TI POSTO SOLO IL LOG DI OCMBOFIX, purtroppo non mi fa installare hijack this, mi dice praticamente che per i criteri impostati dall'amministratore non è possibile installare....
cmq ecco il log:
ComboFix 10-04-30.03 - Marco 01/05/2010 19.45.24.6.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.39.1040.18.1022.423 [GMT 2:00]
Eseguito da: c:\users\Marco\Documents\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\%appdata%
.
((((((((((((((((((((((((( Files Creati Da 2010-04-01 al 2010-05-01 )))))))))))))))))))))))))))))))))))
.
2010-05-01 17:54 . 2010-05-01 17:57 -------- d-----w- c:\users\Marco\AppData\Local\temp
2010-05-01 17:54 . 2010-05-01 17:54 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-05-01 17:54 . 2010-05-01 17:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-18 09:56 . 2010-04-18 09:56 -------- d-----w- c:\program files\Widget vodafone.it
2010-04-14 20:30 . 2010-02-23 11:32 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 20:30 . 2010-02-23 11:32 78848 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 20:30 . 2010-02-23 11:32 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 20:29 . 2010-02-18 14:49 3598216 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 20:29 . 2010-02-18 14:49 3545992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 20:29 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-04-14 20:29 . 2010-02-18 14:49 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 20:29 . 2010-02-18 14:11 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 20:29 . 2010-02-18 11:52 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 11:42 . 2009-12-23 12:43 171520 ----a-w- c:\windows\system32\wintrust.dll
2010-04-14 11:42 . 2010-01-15 00:04 98304 ----a-w- c:\windows\system32\cabview.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-01 17:50 . 2006-11-06 01:52 665464 ----a-w- c:\windows\system32\perfh010.dat
2010-05-01 17:50 . 2006-11-06 01:52 121096 ----a-w- c:\windows\system32\perfc010.dat
2010-05-01 17:40 . 2008-11-03 00:33 -------- d-----w- c:\users\Marco\AppData\Roaming\uTorrent
2010-05-01 09:46 . 2009-01-11 15:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-30 19:42 . 2008-01-10 08:58 -------- d-----w- c:\program files\eMule
2010-04-29 13:39 . 2009-01-11 15:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2009-01-11 15:09 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-28 23:04 . 2009-07-25 21:53 -------- d-----w- c:\program files\Burraconline
2010-04-20 14:17 . 2010-04-20 14:17 12 ----a-w- c:\users\Marco\AppData\Roaming\kcmdte.dat
2010-04-15 10:39 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-14 23:13 . 2007-10-31 18:36 -------- d-----w- c:\programdata\Microsoft Help
2010-03-03 18:14 . 2008-01-10 10:12 -------- d-----w- c:\program files\Windows Live
2010-03-03 18:01 . 2010-03-03 18:01 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-02-25 10:46 . 2008-01-10 08:55 100432 ----a-w- c:\users\Marco\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 08:16 . 2009-10-03 09:53 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39 . 2010-03-31 11:44 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 11:44 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33 . 2010-03-31 11:44 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55 . 2010-03-31 11:44 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:39 . 2010-03-12 00:17 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:37 . 2010-03-12 00:17 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 21:18 . 2010-03-12 00:17 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-02-12 10:48 . 2010-03-12 00:20 293376 ----a-w- c:\windows\system32\browserchoice.exe
2007-08-29 09:07 . 2007-03-06 10:32 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-01-18 289584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 4435968]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\users\Marco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FreePOPs.lnk - c:\program files\FreePOPs\freepopsd.exe [2007-11-17 49152]
Widget vodafone.lnk - c:\program files\Widget vodafone.it\Widget vodafone.it.exe [2010-4-18 95232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3461380361-3916217333-806040310-1003]
"EnableNotificationsRef"=dword:00000001
R3 digitran;Microsoft Input Tablet;c:\windows\system32\drivers\digitran.sys [2007-01-10 23528]
R3 gAGP440p;gAGP440p;c:\users\Marco\AppData\Local\Temp\gAGP440p.sys [x]
R4 smscir;SMSCIR Infrared Receiver;c:\windows\system32\drivers\smscir.sys [2007-01-09 62752]
R4 vhiddigi;Microsoft HID Digitizer Driver;c:\windows\system32\drivers\vhiddigi.sys [2007-01-10 23936]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-01-01 717296]
.
Contenuto della cartella 'Scheduled Tasks'
2010-05-01 c:\windows\Tasks\User_Feed_Synchronization-{D7B70733-77C3-4D66-8CEB-0CB058008DFB}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.facebook.it/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-01 19:57
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys xfilt.sys acpi.sys hal.dll >>UNKNOWN [0x8470B1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x863bc322
\Driver\ACPI -> acpi.sys @ 0x807c1d4c
\Driver\atapi -> 0x8470b1f8
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.032"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ani"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.bay"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Bitmap"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.bw"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.cs1"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.cur"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.dcx"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.dib"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.djv"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.djvu"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.emf"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.eps"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.erf"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.fff"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.fpx"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Gif"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.hdr"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.icl"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.icn"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ico"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.iff"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ilbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.int"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.inta"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.iw4"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.j2c"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.j2k"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jfif"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jif"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jp2"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jpc"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Jpeg"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Jpeg"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jpk"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jpx"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.lbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.mef"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.mos"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pcd"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pct"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pcx"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pgm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pic"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pict"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pix"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Png"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ppm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.psd"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.psp"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ras"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.rgb"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.rgba"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.rle"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.rsb"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.sgi"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.tga"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.thm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Tiff"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Tiff"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ttc"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ttf"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.wbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.wbmp"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.wmf"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.xbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.xif"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.xpm"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\rundll32.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Ora fine scansione: 2010-05-01 20:08:17 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-05-01 18:08
ComboFix2.txt 2009-10-27 09:31
ComboFix3.txt 2009-10-25 16:38
ComboFix4.txt 2009-01-11 19:13
Pre-Run: 152.054.476.800 byte disponibili
Post-Run: 152.599.908.352 byte disponibili
- - End Of File - - 52D6161586D5CA4C3DB5A239E36818A0