Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

system32\samsrv.dll Opzioni
agatone
Inviato: Saturday, April 27, 2013 12:19:45 AM
Rank: AiutAmico

Iscritto dal : 1/5/2011
Posts: 112
Salve a tutti.
Volevo avere un vostro parere.
ho notato che la scansione di Combofix continua a rilevare questo file come infetto:

La copia infetta di c:\windows\system32\samsrv.dll è stata trovata e disinfettata
ipristinata copia da - c:\windows\ServicePackFiles\i386\samsrv.dll

Non riesco a capire da cosa dipende e se e' legato a qualche installazione che a questo punto andrei ad eliminare
Qualcuno puo' darmi qualche indicazione?
Sponsor
Inviato: Saturday, April 27, 2013 12:19:45 AM

 
r16
Inviato: Saturday, April 27, 2013 2:29:55 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
agatone ha scritto:

ho notato che la scansione di Combofix continua a rilevare questo file come infetto:

La copia infetta di c:\windows\system32\samsrv.dll è stata trovata e disinfettata
ipristinata copia da - c:\windows\ServicePackFiles\i386\samsrv.dll

Intendi dire che lo rileva ad ogni scansione, oppure lo ha rilevato una sola volta?
Inoltre per dare un parere decente, è indispensabile vedere tutto il log di Combofix.
agatone
Inviato: Saturday, April 27, 2013 3:10:49 PM
Rank: AiutAmico

Iscritto dal : 1/5/2011
Posts: 112
Si ,lo rileva ad ogni scansione.
Ti allego qui il log Combofix

ComboFix 13-04-26.01 - paolo 26/04/2013 23.42.32.22.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3071.2220 [GMT 2:00]
Eseguito da: c:\documents and settings\paolo\Desktop\combofix13-03-27.01.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: Outpost Firewall Pro *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\TEMP
.
La copia infetta di c:\windows\system32\samsrv.dll è stata trovata e disinfettata
ipristinata copia da - c:\windows\ServicePackFiles\i386\samsrv.dll
.
.
((((((((((((((((((((((((( Files Creati Da 2013-03-26 al 2013-04-26 )))))))))))))))))))))))))))))))))))
.
.
2013-04-26 10:35 . 2013-04-26 10:35 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\SolidDocuments
2013-04-26 07:16 . 2013-04-10 03:08 6906960 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{7C2965AC-976E-4FC2-A61B-2E1A753ED808}\mpengine.dll
2013-04-26 06:51 . 2013-04-10 03:08 6906960 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-25 21:22 . 2013-04-25 21:22 -------- d-----w- c:\programmi\7-Zip
2013-04-24 05:59 . 2013-04-24 06:19 -------- d-----w- C:\combofix13-03-27.01
2013-04-21 20:23 . 2013-04-21 20:23 -------- d-----w- c:\documents and settings\paolo\Impostazioni locali\Dati applicazioni\Sun
2013-04-21 20:20 . 2013-04-21 20:20 -------- d-----w- c:\programmi\File comuni\Java
2013-04-21 20:19 . 2013-04-21 20:19 866720 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-04-21 20:19 . 2013-04-21 20:19 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-04-21 08:59 . 2013-04-21 08:59 -------- d-----w- c:\programmi\Poedit
2013-04-20 14:33 . 2013-04-20 14:33 -------- d-----w- c:\windows\Downloaded Installations
2013-04-20 10:56 . 2013-04-20 10:56 -------- d-sh--w- c:\documents and settings\paolo\UserData
2013-04-19 20:53 . 2013-04-19 20:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Sophos
2013-04-19 20:53 . 2013-04-19 20:53 73728 ----a-r- c:\documents and settings\paolo\Dati applicazioni\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-04-19 20:53 . 2013-04-19 20:53 73728 ----a-r- c:\documents and settings\paolo\Dati applicazioni\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-04-19 20:53 . 2013-04-19 20:53 73728 ----a-r- c:\documents and settings\paolo\Dati applicazioni\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2013-04-19 20:53 . 2013-04-19 20:53 -------- d-----w- c:\programmi\Sophos
2013-04-19 13:29 . 2013-04-19 20:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Wincert
2013-04-19 13:28 . 2013-04-19 13:28 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\KingTranslate
2013-04-19 13:27 . 2013-04-19 13:29 -------- d-----w- c:\programmi\KingTranslate
2013-04-19 13:02 . 2013-04-19 13:02 -------- d-----w- c:\programmi\GKFX FX - CFDs
2013-04-19 12:23 . 2013-04-19 12:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MetaQuotes
2013-04-19 07:33 . 2013-04-19 07:33 -------- d-----w- c:\programmi\OfflinePennyPuncher
2013-04-19 06:26 . 2013-04-19 06:26 -------- d-----w- c:\programmi\iPod
2013-04-19 06:26 . 2013-04-19 06:26 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-04-17 21:51 . 2013-04-17 23:26 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\com.webdimensions.viralvideocuratorpro
2013-04-17 21:50 . 2013-04-17 23:26 -------- d-----w- c:\programmi\Web Dimensions
2013-04-15 23:58 . 2013-04-22 00:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\InstallMate
2013-04-15 15:40 . 2013-04-15 15:44 -------- d-----w- c:\programmi\TIAB
2013-04-14 21:21 . 2013-04-14 21:21 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\Pixarra
2013-04-14 21:06 . 2013-04-14 21:06 -------- d-----w- c:\programmi\Pixarra
2013-04-14 20:36 . 2013-04-14 20:36 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\Ambient Design
2013-04-12 07:59 . 2013-04-12 07:59 -------- d-----w- c:\programmi\Microsoft Agent
2013-04-11 20:07 . 2013-04-11 20:07 -------- d-----w- c:\programmi\Innovative Solutions
2013-04-11 19:49 . 2013-04-11 19:50 -------- d-----w- c:\documents and settings\paolo\Impostazioni locali\Dati applicazioni\SoftwareUpdater
2013-04-11 14:37 . 2013-04-11 14:37 159744 ----a-w- c:\programmi\Internet Explorer\Plugin\npqtplugin7.dll
2013-04-11 14:37 . 2013-04-11 14:37 159744 ----a-w- c:\programmi\Internet Explorer\Plugin\npqtplugin6.dll
2013-04-11 14:37 . 2013-04-11 14:37 159744 ----a-w- c:\programmi\Internet Explorer\Plugin\npqtplugin5.dll
2013-04-11 14:37 . 2013-04-11 14:37 159744 ----a-w- c:\programmi\Internet Explorer\Plugin\npqtplugin4.dll
2013-04-11 14:37 . 2013-04-11 14:37 159744 ----a-w- c:\programmi\Internet Explorer\Plugin\npqtplugin3.dll
2013-04-11 14:37 . 2013-04-11 14:37 159744 ----a-w- c:\programmi\Internet Explorer\Plugin\npqtplugin2.dll
2013-04-11 14:37 . 2013-04-11 14:36 159744 ----a-w- c:\programmi\Internet Explorer\Plugin\npqtplugin.dll
2013-04-11 12:34 . 2011-08-22 15:07 354416 ----a-w- c:\windows\system32\vmnetdhcp.exe
2013-04-11 12:34 . 2011-08-22 15:06 432752 ----a-w- c:\windows\system32\vmnat.exe
2013-04-11 12:34 . 2011-08-22 15:06 25712 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2013-04-11 12:34 . 2011-08-22 15:07 783472 ----a-w- c:\windows\system32\vnetlib.dll
2013-04-11 12:33 . 2013-04-11 12:33 -------- d-----w- c:\programmi\VMware
2013-04-11 12:32 . 2013-04-11 12:33 -------- d-----w- c:\programmi\File comuni\VMware
2013-04-10 16:17 . 2013-04-10 16:38 -------- d-----w- c:\programmi\Acapela Group
2013-04-09 15:49 . 2013-04-09 15:49 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\ElevatedDiagnostics
2013-04-09 15:17 . 2013-04-09 15:21 -------- d-----w- c:\programmi\NextUp Talker
2013-04-09 15:07 . 2013-04-09 15:07 -------- d-----w- c:\programmi\Microsoft Speech SDK 5.1
2013-04-09 11:41 . 2013-04-09 11:41 -------- d-----w- c:\programmi\placemat
2013-04-08 18:30 . 2013-04-08 18:34 -------- d-----w- c:\programmi\Dream Aquarium
2013-04-08 08:40 . 2013-04-08 08:40 -------- d-----w- c:\documents and settings\All Users\Adobe
2013-04-06 09:03 . 2013-04-26 06:59 -------- d-----w- c:\programmi\FBLeadster
2013-04-06 08:40 . 2013-04-06 08:42 -------- d-----w- c:\programmi\CCleaner
2013-04-04 10:40 . 2013-04-04 10:40 -------- d-sh--w- c:\documents and settings\paolo\IECompatCache
2013-04-04 10:29 . 2013-04-04 10:29 -------- d-----w- c:\programmi\Nuance
2013-04-03 23:50 . 2013-04-03 23:50 -------- d-----w- c:\programmi\BabylonToolbar
2013-04-03 23:29 . 2013-04-04 10:40 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\Nuance
2013-04-03 23:12 . 2013-04-03 23:12 -------- d-----w- c:\programmi\File comuni\IVA
2013-04-03 23:11 . 2013-04-04 10:32 -------- d-----w- c:\programmi\File comuni\Nuance
2013-04-03 21:03 . 2013-04-03 21:03 -------- d--h--w- c:\documents and settings\All Users\Dati applicazioni\Common Files
2013-04-03 16:13 . 2013-04-03 16:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Macrovision
2013-04-03 15:00 . 2013-04-03 16:49 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2013-04-03 13:45 . 2013-04-15 01:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ftw
2013-04-03 13:41 . 2013-04-15 01:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\copypart
2013-04-03 12:48 . 2013-04-03 12:48 -------- d-----w- C:\archive_db
2013-04-03 12:31 . 2013-04-15 01:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\complexbackup
2013-04-03 11:29 . 2012-12-05 08:50 785800 ----a-w- c:\windows\system32\drivers\SandBox.sys
2013-04-03 11:29 . 2012-12-03 10:49 285280 ----a-w- c:\windows\system32\drivers\afwcore.sys
2013-04-03 11:29 . 2012-09-03 18:20 33888 ----a-w- c:\windows\system32\drivers\afw.sys
2013-04-03 11:29 . 2013-04-03 11:29 -------- d-----w- c:\programmi\Agnitum
2013-04-02 14:13 . 2013-04-02 14:13 -------- d-----w- c:\programmi\Cepstral
2013-03-31 19:48 . 2013-03-31 19:51 -------- d-----w- c:\programmi\Visual Slideshow
2013-03-31 18:24 . 2013-03-31 18:24 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\facebookpostMain
2013-03-31 18:24 . 2013-03-31 18:24 -------- d-----w- c:\programmi\FB Lead System
2013-03-30 16:09 . 2013-03-30 16:09 -------- d-----w- c:\documents and settings\paolo\Impostazioni locali\Dati applicazioni\Configure
2013-03-30 16:09 . 2013-04-05 12:09 -------- d-----w- c:\documents and settings\paolo\Impostazioni locali\Dati applicazioni\Maker3D
2013-03-28 11:17 . 2013-04-09 11:40 -------- d-----w- c:\documents and settings\paolo\Dati applicazioni\placemat
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-21 20:19 . 2011-07-01 13:13 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-04-21 20:19 . 2010-04-27 19:10 788896 -c--a-w- c:\windows\system32\deployJava1.dll
2013-04-20 11:41 . 2012-09-08 12:22 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-20 11:41 . 2012-09-08 12:22 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-04-04 12:50 . 2010-10-08 07:37 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-04-02 10:33 . 2011-05-06 00:29 237088 ------w- c:\windows\system32\MpSigStub.exe
2013-03-15 05:47 . 2013-03-26 09:08 892704 ----a-w- c:\windows\system32\nvdispgenco3231422.dll
2013-03-15 05:47 . 2013-03-26 09:08 6074368 ----a-w- c:\windows\system32\nvopencl.dll
2013-03-15 05:47 . 2013-03-26 09:08 1012512 ----a-w- c:\windows\system32\nvdispco3231422.dll
2013-03-15 05:47 . 2010-01-12 10:03 2733344 ----a-w- c:\windows\system32\nvcuvid.dll
2013-03-15 05:47 . 2010-01-12 10:03 1995552 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-03-15 05:47 . 2010-01-12 10:03 17551360 ----a-w- c:\windows\system32\nvcompiler.dll
2013-03-15 05:47 . 2008-10-07 05:33 7745536 ----a-w- c:\windows\system32\nvcuda.dll
2013-03-15 05:47 . 2008-10-07 05:33 4079104 ----a-w- c:\windows\system32\nv4_disp.dll
2013-03-15 05:47 . 2008-10-07 05:33 2490368 ----a-w- c:\windows\system32\nvapi.dll
2013-03-15 05:47 . 2008-10-07 05:33 19689472 ----a-w- c:\windows\system32\nvoglnt.dll
2013-03-15 05:47 . 2008-10-07 05:33 10713024 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2013-03-15 02:59 . 2010-04-03 18:23 229376 ----a-w- c:\windows\system32\nvrszhc.dll
2013-03-15 02:59 . 2010-04-03 18:23 126976 ----a-w- c:\windows\system32\nvrszht.dll
2013-03-15 02:59 . 2010-04-03 18:22 258048 ----a-w- c:\windows\system32\nvrstr.dll
2013-03-15 02:59 . 2010-04-03 18:22 253952 ----a-w- c:\windows\system32\nvrsth.dll
2013-03-15 02:59 . 2010-04-03 18:22 274432 ----a-w- c:\windows\system32\nvrspt.dll
2013-03-15 02:59 . 2010-04-03 18:22 270336 ----a-w- c:\windows\system32\nvrsru.dll
2013-03-15 02:59 . 2010-04-03 18:22 270336 ----a-w- c:\windows\system32\nvrsptb.dll
2013-03-15 02:59 . 2010-04-03 18:22 258048 ----a-w- c:\windows\system32\nvrssl.dll
2013-03-15 02:59 . 2010-04-03 18:22 258048 ----a-w- c:\windows\system32\nvrssk.dll
2013-03-15 02:59 . 2010-04-03 18:22 253952 ----a-w- c:\windows\system32\nvrssv.dll
2013-03-15 02:59 . 2010-04-03 18:22 274432 ----a-w- c:\windows\system32\nvrsnl.dll
2013-03-15 02:59 . 2010-04-03 18:22 258048 ----a-w- c:\windows\system32\nvrspl.dll
2013-03-15 02:59 . 2010-04-03 18:22 253952 ----a-w- c:\windows\system32\nvrsno.dll
2013-03-15 02:59 . 2010-04-03 18:22 335872 ----a-w- c:\windows\system32\nvrshe.dll
2013-03-15 02:59 . 2010-04-03 18:22 282624 ----a-w- c:\windows\system32\nvrsit.dll
2013-03-15 02:59 . 2010-04-03 18:22 274432 ----a-w- c:\windows\system32\nvrsja.dll
2013-03-15 02:59 . 2010-04-03 18:22 266240 ----a-w- c:\windows\system32\nvrsko.dll
2013-03-15 02:59 . 2010-04-03 18:22 262144 ----a-w- c:\windows\system32\nvrshu.dll
2013-03-15 02:59 . 2010-04-03 18:22 286720 ----a-w- c:\windows\system32\nvrsfr.dll
2013-03-15 02:59 . 2010-04-03 18:22 282624 ----a-w- c:\windows\system32\nvrses.dll
2013-03-15 02:59 . 2010-04-03 18:22 282624 ----a-w- c:\windows\system32\nvrsel.dll
2013-03-15 02:59 . 2010-04-03 18:22 278528 ----a-w- c:\windows\system32\nvrsde.dll
2013-03-15 02:59 . 2010-04-03 18:22 274432 ----a-w- c:\windows\system32\nvrsesm.dll
2013-03-15 02:59 . 2010-04-03 18:22 249856 ----a-w- c:\windows\system32\nvrsfi.dll
2013-03-15 02:59 . 2010-04-03 18:22 249856 ----a-w- c:\windows\system32\nvrseng.dll
2013-03-15 02:59 . 2010-04-03 18:22 253952 ----a-w- c:\windows\system32\nvrsda.dll
2013-03-15 02:59 . 2010-04-03 18:22 335872 ----a-w- c:\windows\system32\nvrsar.dll
2013-03-15 02:59 . 2010-04-03 18:22 249856 ----a-w- c:\windows\system32\nvrscs.dll
2013-03-15 02:57 . 2010-04-03 18:22 54272 ----a-w- c:\windows\system32\nvwddi.dll
2013-03-15 02:57 . 2010-04-03 18:23 223008 ----a-w- c:\windows\system32\nvmctray.dll
2013-03-15 02:57 . 2010-04-03 18:23 156960 ----a-w- c:\windows\system32\nvsvc32.exe
2013-03-15 02:57 . 2010-04-03 18:23 15668512 ----a-w- c:\windows\system32\nvcpl.dll
2013-03-15 02:57 . 2010-04-03 18:23 144160 ----a-w- c:\windows\system32\nvcolor.exe
2013-03-08 08:36 . 2004-08-19 12:00 293888 ----a-w- c:\windows\system32\winsrv.dll
2013-03-07 15:56 . 2004-08-19 15:34 2032128 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-07 15:56 . 2004-08-19 12:00 2153472 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-02 01:57 . 2004-08-19 12:00 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-03-02 01:55 . 2004-08-19 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2013-03-02 01:55 . 2004-08-19 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-03-02 01:55 . 2004-08-19 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:08 . 2004-08-19 12:00 385024 ----a-w- c:\windows\system32\html.iec
2013-02-27 07:56 . 2010-04-21 06:17 2067456 ----a-w- c:\windows\system32\mstscax.dll
2013-02-12 00:32 . 2008-04-13 18:56 12928 ------w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2004-08-19 12:00 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-08 16:07 . 2010-09-07 08:57 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-01-15 08:36 . 2011-07-25 14:51 75040 ----a-w- c:\programmi\File comuni\SpeechUninstall.exe
2001-07-03 17:47 . 2010-04-26 10:08 69632 -c--a-w- c:\programmi\sylia.dll
2001-03-01 09:51 . 2010-04-26 10:08 36864 -c--a-w- c:\programmi\AuxSetup.exe
2000-09-24 04:48 . 2010-04-26 10:08 7752 -c--a-w- c:\programmi\vdsvrlnk.dll
2000-09-24 04:48 . 2010-04-26 10:08 10824 -c--a-w- c:\programmi\vdremote.dll
2000-04-16 20:22 . 2010-04-26 10:08 45056 -c--a-w- c:\programmi\vdicmdrv.dll
2013-04-20 22:04 . 2013-04-20 22:03 263064 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\documents and settings\paolo\Dati applicazioni\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\documents and settings\paolo\Dati applicazioni\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\documents and settings\paolo\Dati applicazioni\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\documents and settings\paolo\Dati applicazioni\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkinClock"="c:\programmi\Atomic Alarm Clock\AtomicAlarmClock.exe" [2007-09-10 563007]
"WorkShelf"="c:\programmi\Winstep\WorkShelf.exe" [2012-03-28 19256448]
"BitTorrent"="c:\programmi\BitTorrent\bittorrent.exe" [2013-04-13 882520]
"CursorFX"="c:\programmi\Stardock\CursorFX\CursorFX.exe" [2010-03-23 417280]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2011-12-05 20065384]
"itype"="c:\programmi\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]
"Babylon Client"="c:\programmi\Babylon\Babylon-Pro\Babylon.exe" [2013-02-07 3590224]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2013-03-15 15668512]
"NvMediaCenter"="NvMCTray.dll" [2013-03-15 223008]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2012-12-14 3452344]
"BCSSync"="c:\programmi\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AdobeAAMUpdater-1.0"="c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904]
"SwitchBoard"="c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"vmware-tray"="c:\programmi\VMware\VMware Workstation\vmware-tray.exe" [2011-08-22 103536]
"TkBellExe"="c:\programmi\real\realplayer\update\realsched.exe" [2012-07-04 296096]
"APSDaemon"="c:\programmi\File comuni\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"MSC"="c:\programmi\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Rocketdock.lnk - c:\programmi\RocketDock\RocketDock.exe [2011-7-7 495616]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2008-03-28 08:23 49152 ----a-w- c:\progra~1\FILECO~1\Stardock\MCPStub.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2010-04-01 21:40 172336 ----a-w- c:\progra~1\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-11-11 12:08 205336 ----a-w- c:\programmi\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-04-27 19:11 39408 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2012-07-04 21:01 296096 ----a-w- c:\programmi\Real\RealPlayer\Update\realsched.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NextSTART"=c:\programmi\Winstep\nextstart.exe autostart
"OfficeSyncProcess"="c:\programmi\Microsoft Office\Office14\MSOSYNC.EXE"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
"TkBellExe"="c:\programmi\Real\RealPlayer\update\realsched.exe" -osboot
"NvMediaCenter"=RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
"nwiz"=c:\programmi\NVIDIA Corporation\nView\nwiz.exe /installquiet
"AdobeCS4ServiceManager"="c:\programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"BCSSync"="c:\programmi\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Logitech\\Logitech Vid\\Vid.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
"c:\\Programmi\\File comuni\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Documents and Settings\\paolo\\Impostazioni locali\\Dati applicazioni\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Programmi\\File comuni\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\paolo\\Dati applicazioni\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Programmi\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Programmi\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"c:\\Programmi\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Programmi\\TeamViewer\\Version5\\TeamViewer_Service.exe"=
"c:\\Programmi\\VMware\\VMware Workstation\\vmware-authd.exe"=
"c:\\Programmi\\VMware\\VMware Workstation\\vmware-hostd.exe"=
"c:\\Programmi\\File comuni\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Video Streaming Server TCP/IP Port
"1935:TCP"= 1935:TCP:BroadCam Video Streaming Server Flash Video Server
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Dragon Smart Phone Server
.
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [01/07/2011 14.21.48 16024]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/05/2010 12.48.10 691696]
R0 vmci;VMware VMCI Bus Driver;c:\windows\system32\drivers\vmci.sys [08/08/2011 14.58.56 98928]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [21/04/2010 9.07.13 13696]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [03/04/2013 13.29.59 785800]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [07/09/2010 10.57.56 101720]
R1 Uim_Vim;UIM Virtual Image Plugin;c:\windows\system32\drivers\Uim_Vim.sys [22/11/2012 23.15.04 283600]
R2 Cepstral License Server;Cepstral License Server;c:\programmi\Cepstral\bin\CepstralLicSrv.exe [15/03/2007 13.54.48 57344]
R2 DragonSvc;Dragon Service;c:\programmi\File comuni\Nuance\dgnsvc.exe [11/02/2013 18.48.56 311184]
R2 MBAMScheduler;MBAMScheduler;c:\programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe [20/02/2013 19.40.47 418376]
R2 MBAMService;MBAMService;c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe [08/10/2010 9.37.43 701512]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\programmi\Macrium\Reflect\ReflectService.exe [01/07/2011 14.21.53 220824]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\programmi\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [29/05/2012 20.46.46 1528672]
R2 VMUSBArbService;VMware USB Arbitration Service;c:\programmi\File comuni\VMware\USB\vmware-usbarbitrator.exe [21/08/2011 23.11.22 665200]
R2 VMwareHostd;VMware Workstation Server;c:\programmi\VMware\VMware Workstation\vmware-hostd.exe [22/08/2011 16.34.52 11837440]
R2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);c:\windows\system32\drivers\vstor2-mntapi10-shared.sys [08/07/2011 15.32.56 22768]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [07/05/2011 11.08.46 17984]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [03/04/2013 13.29.47 33888]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [03/04/2013 13.29.47 285280]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [01/07/2011 13.03.47 45288]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [08/10/2010 9.37.37 22856]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\programmi\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [20/10/2011 11.48.16 10064]
R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM108.sys [01/07/2011 13.05.06 1513984]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [03/04/2013 13.29.35 2312176]
S2 KMService;KMService;c:\windows\system32\srvany.exe [10/01/2011 2.18.42 8192]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [21/04/2010 9.09.42 1691480]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver; [x]
S3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [04/02/2012 11.40.44 24064]
S3 pgusbwdm;usb-audio.de driver (commercial 2.8.45);c:\windows\system32\drivers\pgusbwdm.sys [02/07/2011 4.45.37 403008]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [01/07/2011 14.21.48 45208]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [08/02/2013 16.17.17 27064]
S3 SwitchBoard;Adobe SwitchBoard;c:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13.37.14 517096]
S4 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\programmi\File comuni\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15/08/2008 6.46.20 284016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan sysagent
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenuto della cartella 'Scheduled Tasks'
.
2013-04-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-08 11:41]
.
2013-04-22 c:\windows\Tasks\AdobeAAMUpdater-1.0-PAOLO-PC-paolo.job
- c:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2012-09-20 05:27]
.
2013-04-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2013-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-04-24 02:56]
.
2013-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-04-24 02:56]
.
2013-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1801674531-725345543-1003Core.job
- c:\documents and settings\paolo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2011-07-30 20:12]
.
2013-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1801674531-725345543-1003UA.job
- c:\documents and settings\paolo\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2011-07-30 20:12]
.
2012-04-27 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
- c:\programmi\Microsoft IntelliType Pro\itype.exe [2011-08-10 14:39]
.
2013-04-26 c:\windows\Tasks\MpIdleTask.job
- c:\programmi\Microsoft Security Client\MpCmdRun.exe [2013-01-27 10:11]
.
2013-04-26 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\programmi\File comuni\ParetoLogic\UUS3\UUS3.dll [2011-11-25 02:25]
.
2013-04-22 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\programmi\File comuni\ParetoLogic\UUS3\Pareto_Update3.exe [2011-11-25 02:25]
.
2013-04-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1801674531-725345543-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2012-06-21 10:00]
.
2013-04-22 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1801674531-725345543-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2012-06-21 10:00]
.
2013-04-15 c:\windows\Tasks\RegCure Pro.job
- c:\programmi\ParetoLogic\RegCure Pro\RegCurePro.exe [2011-12-21 21:18]
.
2013-04-26 c:\windows\Tasks\User_Feed_Synchronization-{04E0ABEC-BE27-4E72-B7E0-9A0EA032BD5F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = <local>;*.local
IE: Aggiungi a PDF esistente - c:\programmi\File comuni\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Aggiungi destinazione link a PDF esistente - c:\programmi\File comuni\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti destinazione link in Adobe PDF - c:\programmi\File comuni\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\File comuni\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&sporta in Microsoft Excel - c:\progra~1\Microsoft Office\Office14\EXCEL.EXE/3000
IE: Google Sidewiki...
IE: I&nvia a OneNote - c:\progra~1\Microsoft Office\Office14\ONBttnIE.dll/105
IE: Translate this web page with Babylon - c:\programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
LSP: %SystemRoot%\system32\vsocklib.dll
TCP: DhcpNameServer = 62.101.93.101 83.103.25.250
FF - ProfilePath - c:\documents and settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://websearch.helpmefindyour.info/?pid=703&r=2013/04/18&hid=377599103&lg=EN&cc=IT&l=1&q=
FF - prefs.js: browser.startup.homepage - hxxp://search.findeer.com
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-04-04 01:50; ocr@babylon.com; c:\programmi\Mozilla Firefox\extensions\ocr@babylon.com
FF - ExtSQL: 2013-04-19 15:28; wcapturex@deskperience.com; c:\programmi\KingTranslate\WCaptureMoz
FF - ExtSQL: 2013-04-20 12:24; web2pdfextension@web2pdf.adobedotcom; c:\programmi\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF - ExtSQL: !HIDDEN! 2013-02-08 17:40; ocr@babylon.com; c:\programmi\Babylon\Babylon-Pro\Utils\ocr@babylon.com
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=18b851bd0000000000000030674bda25&q=
FF - user.js: extensions.BabylonToolbar.id - 18b851bd0000000000000030674bda25
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15798
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.11.10
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.11.10
FF - user.js: extensions.BabylonToolbar.vrsnTs - 1.8.11.101:50
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - na
FF - user.js: extensions.BabylonToolbar.dfltLng - it
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.ffxUnstlRst - true
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=14795&tt=250111_def
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - def
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar.rvrt - false
FF - user.js: extensions.BabylonToolbar.newTab - false
.
.
------- Associazioni dei file -------
.
.reg=regfile.reg
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
BHO-{1d03a978-ac0c-4004-b9fd-9cf361c7bd3f} - REG_SZ
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-26 23:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-823518204-1801674531-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
@DACL=(02 0010)
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@DACL=(02 0010)
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:23,2c,cd,bc,3c,0d,26,9b,61,6f,1c,da,99,95,b0,c8,24,b6,89,8b,a0,
a8,6a,cd,09,99,84,f3,b0,3d,2c,54,44,2c,32,40,de,10,7c,d5,5a,ce,48,1b,03,d4,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
.
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:23,2c,cd,bc,3c,0d,26,9b,61,6f,1c,da,99,95,b0,c8,24,b6,89,8b,a0,
a8,6a,cd,09,99,84,f3,b0,3d,2c,54,44,2c,32,40,de,10,7c,d5,5a,ce,48,1b,03,d4,\
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(1988)
c:\progra~1\FILECO~1\Stardock\mcpstub.dll
c:\progra~1\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
.
- - - - - - - > 'lsass.exe'(488)
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'explorer.exe'(2464)
c:\windows\system32\WININET.dll
c:\programmi\RocketDock\RocketDock.dll
c:\programmi\Babylon\Babylon-Pro\Captlib.dll
c:\documents and settings\paolo\Dati applicazioni\Dropbox\bin\DropboxExt.17.dll
c:\progra~1\FILECO~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~3\Office14\1040\GrooveIntlResource.dll
c:\programmi\Stardock\Object Desktop\IconPackager\shellext.dll
c:\programmi\Atomic Alarm Clock\Clock.dll
c:\progra~1\FILECO~1\Stardock\mcpcore.dll
c:\progra~1\Stardock\Object Desktop\WindowBlinds\tray.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Stardock\Object Desktop\IconPackager\iprepair.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Microsoft Security Client\MsMpEng.exe
c:\progra~1\FILECO~1\Stardock\SDMCP.exe
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre7\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
c:\windows\RTHDCPL.EXE
c:\programmi\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\system32\RunDLL32.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\vmnat.exe
c:\programmi\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
c:\windows\system32\vmnetdhcp.exe
c:\programmi\VMware\VMware Workstation\vmware-authd.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2013-04-27 00:00:40 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2013-04-26 22:00
ComboFix2.txt 2013-04-26 06:44
ComboFix3.txt 2013-04-26 06:30
ComboFix4.txt 2013-04-25 05:41
ComboFix5.txt 2013-04-26 21:41
.
Pre-Run: 129.299.296.256 byte disponibili
Post-Run: 129.312.686.080 byte disponibili
.
- - End Of File - - 91E23D3955F763EA3A410363E72B0F3D
r16
Inviato: Saturday, April 27, 2013 3:30:22 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Rinomina Combofix in uninstall e avvialo.
Aspetta la sua disistallazione.
Al riavvio, fai una pulizia con CCleaner (registro compreso.)

Scarica Adwcleaner sul desktop:
http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner
Clicca sul pulsante "Elimina".
Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e uscirà il log con le eliminazioni.
Postalo qui.

Poi:
Scarica OTL, e salvalo sul desktop:

http://oldtimer.geekstogo.com/OTL.exe

Clicca sull'icona di OTL che trovi sul tuo desktop .

Metti la spunta su SCAN ALL USERS.

Sotto output, metti la spunta : minimal output

Clicca sulla freccettina di File Age e seleziona 60 Days

Metti la spunta a LOP Check e Purity Check.

Clicca su RUN SCAN

Lascia fare la scansione senza interferire.

Al termine della scansione trovi 2 log sul desktop. OTL.txt ed Extras.txt, salvali e caricali su Wikisend, per postarli sul forum.

Per postare i log:
Collegati ad internet e vai alla pagina WikiSend: http://www.wikisend.com/
Clicca sul bottone "Sfoglia"
Seleziona il file appena salvato
Clicca su Upload file
Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati:
Download Link / Forum Link
Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum.


agatone
Inviato: Saturday, April 27, 2013 8:54:10 PM
Rank: AiutAmico

Iscritto dal : 1/5/2011
Posts: 112
Ecco il log AdwsCleaner : adesso procedo con gli altri passaggi.

# AdwCleaner v2.202 - Logfile creato il 27/04/2013 alle 20:40:51
# Aggiornamento 23/04/2013 by Xplode
# Sistema Operativo : Microsoft Windows XP Service Pack 3 (32 bits)
# Utente : paolo - PAOLO-PC
# Modalità Avvio : Modalità Normale
# Eseguito da : C:\Documents and Settings\paolo\Desktop\adwcleaner.exe
# Opzioni [Elimina]


***** [Servizi] *****


***** [File / Cartelle] *****

Cartella Eliminato : C:\Documents and Settings\All Users\Dati applicazioni\Babylon
Cartella Eliminato : C:\Documents and Settings\All Users\Dati applicazioni\boost_interprocess
Cartella Eliminato : C:\Documents and Settings\All Users\Dati applicazioni\InstallMate
Cartella Eliminato : C:\Documents and Settings\All Users\Dati applicazioni\Tarma Installer
Cartella Eliminato : C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\AskToolbar
Cartella Eliminato : C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Conduit
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\Babylon
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\Conduit
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\extensions\staged
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\jetpack
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\myfreezetoolbar
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\OpenCandy
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\SiteRanker
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\widestream
Cartella Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\yourfiledownloader
Cartella Eliminato : C:\Documents and Settings\paolo\Documenti\widestream
Cartella Eliminato : C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\Babylon
Cartella Eliminato : C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\Conduit
Cartella Eliminato : C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\OpenCandy
Cartella Eliminato : C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\PackageAware
Cartella Eliminato : C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\PutLockerDownloader
Cartella Eliminato : C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\widestream6 Air
Cartella Eliminato : C:\Programmi\BabylonToolbar
Cartella Eliminato : C:\Programmi\Mozilla Firefox\Extensions\ocr@babylon.com
Cartella Eliminato : C:\Programmi\PriceGong
Cartella Eliminato : C:\WINDOWS\Installer\{2C8574B5-6935-4FCE-860E-F4E8602378FF}
Cartella Eliminato : C:\WINDOWS\Installer\{835525BE-63BD-4EC4-9425-00CEAD4849C2}
Eliminato al riavvio : C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Eliminato al riavvio : C:\Programmi\Babylon
File Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\searchplugins\Conduit.xml
File Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\searchplugins\Search_Results.xml
File Eliminato : C:\Documents and Settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\searchplugins\WebSearch.xml
File Eliminato : C:\Programmi\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Eliminato : C:\Programmi\Mozilla Firefox\searchplugins\babylon.xml
File Eliminato : C:\Programmi\Mozilla Firefox\searchplugins\crawlersrch.xml

***** [Registro] *****

Chiave Eliminata : HKCU\Software\AppDataLow\SProtector
Chiave Eliminata : HKCU\Software\Babylon
Chiave Eliminata : HKCU\Software\BabylonToolbar
Chiave Eliminata : HKCU\Software\Conduit
Chiave Eliminata : HKCU\Software\DataMngr_Toolbar
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Translate this web page with Babylon
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Translate with Babylon
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F1AF26F8-1828-4279-ABCE-074EF3235BD7}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F1AF26F8-1828-4279-ABCE-074EF3235BD7}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Chiave Eliminata : HKCU\Software\Softonic
Chiave Eliminata : HKCU\Software\Spointer
Chiave Eliminata : HKCU\Software\WideStream
Chiave Eliminata : HKLM\Software\Babylon
Chiave Eliminata : HKLM\Software\BabylonToolbar
Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{B16632F1-24E0-4D99-A68D-70BFB6447C48}
Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\BabylonIEPI.DLL
Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Chiave Eliminata : HKLM\SOFTWARE\Classes\BabyDict
Chiave Eliminata : HKLM\SOFTWARE\Classes\BabyGloss
Chiave Eliminata : HKLM\SOFTWARE\Classes\BabylonIEPI.BabylonIEBho
Chiave Eliminata : HKLM\SOFTWARE\Classes\BabylonIEPI.BabylonIEBho.1
Chiave Eliminata : HKLM\SOFTWARE\Classes\BabylonOfficeAddin.OfficeAddin
Chiave Eliminata : HKLM\SOFTWARE\Classes\BabylonOfficeAddin.OfficeAddin.1
Chiave Eliminata : HKLM\SOFTWARE\Classes\BabyOptFile
Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{6AC0BB10-C922-45E2-857D-2A368FE749E5}
Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0BF91075-F457-4A8B-99EF-140B52D2F22A}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{37425600-CB21-49A0-8659-476FBAB0F8E8}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{5C9A230D-70A5-11D5-AFB0-0050DAC67890}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{5F339F0B-716F-408F-A627-DEEB5DEB4020}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8911483C-C00A-4183-9FBC-6C9C00946C15}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{C3F058A9-407D-4CD1-8F66-B75605B54B69}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Prod.cap
Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{162E06EC-4E38-4809-AE76-BF2400D34334}
Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{5C9A2304-70A5-11D5-AFB0-0050DAC67890}
Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{A1489C85-4F6F-48C4-AC9E-18B63AF4703E}
Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{F310F027-15CB-4A7F-B10D-3A4AFB5013A5}
Chiave Eliminata : HKLM\Software\Conduit
Chiave Eliminata : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Babylon
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Babylon.exe
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chiave Eliminata : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Babylon
Chiave Eliminata : HKLM\Software\SearchquSRTB
Chiave Eliminata : HKLM\Software\SProtector
Valore Eliminata : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Valore Eliminata : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Babylon Client]

***** [Browser Internet] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registro Pulito.

-\\ Mozilla Firefox v19.0 (it)

File : C:\Documents and Settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\prefs.js

C:\Documents and Settings\paolo\Dati applicazioni\Mozilla\Firefox\Profiles\a1ik5tuv.default\user.js ... Eliminato !

Eliminata : user_pref("CT2530241.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Eliminata : user_pref("CT2530241.CTID", "CT2530241");
Eliminata : user_pref("CT2530241.CurrentServerDate", "24-1-2011");
Eliminata : user_pref("CT2530241.DialogsAlignMode", "LTR");
Eliminata : user_pref("CT2530241.DownloadReferralCookieData", "");
Eliminata : user_pref("CT2530241.EMailNotifierPollDate", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solare Europa o[...]
Eliminata : user_pref("CT2530241.FeedLastCount129102019943903009", 756);
Eliminata : user_pref("CT2530241.FeedPollDate6950684221136826014", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684221267301652", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684221524553831", "Mon Jan 24 2011 09:49:23 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684221590001098", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684221785237350", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684222064595900", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684222129686883", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684222201547670", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684222513881372", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684222671718962", "Mon Jan 24 2011 09:49:23 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684223112896107", "Mon Jan 24 2011 09:49:23 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684223216229724", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684223476241864", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684223782977569", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684223899376495", "Mon Jan 24 2011 09:49:23 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684224107713633", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684224160233948", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684224256660610", "Mon Jan 24 2011 09:49:23 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684224303045800", "Mon Jan 24 2011 09:49:23 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684224573631499", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684224768320385", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedPollDate6950684224786818075", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solar[...]
Eliminata : user_pref("CT2530241.FeedTTL6950684222201547670", 2);
Eliminata : user_pref("CT2530241.FeedTTL6950684222671718962", 10);
Eliminata : user_pref("CT2530241.FeedTTL6950684223782977569", 2);
Eliminata : user_pref("CT2530241.FirstServerDate", "18-9-2010");
Eliminata : user_pref("CT2530241.FirstTime", true);
Eliminata : user_pref("CT2530241.FirstTimeFF3", true);
Eliminata : user_pref("CT2530241.FirstTimeSettingsDone", true);
Eliminata : user_pref("CT2530241.FixPageNotFoundErrors", true);
Eliminata : user_pref("CT2530241.GroupingServerCheckInterval", 1440);
Eliminata : user_pref("CT2530241.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Eliminata : user_pref("CT2530241.Initialize", true);
Eliminata : user_pref("CT2530241.InitializeCommonPrefs", true);
Eliminata : user_pref("CT2530241.InstallationAndCookieDataSentCount", 3);
Eliminata : user_pref("CT2530241.InstallationType", "UnknownIntegration");
Eliminata : user_pref("CT2530241.InstalledDate", "Sat Sep 18 2010 19:22:27 GMT+0200 (ora legale Europa occidenta[...]
Eliminata : user_pref("CT2530241.InvalidateCache", false);
Eliminata : user_pref("CT2530241.IsGrouping", false);
Eliminata : user_pref("CT2530241.IsMulticommunity", false);
Eliminata : user_pref("CT2530241.IsOpenThankYouPage", false);
Eliminata : user_pref("CT2530241.IsOpenUninstallPage", true);
Eliminata : user_pref("CT2530241.LanguagePackLastCheckTime", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solare Euro[...]
Eliminata : user_pref("CT2530241.LanguagePackReloadIntervalMM", 1440);
Eliminata : user_pref("CT2530241.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Eliminata : user_pref("CT2530241.LastLogin_2.7.1.3", "Wed Oct 13 2010 14:47:58 GMT+0200 (ora legale Europa occid[...]
Eliminata : user_pref("CT2530241.LastLogin_2.7.2.0", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solare Europa occid[...]
Eliminata : user_pref("CT2530241.LatestVersion", "3.2.5.2");
Eliminata : user_pref("CT2530241.Locale", "it");
Eliminata : user_pref("CT2530241.LoginCache", 4);
Eliminata : user_pref("CT2530241.MCDetectTooltipHeight", "83");
Eliminata : user_pref("CT2530241.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Eliminata : user_pref("CT2530241.MCDetectTooltipWidth", "295");
Eliminata : user_pref("CT2530241.RadioIsPodcast", false);
Eliminata : user_pref("CT2530241.RadioLastCheckTime", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solare Europa occi[...]
Eliminata : user_pref("CT2530241.RadioLastUpdateIPServer", "3");
Eliminata : user_pref("CT2530241.RadioLastUpdateServer", "129167784706500000");
Eliminata : user_pref("CT2530241.RadioMediaID", "20503766");
Eliminata : user_pref("CT2530241.RadioMediaType", "Media Player");
Eliminata : user_pref("CT2530241.RadioMenuSelectedID", "EBRadioMenu_CT253024120503766");
Eliminata : user_pref("CT2530241.RadioStationName", "Radio%20105");
Eliminata : user_pref("CT2530241.RadioStationURL", "hxxp://105.net/sezioni/inradio/radio/asx/ch_0.asx");
Eliminata : user_pref("CT2530241.SavedHomepage", "resource:/browserconfig.properties");
Eliminata : user_pref("CT2530241.SearchEngine", "Cerca||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM[...]
Eliminata : user_pref("CT2530241.SearchFromAddressBarIsInit", true);
Eliminata : user_pref("CT2530241.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT253[...]
Eliminata : user_pref("CT2530241.SearchInNewTabEnabled", true);
Eliminata : user_pref("CT2530241.SearchInNewTabIntervalMM", 1440);
Eliminata : user_pref("CT2530241.SearchInNewTabLastCheckTime", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solare Eu[...]
Eliminata : user_pref("CT2530241.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Eliminata : user_pref("CT2530241.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Eliminata : user_pref("CT2530241.SettingsCheckIntervalMin", 120);
Eliminata : user_pref("CT2530241.SettingsLastCheckTime", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solare Europa o[...]
Eliminata : user_pref("CT2530241.SettingsLastUpdate", "1284303005");
Eliminata : user_pref("CT2530241.ThirdPartyComponentsInterval", 504);
Eliminata : user_pref("CT2530241.ThirdPartyComponentsLastCheck", "Mon Jan 24 2011 09:49:21 GMT+0100 (ora solare [...]
Eliminata : user_pref("CT2530241.ThirdPartyComponentsLastUpdate", "1291279838");
Eliminata : user_pref("CT2530241.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Eliminata : user_pref("CT2530241.Uninstall", true);
Eliminata : user_pref("CT2530241.UserID", "UN66016628961320762");
Eliminata : user_pref("CT2530241.ValidationData_Toolbar", 0);
Eliminata : user_pref("CT2530241.WeatherNetwork", "");
Eliminata : user_pref("CT2530241.WeatherPollDate", "Mon Jan 24 2011 09:49:22 GMT+0100 (ora solare Europa occiden[...]
Eliminata : user_pref("CT2530241.WeatherUnit", "C");
Eliminata : user_pref("CT2530241.alertChannelId", "923244");
Eliminata : user_pref("CT2530241.clientLogIsEnabled", false);
Eliminata : user_pref("CT2530241.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Eliminata : user_pref("CT2530241.myStuffEnabled", true);
Eliminata : user_pref("CT2530241.myStuffPublihserMinWidth", 400);
Eliminata : user_pref("CT2530241.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Eliminata : user_pref("CT2530241.myStuffServiceIntervalMM", 1440);
Eliminata : user_pref("CT2530241.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Eliminata : user_pref("CT2530241.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Eliminata : user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Eliminata : user_pref("CT2786678.CTID", "CT2786678");
Eliminata : user_pref("CT2786678.CurrentServerDate", "24-1-2011");
Eliminata : user_pref("CT2786678.DialogsAlignMode", "LTR");
Eliminata : user_pref("CT2786678.DownloadReferralCookieData", "");
Eliminata : user_pref("CT2786678.EMailNotifierPollDate", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare Europa o[...]
Eliminata : user_pref("CT2786678.FeedLastCount5690698542593514850", 494);
Eliminata : user_pref("CT2786678.FeedPollDate129301619375443753", "Mon Jan 24 2011 09:49:43 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375443759", "Mon Jan 24 2011 09:49:43 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444699", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444705", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444711", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444717", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444723", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444729", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444735", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444741", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedPollDate129301619375444747", "Mon Jan 24 2011 09:49:43 GMT+0100 (ora solare[...]
Eliminata : user_pref("CT2786678.FeedTTL129301619375444699", 10);
Eliminata : user_pref("CT2786678.FeedTTL129301619375444723", 15);
Eliminata : user_pref("CT2786678.FeedTTL129301619375444735", 5);
Eliminata : user_pref("CT2786678.FeedTTL129301619375444747", 5);
Eliminata : user_pref("CT2786678.FirstServerDate", "24-11-2010");
Eliminata : user_pref("CT2786678.FirstTime", true);
Eliminata : user_pref("CT2786678.FirstTimeFF3", true);
Eliminata : user_pref("CT2786678.FirstTimeSettingsDone", true);
Eliminata : user_pref("CT2786678.FixPageNotFoundErrors", false);
Eliminata : user_pref("CT2786678.GroupingServerCheckInterval", 1440);
Eliminata : user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Eliminata : user_pref("CT2786678.Initialize", true);
Eliminata : user_pref("CT2786678.InitializeCommonPrefs", true);
Eliminata : user_pref("CT2786678.InstallationAndCookieDataSentCount", 3);
Eliminata : user_pref("CT2786678.InstallationType", "UnknownIntegration");
Eliminata : user_pref("CT2786678.InstalledDate", "Wed Nov 24 2010 21:35:44 GMT+0100 (ora solare Europa occidenta[...]
Eliminata : user_pref("CT2786678.IsGrouping", false);
Eliminata : user_pref("CT2786678.IsMulticommunity", false);
Eliminata : user_pref("CT2786678.IsOpenThankYouPage", false);
Eliminata : user_pref("CT2786678.IsOpenUninstallPage", false);
Eliminata : user_pref("CT2786678.LanguagePackLastCheckTime", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare Euro[...]
Eliminata : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440);
Eliminata : user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Eliminata : user_pref("CT2786678.LastLogin_2.7.2.0", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare Europa occid[...]
Eliminata : user_pref("CT2786678.LatestVersion", "3.2.5.2");
Eliminata : user_pref("CT2786678.Locale", "en");
Eliminata : user_pref("CT2786678.LoginCache", 4);
Eliminata : user_pref("CT2786678.MCDetectTooltipHeight", "83");
Eliminata : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Eliminata : user_pref("CT2786678.MCDetectTooltipWidth", "295");
Eliminata : user_pref("CT2786678.SHRINK_TOOLBAR", 1);
Eliminata : user_pref("CT2786678.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Eliminata : user_pref("CT2786678.SearchFromAddressBarIsInit", true);
Eliminata : user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT278[...]
Eliminata : user_pref("CT2786678.SearchInNewTabEnabled", true);
Eliminata : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440);
Eliminata : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare Eu[...]
Eliminata : user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Eliminata : user_pref("CT2786678.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Eliminata : user_pref("CT2786678.SettingsCheckIntervalMin", 120);
Eliminata : user_pref("CT2786678.SettingsLastCheckTime", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora solare Europa o[...]
Eliminata : user_pref("CT2786678.SettingsLastUpdate", "1295815474");
Eliminata : user_pref("CT2786678.ThirdPartyComponentsInterval", 504);
Eliminata : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Sat Jan 08 2011 14:52:25 GMT+0100 (ora solare [...]
Eliminata : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1246790578");
Eliminata : user_pref("CT2786678.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Eliminata : user_pref("CT2786678.Uninstall", true);
Eliminata : user_pref("CT2786678.UserID", "UN87540555035618945");
Eliminata : user_pref("CT2786678.ValidationData_Toolbar", 2);
Eliminata : user_pref("CT2786678.WeatherNetwork", "");
Eliminata : user_pref("CT2786678.WeatherPollDate", "Mon Jan 24 2011 09:49:43 GMT+0100 (ora solare Europa occiden[...]
Eliminata : user_pref("CT2786678.WeatherUnit", "C");
Eliminata : user_pref("CT2786678.alertChannelId", "1178763");
Eliminata : user_pref("CT2786678.clientLogIsEnabled", true);
Eliminata : user_pref("CT2786678.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Eliminata : user_pref("CT2786678.myStuffEnabled", true);
Eliminata : user_pref("CT2786678.myStuffPublihserMinWidth", 400);
Eliminata : user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Eliminata : user_pref("CT2786678.myStuffServiceIntervalMM", 1440);
Eliminata : user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Eliminata : user_pref("CT2786678.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Eliminata : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Eliminata : user_pref("CommunityToolbar.ToolbarsList", "CT2530241,CT2786678");
Eliminata : user_pref("CommunityToolbar.ToolbarsList2", "CT2530241,CT2786678");
Eliminata : user_pref("CommunityToolbar.alert.alertInfoInterval", 720);
Eliminata : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Oct 13 2010 14:47:56 GMT+0200 (ora l[...]
Eliminata : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Eliminata : user_pref("CommunityToolbar.alert.locale", "en");
Eliminata : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Eliminata : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Oct 13 2010 14:47:56 GMT+0200 (ora legal[...]
Eliminata : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1283688156");
Eliminata : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Eliminata : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Eliminata : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Eliminata : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Eliminata : user_pref("CommunityToolbar.alert.userId", "{90d2bbcc-3d58-4f7d-8213-42dea11178f6}");
Eliminata : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Mon Jan 24 2011 09:49:42 GMT+0100 (ora[...]
Eliminata : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2530241");
Eliminata : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Eliminata : user_pref("browser.search.defaultenginename", "Search Results");
Eliminata : user_pref("browser.search.defaultthis.engineName", "Softonic-IT Customized Web Search");
Eliminata : user_pref("browser.search.defaulturl", "hxxp://websearch.helpmefindyour.info/?pid=703&r=2013/04/18&h[...]
Eliminata : user_pref("extensions.BabylonToolbar.admin", false);
Eliminata : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Eliminata : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
Eliminata : user_pref("extensions.BabylonToolbar.autoRvrt", "false");
Eliminata : user_pref("extensions.BabylonToolbar.bbDpng", 15);
Eliminata : user_pref("extensions.BabylonToolbar.cntry", "IT");
Eliminata : user_pref("extensions.BabylonToolbar.dfltLng", "it");
Eliminata : user_pref("extensions.BabylonToolbar.excTlbr", false);
Eliminata : user_pref("extensions.BabylonToolbar.ffxUnstlRst", true);
Eliminata : user_pref("extensions.BabylonToolbar.firstRun", false);
Eliminata : user_pref("extensions.BabylonToolbar.hdrMd5", "D619D27EF7EEC713C1262FF5C3F91707");
Eliminata : user_pref("extensions.BabylonToolbar.id", "18b851bd0000000000000030674bda25");
Eliminata : user_pref("extensions.BabylonToolbar.instlDay", "15798");
Eliminata : user_pref("extensions.BabylonToolbar.instlRef", "na");
Eliminata : user_pref("extensions.BabylonToolbar.lastActv", "15");
Eliminata : user_pref("extensions.BabylonToolbar.lastDP", 15);
Eliminata : user_pref("extensions.BabylonToolbar.newTab", false);
Eliminata : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Eliminata : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Eliminata : user_pref("extensions.BabylonToolbar.rvrt", "false");
Eliminata : user_pref("extensions.BabylonToolbar.smplGrp", "none");
Eliminata : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Eliminata : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...]
Eliminata : user_pref("extensions.BabylonToolbar.vrsn", "1.8.11.10");
Eliminata : user_pref("extensions.BabylonToolbar.vrsnTs", "1.8.11.101:50:15");
Eliminata : user_pref("extensions.BabylonToolbar.vrsni", "1.8.11.10");
Eliminata : user_pref("extensions.BabylonToolbar_i.babExt", "");
Eliminata : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=14795&tt=250111_def");
Eliminata : user_pref("extensions.BabylonToolbar_i.srcExt", "def");
Eliminata : user_pref("extensions.enabledAddons", "%7Bd5eeb813-935a-435d-b01e-b3a02f2cb408%7D:0.9.4,%7B20a82645-[...]
Eliminata : user_pref("extensions.ocr@babylon.com.install-event-fired", true);

-\\ Google Chrome v26.0.1410.64

File : C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Preferences

[OK] File Pulito.

*************************

AdwCleaner[S1].txt - [31970 octets] - [27/04/2013 20:40:51]

########## EOF - C:\AdwCleaner[S1].txt - [32031 octets] ##########
agatone
Inviato: Saturday, April 27, 2013 9:51:16 PM
Rank: AiutAmico

Iscritto dal : 1/5/2011
Posts: 112
Ciao R16
OTL mi ha dato solo 1 txt

OTL.Txt
r16
Inviato: Saturday, April 27, 2013 10:08:45 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Avvia OTL.

Sotto "Custom Scans\Fixes" copia-incolla questo codice:


Code:
:OTL
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-21-823518204-1801674531-725345543-1010\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
FF - prefs.js..browser.startup.homepage: " http://search.findeer.com"
FF - prefs.js..extensions.enabledItems: ocr@babylon.com:1.1
[2013/04/27 12.38.08 | 000,000,000 | ---D | M] (Babylon Translation Activation) -- C:\Programmi\Mozilla Firefox\updated\extensions\ocr@babylon.com
CHR - plugin: Babylon Chrome Plugin (Enabled) = C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.0_0\BabylonChromePI.dll
O2 - BHO: (no name) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - No CLSID value found.
O3 - HKU\S-1-5-21-823518204-1801674531-725345543-1003\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-21-823518204-1801674531-725345543-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-823518204-1801674531-725345543-1003\..\Toolbar\WebBrowser: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\File comuni\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Translate this web page with Babylon - Reg Error: Value error. File not found
O8 - Extra context menu item: Translate with Babylon - Reg Error: Value error. File not found
[2013/04/24 08.55.31 | 000,000,000 | ---D | C] -- C:\combofix13-03-27.0130480c
[2013/04/24 07.59.29 | 000,000,000 | ---D | C] -- C:\combofix13-03-27.01
[2013/04/19 22.53.56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\Sophos
[2010/04/23 20.43.14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Alwil Software

:Files
C:\Programmi\Sophos
C:\Documents and Settings\paolo\Impostazioni locali\Dati applicazioni\SoftwareUpdater
C:\Documents and Settings\All Users\Dati applicazioni\xqkcebzs.dik
ipconfig /flushdns /c

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"

:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]


Clicca sul pulsante RUN FIX.
Lascia fare la scansione senza interferire.
Posta il log.

Dimmi come funziona il pc.
agatone
Inviato: Sunday, April 28, 2013 12:31:01 AM
Rank: AiutAmico

Iscritto dal : 1/5/2011
Posts: 112
Mi pare che viaggi a meraviglia
A sensazione lo sento piu' leggero.
visto che ci sono ho dato un'occhiata ad una proprieta' che mi da errore da un po di tempo.
In Pannello di Controllo e poi nella sottovoce Sintesi e riconoscimento vocale mi compare ancora il messaggio di errore :

Si e' verificata un'eccezione durante l'esecuzione di
"C:\WINDOWS\system32.dll,Control_RunDLL
"C\Programmi\File comuni\Microsoft Shared\sapi.cpl",Sintesi e riconoscimento vocale"


Per il resto ,tutto a meraviglia
r16
Inviato: Sunday, April 28, 2013 2:00:27 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Apri OTL e clicca su Cleanup.
Si disistallerà correttamente OTL.
Ti chiederà il riavvio: acconsenti.

Disattiva il Ripristino configurazione sistema.
Poi lo Riattivi, e crea un punto di ripristino, che può servire in futuro.

Commenta:
Si e' verificata un'eccezione durante l'esecuzione di
"C:\WINDOWS\system32.dll,Control_RunDLL
"C\Programmi\File comuni\Microsoft Shared\sapi.cpl",Sintesi e riconoscimento vocale"

Mi dispiace ma non è il mio campo.
Per cui meglio stare zitti, che sparare cazzate. Whistle

Se vuoi prova a porre il quesito in "Problemi Informatici":
http://forum.aiutamici.com/yaf_topics8_Problemi-Informatici.aspx
Ciao.
agatone
Inviato: Sunday, April 28, 2013 2:49:30 PM
Rank: AiutAmico

Iscritto dal : 1/5/2011
Posts: 112
Ciao R16 Grazie di tutto
Dopo averlo riattivato, il punto di ripristino si crea da solo ?
Per quanto riguarda in messaggio di errore in "sintesi e riconoscimento vocale,non e' in realta' un problema,non mi da nessun fastidio.
Ma vorrei ringraziarti adesso ancora una volta
Ogni volta rimango meravigliato della disponiblita' e esperienza che mettete a disposizione
agatone
Inviato: Sunday, April 28, 2013 3:04:12 PM
Rank: AiutAmico

Iscritto dal : 1/5/2011
Posts: 112
Ciao R 16
Ho ricercato su Google per creare un punto di ripristino
Programmi-Accessori-Utilita' di Sistema ecc..
Quindi sarei davvero a posto
Grazie ancora e buona giornata

r16
Inviato: Sunday, April 28, 2013 3:08:51 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Commenta:
Dopo averlo riattivato, il punto di ripristino si crea da solo ?

No, anche se lo creerà.
Dipende da come è tarato il Ripristino.
Comunque non è un problema anche se non lo crei tu.
Commenta:
Quindi sarei davvero a posto
Grazie ancora e buona giornata

Sì, se il pc funziona bene abbiamo concluso.
Prego, e buona Domenica anche a te.
Ciao.
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.