ecco il file di testo di combofix:
ComboFix 10-04-21.01 - alessandra 26/04/2010 19.38.01.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.39.1040.18.1014.276 [GMT 2:00]
Eseguito da: c:\users\alessandra\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2635387291-1119825907-1126837931-500
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\intel64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\localsys64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\ntos.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\oembios.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\sdra64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\swin32.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\twex.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\twext.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\wsnpoema.exe
c:\program files\messengerskinner
c:\program files\messengerskinner\download\defaultPack.cab
c:\program files\messengerskinner\resources\appconfig.xml
c:\program files\messengerskinner\resources\btn.rgn
c:\program files\messengerskinner\resources\btnBnr.rgn
c:\program files\messengerskinner\resources\btnIn.rgn
c:\program files\messengerskinner\resources\btnInNormal.bmp
c:\program files\messengerskinner\resources\btnInOver.bmp
c:\program files\messengerskinner\resources\btnNormal.bmp
c:\program files\messengerskinner\resources\btnNormal.gif
c:\program files\messengerskinner\resources\btnNormalBnr.bmp
c:\program files\messengerskinner\resources\btnNormalBnr.gif
c:\program files\messengerskinner\resources\btnOver.bmp
c:\program files\messengerskinner\resources\btnOver.gif
c:\program files\messengerskinner\resources\btnOverBnr.bmp
c:\program files\messengerskinner\resources\btnOverBnr.gif
c:\program files\messengerskinner\resources\languages_v2.xml
c:\program files\messengerskinner\uninst.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner
c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Condizioni generali.url
c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Disinstalla.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\MessengerSkinner.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Riservatezza.url
c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Website.url
c:\users\ALESSA~1\FAVORI~1\Videos.url
c:\users\alessandra\AppData\Local\yikcc.dat
c:\users\alessandra\AppData\Local\yikcc.exe
c:\users\alessandra\AppData\Local\yikcc_nav.dat
c:\users\alessandra\AppData\Local\yikcc_navps.dat
c:\users\alessandra\AppData\Roaming\MessengerSkinner
c:\users\alessandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Videos.url
c:\users\alessandra\Desktop\Videos.url
c:\users\alessandra\Favorites\Videos.url
c:\windows\system32\nvs2.inf
.
((((((((((((((((((((((((( Files Creati Da 2010-03-26 al 2010-04-26 )))))))))))))))))))))))))))))))))))
.
2010-04-26 17:54 . 2010-04-26 17:59 -------- d-----w- c:\users\alessandra\AppData\Local\temp
2010-04-26 17:54 . 2010-04-26 17:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-26 15:49 . 2010-04-26 15:49 -------- d-----w- c:\users\alessandra\AppData\Local\Kiwee Toolbar2
2010-04-26 12:42 . 2010-04-26 12:42 -------- d-----w- c:\users\alessandra\AppData\Roaming\IObit
2010-04-26 12:42 . 2010-04-26 12:42 -------- d-----w- c:\program files\IObit
2010-04-26 11:13 . 2010-04-26 11:13 -------- d-----w- C:\PerfLogs
2010-04-26 08:56 . 2010-04-26 08:55 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-26 08:16 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
2010-04-26 08:16 . 2009-03-08 11:31 48128 ----a-w- c:\windows\system32\mshtmler.dll
2010-04-26 08:16 . 2009-03-08 11:22 156160 ----a-w- c:\windows\system32\msls31.dll
2010-04-26 08:16 . 2009-03-08 11:33 18944 ----a-w- c:\windows\system32\corpol.dll
2010-04-26 08:11 . 2008-11-01 03:44 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-04-26 08:11 . 2008-03-08 04:21 1695744 ----a-w- c:\windows\system32\gameux.dll
2010-04-26 08:11 . 2008-11-01 01:21 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-04-25 18:23 . 2010-02-12 10:49 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-04-25 17:25 . 2008-06-20 01:18 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-04-25 17:25 . 2008-06-20 01:17 97800 ----a-w- c:\windows\system32\infocardapi.dll
2010-04-25 17:25 . 2008-06-20 01:17 622080 ----a-w- c:\windows\system32\icardagt.exe
2010-04-25 17:25 . 2008-06-20 01:17 11264 ----a-w- c:\windows\system32\icardres.dll
2010-04-25 17:25 . 2008-06-20 01:18 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-04-25 17:24 . 2008-06-20 01:18 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2010-04-25 17:24 . 2008-06-20 01:18 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2010-04-25 17:08 . 2008-07-27 18:00 96760 ----a-w- c:\windows\system32\dfshim.dll
2010-04-25 17:08 . 2008-07-27 18:00 282112 ----a-w- c:\windows\system32\mscoree.dll
2010-04-25 17:08 . 2008-07-27 18:00 41984 ----a-w- c:\windows\system32\netfxperf.dll
2010-04-25 17:08 . 2008-07-27 18:00 158720 ----a-w- c:\windows\system32\mscorier.dll
2010-04-25 17:08 . 2008-07-27 18:00 83968 ----a-w- c:\windows\system32\mscories.dll
2010-04-25 17:05 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-04-25 17:05 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-04-25 17:05 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-04-25 17:00 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2010-04-25 17:00 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2010-04-25 17:00 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2010-04-25 17:00 . 2008-01-19 07:36 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2010-04-25 17:00 . 2008-01-19 07:36 64512 ----a-w- c:\windows\system32\wlanapi.dll
2010-04-25 17:00 . 2008-01-05 11:34 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2010-04-25 17:00 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2010-04-25 16:53 . 2008-06-06 03:27 38912 ----a-w- c:\windows\system32\xolehlp.dll
2010-04-25 16:53 . 2008-06-06 03:27 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2010-04-25 16:52 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-04-25 16:52 . 2009-10-19 14:27 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-04-25 16:52 . 2009-10-19 14:24 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-04-25 16:52 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
2010-04-25 16:52 . 2008-01-19 07:34 23552 ----a-w- c:\windows\system32\lpk.dll
2010-04-25 16:52 . 2009-12-11 12:07 301568 ----a-w- c:\windows\system32\drivers\srv.sys
2010-04-25 16:52 . 2009-12-11 12:07 98304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-04-25 16:51 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2010-04-25 16:51 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2010-04-25 16:51 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2010-04-25 16:51 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2010-04-25 16:51 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2010-04-25 16:51 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2010-04-25 16:51 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2010-04-25 16:51 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2010-04-25 16:51 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2010-04-25 16:48 . 2008-10-21 05:25 296960 ----a-w- c:\windows\system32\gdi32.dll
2010-04-25 16:48 . 2009-08-10 11:00 1257472 ----a-w- c:\windows\system32\msxml3.dll
2010-04-25 16:48 . 2009-08-10 11:01 1399296 ----a-w- c:\windows\system32\msxml6.dll
2010-04-25 16:48 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2010-04-25 16:48 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2010-04-25 16:48 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll
2010-04-25 16:48 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2010-04-25 16:48 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2010-04-25 16:48 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2010-04-25 16:47 . 2010-02-23 11:32 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-25 16:47 . 2010-02-23 11:32 78848 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-25 16:47 . 2010-02-23 11:32 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-25 16:47 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2010-04-25 16:47 . 2008-01-19 07:34 98816 ----a-w- c:\windows\system32\mfps.dll
2010-04-25 16:47 . 2008-01-19 07:33 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2010-04-25 16:47 . 2008-01-19 07:33 24576 ----a-w- c:\windows\system32\mfpmp.exe
2010-04-25 16:47 . 2010-02-18 14:49 3598216 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-25 16:47 . 2010-02-18 14:49 3545992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-25 16:47 . 2008-12-06 04:42 376832 ----a-w- c:\windows\system32\winhttp.dll
2010-04-25 16:46 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2010-04-25 16:45 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
2010-04-25 16:45 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2010-04-25 16:44 . 2008-01-19 07:36 53248 ----a-w- c:\windows\system32\tsgqec.dll
2010-04-25 16:44 . 2008-01-19 07:33 136192 ----a-w- c:\windows\system32\aaclient.dll
2010-04-25 16:44 . 2008-06-26 03:29 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2010-04-25 16:41 . 2009-12-28 12:35 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-04-25 16:41 . 2009-12-28 12:28 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-04-25 16:41 . 2009-12-28 12:35 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2010-04-25 16:41 . 2009-12-28 12:32 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-04-25 16:41 . 2009-12-28 12:32 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-04-25 16:41 . 2009-12-28 12:32 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-04-25 16:41 . 2009-12-28 12:31 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-04-25 16:41 . 2009-12-28 12:32 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-04-25 16:41 . 2009-12-28 12:31 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-04-25 16:41 . 2009-12-28 12:28 65024 ----a-w- c:\windows\system32\avicap32.dll
2010-04-25 16:22 . 2010-01-23 09:44 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-25 16:18 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
2010-04-25 16:15 . 2010-02-18 14:49 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-25 16:15 . 2010-02-18 14:11 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-25 16:15 . 2010-02-18 11:52 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-25 16:15 . 2008-01-19 05:55 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2010-04-25 16:15 . 2009-03-17 03:38 13824 ----a-w- c:\windows\system32\apilogen.dll
2010-04-25 16:15 . 2009-03-17 03:38 24064 ----a-w- c:\windows\system32\amxread.dll
2010-04-25 16:15 . 2008-08-12 03:39 443392 ----a-w- c:\windows\system32\win32spl.dll
2010-04-25 16:15 . 2008-01-19 07:36 37888 ----a-w- c:\windows\system32\printcom.dll
2010-04-25 16:14 . 2009-08-14 13:53 2035712 ----a-w- c:\windows\system32\win32k.sys
2010-04-25 16:14 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2010-04-25 16:14 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-04-25 16:14 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2010-04-25 16:14 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2010-04-25 16:13 . 2008-11-27 04:43 268288 ----a-w- c:\windows\system32\schannel.dll
2010-04-25 16:13 . 2008-06-23 01:59 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2010-04-25 16:13 . 2008-06-23 01:58 94720 ----a-w- c:\windows\system32\logagent.exe
2010-04-25 16:12 . 2009-09-04 12:24 61440 ----a-w- c:\windows\system32\msasn1.dll
2010-04-25 16:12 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2010-04-25 16:11 . 2009-09-14 09:44 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-04-25 16:11 . 2009-10-07 12:41 244224 ----a-w- c:\windows\system32\rastls.dll
2010-04-25 16:11 . 2009-10-07 12:41 281600 ----a-w- c:\windows\system32\raschap.dll
2010-04-25 16:10 . 2009-08-10 13:05 351232 ----a-w- c:\windows\system32\WSDApi.dll
2010-04-25 16:10 . 2009-04-02 12:37 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2010-04-25 16:06 . 2010-04-26 12:17 -------- d-----w- c:\programdata\Norton
2010-04-25 16:05 . 2010-04-25 16:05 -------- d-----w- c:\programdata\NortonInstaller
2010-04-25 16:02 . 2010-04-26 17:27 -------- d-----w- c:\users\alessandra\Tracing
2010-04-25 15:58 . 2009-08-05 20:48 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2010-04-25 15:58 . 2010-04-25 15:58 -------- dc----w- c:\windows\system32\DRVSTORE
2010-04-25 15:53 . 2010-04-25 15:53 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-04-25 15:43 . 2008-06-26 03:21 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2010-04-25 15:43 . 2008-06-26 03:21 347648 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2010-04-25 15:36 . 2010-04-25 15:36 -------- d-----w- c:\program files\Microsoft
2010-04-25 15:35 . 2010-04-25 15:35 -------- d-----w- c:\program files\Windows Live SkyDrive
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-26 17:55 . 2007-10-08 10:45 12 ----a-w- c:\windows\bthservsdp.dat
2010-04-26 17:43 . 2006-11-06 01:52 662862 ----a-w- c:\windows\system32\perfh010.dat
2010-04-26 17:43 . 2006-11-06 01:52 120326 ----a-w- c:\windows\system32\perfc010.dat
2010-04-26 16:07 . 2007-04-13 14:36 -------- d-----w- c:\program files\Symantec
2010-04-26 16:05 . 2007-08-09 21:55 -------- d-----w- c:\users\alessandra\AppData\Roaming\Skype
2010-04-26 16:03 . 2007-04-13 14:36 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-04-26 15:11 . 2007-04-13 15:03 -------- d-----w- c:\program files\Google
2010-04-26 12:18 . 2007-09-07 19:36 -------- d-----w- c:\program files\Totò Sapore
2010-04-26 12:17 . 2008-03-19 19:54 -------- d-----w- c:\program files\Norton Security Scan
2010-04-26 11:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-04-26 11:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-04-26 11:31 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-26 11:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-04-26 11:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-04-26 11:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-04-26 11:30 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-04-26 10:24 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2010-04-26 10:23 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2010-04-26 08:57 . 2007-04-13 15:20 -------- d-----w- c:\program files\Common Files\Java
2010-04-26 08:54 . 2007-04-13 15:20 -------- d-----w- c:\program files\Java
2010-04-25 19:58 . 2008-03-04 21:35 -------- d-----w- c:\program files\Microsoft Silverlight
2010-04-25 19:06 . 2008-06-22 13:18 -------- d-----w- c:\program files\Virtual Earth 3D
2010-04-25 18:09 . 2007-04-13 14:49 -------- d-----w- c:\program files\Microsoft Works
2010-04-25 16:31 . 2008-05-20 10:05 95 ----a-w- c:\users\alessandra\AppData\Local\sxdinzx.bat
2010-04-25 15:58 . 2008-05-11 21:05 -------- d-----w- c:\program files\Windows Live
2010-04-25 15:56 . 2007-09-02 20:10 -------- d-----w- c:\program files\Windows Live Toolbar
2010-04-25 14:42 . 2008-05-19 21:52 -------- d-----w- c:\programdata\Kiwee Toolbar2
2010-02-23 06:39 . 2010-04-26 08:25 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-04-26 08:25 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33 . 2010-04-26 08:25 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55 . 2010-04-26 08:25 133632 ----a-w- c:\windows\system32\ieUnatt.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
2008-04-03 08:52 265360 ----a-w- c:\program files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2006-07-13 20034600]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2007-02-12 253000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 729088]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-02-16 172032]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-12-04 46704]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"CognizanceTS"="c:\progra~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll" [2003-12-22 17920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-09 77824]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-04-25 30192]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
"KiweeHook"="c:\program files\Kiwee Toolbar2\1.5.131\kwtbaim.exe" [2008-04-03 56456]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\APSHook.dll c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-04-25 30192]
R3 GTFFBUS;GT FF BUS;c:\windows\system32\DRIVERS\gtffbus.sys [2006-11-16 17024]
R3 GTMNDISIRPXP;GT M 3G+ IRP NDIS;c:\windows\system32\DRIVERS\Gtm51Irp.sys [2006-11-16 115840]
R3 GTUQBUS;GT UQ BUS;c:\windows\system32\DRIVERS\gtuqbus.sys [2006-11-16 34560]
S2 ASBroker;Operatore della sessione di accesso;c:\windows\System32\svchost.exe [2008-01-19 21504]
S2 ASChannel;Canale di comunicazione locale;c:\windows\System32\svchost.exe [2008-01-19 21504]
S2 GtDetectSc;GT Detect;c:\windows\system32\GtDetectSc.exe [2006-11-16 167936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
bthsvcs REG_MULTI_SZ BthServ
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contenuto della cartella 'Scheduled Tasks'
2010-04-26 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-04-26 12:54]
2008-08-06 c:\windows\Tasks\HPCeeScheduleForalessandra.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2007-04-13 14:08]
2010-04-26 c:\windows\Tasks\User_Feed_Synchronization-{1185D9E9-3F6E-4526-ADAA-F3441A5E3878}.job
- c:\windows\system32\msfeedssync.exe [2010-04-26 04:54]
.
.
------- Scansione supplementare -------
.
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=IT_IT&c=71&bd=Pavilion&pf=laptop
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
URLSearchHooks-*{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
AddRemove-{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA} - c:\program files\InstallShield Installation Information\{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}\Setup.exeUNINSTALL
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-26 20:00
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'Explorer.exe'(2260)
c:\windows\system32\APSHook.dll
c:\program files\Bioscrypt\VeriSoft\Bin\ItClient.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\program files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
c:\windows\system32\conime.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
.
**************************************************************************
.
Ora fine scansione: 2010-04-26 20:09:52 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-04-26 18:09
Pre-Run: 61.754.552.320 byte disponibili
Post-Run: 61.435.850.752 byte disponibili
- - End Of File - - 4F72C76FAD34CA917B2C802EFFF5E2E6
Attendo istruzioni prima di sostituire l'antivirus.
Salutoni