BAB332093CB0F92692B5CB8 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\TCPIP.SYS
[-] 2009-10-19 . 3C966F647BAB332093CB0F92692B5CB8 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\drivers\TCPIP.SYS
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\073a8e9684d59d4923c2eb2e44aa36af\tcpip.sys
[7] 2006-06-22 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$NtUninstallKB917953$\tcpip.sys
[7] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[7] 2006-04-20 . 1DBF125862891817F374F407626967F4 . 359808 . . [5.1.2600.2892] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-25 39408]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Creative WebCam Tray"="c:\programmi\Creative\Shared Files\CamTray.exe" [2005-10-27 299008]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Steam"="c:\programmi\Steam\Steam.exe" [2009-11-13 1217808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Quick Search Box"="c:\programmi\Google\Quick Search Box\GoogleQuickSearchBox.exe " [X]
"XboxStat"="c:\programmi\Microsoft Xbox 360 Accessories\XboxStat.exe silentrun" [X]
"nwiz"="c:\programmi\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-09-25 149280]
"ChangeFilterMerit"="c:\programmi\NewSoft\Presto! PVR\ChangeFilterMerit.exe" [2007-06-08 51280]
"Presto! PVR Monitor"="c:\programmi\NewSoft\Presto! PVR\Monitor.exe" [2009-01-15 157520]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"ISTray"="c:\programmi\Spyware Doctor\pctsTray.exe" [2009-09-22 1243088]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-03-21 16126464]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\Robert\Menu Avvio\Programmi\Esecuzione automatica\
Utilit… controllo supporti di Picture Motion Browser.lnk - c:\programmi\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-9-25 390432]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Programmi\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Programmi\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Programmi\\TVAnts\\Tvants.exe"=
"c:\\Programmi\\Ubisoft\\Related Designs\\ANNO 1404\\Anno4.exe"=
"c:\\Programmi\\Ubisoft\\Related Designs\\ANNO 1404\\tools\\Anno4Web.exe"=
"c:\\Programmi\\Codemasters\\FUEL\\FUEL.exe"=
"c:\\Documents and Settings\\Robert\\Desktop\\pes2010.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
"c:\\Documents and Settings\\Robert\\Dati applicazioni\\VuzeStream\\VuzeStream.exe"=
"c:\\Programmi\\CAPCOM\\RESIDENT EVIL 5\\RE5DX9.EXE"=
"c:\\Programmi\\CAPCOM\\RESIDENT EVIL 5\\RE5DX10.EXE"=
"c:\\Programmi\\FlashGet\\flashget.exe"=
"c:\\Documents and Settings\\Robert\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [23/11/2009 19.39.29 207280]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\programmi\Spyware Doctor\BDT\BDTUpdateService.exe [23/11/2009 19.41.00 112592]
R2 sdAuxService;PC Tools Auxiliary Service;c:\programmi\Spyware Doctor\pctsAuxs.exe [23/11/2009 19.39.15 358600]
R3 V0260VID;Live! Cam Vista IM;c:\windows\system32\drivers\V0260Vid.sys [25/09/2009 16.49.00 178913]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/09/2009 13.34.37 721904]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [25/09/2009 23.48.57 133104]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - PCTSDInjDriver32
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-09-25 22:48]
2009-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-09-25 22:48]
2009-11-25 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-09-27 20:18]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.europowersearch.com/Search.html?SelectedSearchLang=IT
uInternet Settings,ProxyOverride = local
IE: &Scarica con FlashGet - c:\programmi\FlashGet\jc_link.htm
IE: &Scarica tutto con FlashGet - c:\programmi\FlashGet\jc_all.htm
IE: E&sporta in Microsoft Excel - c:\progra~1\Microsoft Office\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-NWEReboot - (no file)
AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI
AddRemove-Uniblue DriverScanner 2009 - c:\documents and settings\All Users\Dati applicazioni\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\DriverScanner_Setup.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-Uniblue SpeedUpMyPC 2009 - c:\documents and settings\All Users\Dati applicazioni\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}\speedupmypc2009.exe REMOVE=TRUE MODIFY=FALSE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-25 21:52
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2009-11-25 21:53
ComboFix-quarantined-files.txt 2009-11-25 20:53
Pre-Run: 301.690.707.968 byte disponibili
Post-Run: 301.682.933.760 byte disponibili
- - End Of File - - CF0A04A061FF40A09D5658CDAB4944C8