ComboFix 11-11-26.04 - Utente 27/11/2011 10.24.47.1.8 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3063.2179 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: AVG Internet Security *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\mazuki.dll
c:\documents and settings\All Users\Dati applicazioni\page
c:\documents and settings\All Users\Dati applicazioni\page\page.ico
c:\documents and settings\All Users\Dati applicazioni\page\page.URL
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\All Users\Dati applicazioni\TorrentEasy\fdmbtsupp.dll
c:\documents and settings\Utente\Dati applicazioni\.#
c:\documents and settings\Utente\Dati applicazioni\.#\MBX@26BC@383FA0.###
c:\documents and settings\Utente\Dati applicazioni\.#\MBX@26BC@383FD0.###
c:\documents and settings\Utente\Dati applicazioni\facemoods.com
c:\documents and settings\Utente\Dati applicazioni\inst.exe
c:\documents and settings\Utente\Dati applicazioni\vso_ts_preview.xml
c:\documents and settings\Utente\WINDOWS
C:\install.exe
c:\programmi\Fast Browser Search
c:\programmi\Fast Browser Search\IE\about.html
c:\programmi\Fast Browser Search\IE\affid.dat
c:\programmi\Fast Browser Search\IE\basis.xml
c:\programmi\Fast Browser Search\IE\basis_br.xml
c:\programmi\Fast Browser Search\IE\basis_de.xml
c:\programmi\Fast Browser Search\IE\basis_en.xml
c:\programmi\Fast Browser Search\IE\basis_es.xml
c:\programmi\Fast Browser Search\IE\basis_fr.xml
c:\programmi\Fast Browser Search\IE\basis_it.xml
c:\programmi\Fast Browser Search\IE\basis_nr.xml
c:\programmi\Fast Browser Search\IE\basis_pt.xml
c:\programmi\Fast Browser Search\IE\basis_ru.xml
c:\programmi\Fast Browser Search\IE\basis_tr.xml
c:\programmi\Fast Browser Search\IE\error.html
c:\programmi\Fast Browser Search\IE\fbsProtection.xml
c:\programmi\Fast Browser Search\IE\FbsSearchProvider.xml
c:\programmi\Fast Browser Search\IE\FbsSearchProvider01.xml
c:\programmi\Fast Browser Search\IE\FbsSearchProvider05.xml
c:\programmi\Fast Browser Search\IE\FbsSearchProvider08.xml
c:\programmi\Fast Browser Search\IE\FbsSearchProvider14.xml
c:\programmi\Fast Browser Search\IE\fbstoolbar.jar
c:\programmi\Fast Browser Search\IE\icons.bmp
c:\programmi\Fast Browser Search\IE\info.txt
c:\programmi\Fast Browser Search\IE\local.xml
c:\programmi\Fast Browser Search\IE\logobg.bmp
c:\programmi\Fast Browser Search\IE\MTWBtoolbar.html
c:\programmi\Fast Browser Search\IE\Provider01.xml
c:\programmi\Fast Browser Search\IE\Provider05.xml
c:\programmi\Fast Browser Search\IE\Provider08.xml
c:\programmi\Fast Browser Search\IE\Provider14.xml
c:\programmi\Fast Browser Search\IE\search.bmp
c:\programmi\Fast Browser Search\IE\search_br.bmp
c:\programmi\Fast Browser Search\IE\search_de.bmp
c:\programmi\Fast Browser Search\IE\search_es.bmp
c:\programmi\Fast Browser Search\IE\search_fr.bmp
c:\programmi\Fast Browser Search\IE\search_it.bmp
c:\programmi\Fast Browser Search\IE\search_pt.bmp
c:\programmi\Fast Browser Search\IE\search_ru.bmp
c:\programmi\Fast Browser Search\IE\SearchProvider01.xml
c:\programmi\Fast Browser Search\IE\SearchProvider05.xml
c:\programmi\Fast Browser Search\IE\SearchProvider08.xml
c:\programmi\Fast Browser Search\IE\SearchProvider14.xml
c:\programmi\Fast Browser Search\IE\sgpUpdater.xml
c:\programmi\Fast Browser Search\IE\tbs_include_script_003175.js
c:\programmi\Fast Browser Search\IE\tbs_include_script_005064.js
c:\programmi\Fast Browser Search\IE\tbs_include_script_012817.js
c:\programmi\Fast Browser Search\IE\Toolbar Help.htm
c:\programmi\Fast Browser Search\IE\version.txt
c:\programmi\Internet Explorer\SET10.tmp
c:\programmi\Internet Explorer\SET11.tmp
c:\programmi\Internet Explorer\SET17.tmp
c:\programmi\Internet Explorer\SET19.tmp
c:\programmi\Internet Explorer\SET6.tmp
c:\programmi\Internet Explorer\SET7.tmp
c:\programmi\Internet Explorer\SET8.tmp
c:\programmi\Internet Explorer\SET9.tmp
c:\programmi\Internet Explorer\SETA.tmp
c:\programmi\Internet Explorer\SETA0.tmp
c:\programmi\Internet Explorer\SETA1.tmp
c:\programmi\Internet Explorer\SETA2.tmp
c:\programmi\Internet Explorer\SETB.tmp
c:\programmi\Internet Explorer\SETC.tmp
c:\programmi\Internet Explorer\SETD.tmp
c:\programmi\Internet Explorer\SETD9.tmp
c:\programmi\Internet Explorer\SETDA.tmp
c:\programmi\Internet Explorer\SETDB.tmp
c:\programmi\Internet Explorer\SETE.tmp
c:\programmi\Internet Explorer\SETF.tmp
c:\programmi\Search Guard Plus
c:\programmi\Search Guard Plus\fbsProtection.xml
c:\programmi\Search Guard Plus\fbsSearchProvider.xml
c:\programmi\Search Guard Plus\FbsSearchProvider01.xml
c:\programmi\Search Guard Plus\FbsSearchProvider05.xml
c:\programmi\Search Guard Plus\FbsSearchProvider08.xml
c:\programmi\Search Guard Plus\FbsSearchProvider14.xml
c:\programmi\Search Guard Plus\Provider01.xml
c:\programmi\Search Guard Plus\Provider05.xml
c:\programmi\Search Guard Plus\Provider08.xml
c:\programmi\Search Guard Plus\Provider14.xml
c:\programmi\Search Guard Plus\SearchProvider01.xml
c:\programmi\Search Guard Plus\SearchProvider05.xml
c:\programmi\Search Guard Plus\SearchProvider08.xml
c:\programmi\Search Guard Plus\SearchProvider14.xml
c:\programmi\Search Guard PlusU
c:\programmi\Search Guard PlusU\sgpUpdater.xml
c:\programmi\Windows Searchqu Toolbar
c:\windows\CSC\d6
c:\windows\IsUn0410.exe
c:\windows\system32\_000125_.tmp.dll
c:\windows\system32\AF15BDAEX.dll
c:\windows\system32\f3PSSavr.scr
c:\windows\system32\system
c:\windows\system32\systeminfo.dll
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MYWEBSEARCHSERVICE
.
.
((((((((((((((((((((((((( Files Creati Da 2011-10-27 al 2011-11-27 )))))))))))))))))))))))))))))))))))
.
.
2011-11-26 17:07 . 2011-11-26 19:46 -------- d--h--w- c:\documents and settings\Utente\Dati applicazioni\drivers
2011-11-26 13:00 . 2011-11-26 13:00 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2011-11-26 13:00 . 2011-11-26 13:00 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-11-26 13:00 . 2011-11-26 13:00 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-11-26 13:00 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-20 20:40 . 2011-11-20 20:40 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\JockerSoft
2011-11-20 20:39 . 2011-11-20 20:39 -------- d-----w- c:\programmi\JockerSoft
2011-11-20 20:36 . 2011-11-20 20:36 -------- d-----w- c:\programmi\AVIcodec
2011-11-20 18:22 . 2011-11-20 18:22 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\NeroDigital(TM)
2011-11-16 20:45 . 2011-11-16 20:45 -------- d-----w- c:\programmi\iPod
2011-11-14 09:15 . 2011-11-14 22:52 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\BitComet
2011-11-11 19:26 . 2011-11-11 19:26 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PhotoSi
2011-11-11 16:08 . 2007-03-12 15:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2011-11-09 14:01 . 2011-11-09 14:01 -------- d-----w- c:\programmi\ImageShack Uploader
2011-11-08 23:09 . 2011-11-08 23:09 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\IObit
2011-11-08 22:29 . 2011-11-08 22:29 388096 ----a-r- c:\documents and settings\Utente\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-08 22:29 . 2011-11-08 22:29 -------- d-----w- c:\programmi\Trend Micro
2011-11-08 20:19 . 2011-11-05 07:25 134104 ----a-w- c:\programmi\Mozilla Firefox\components\browsercomps.dll
2011-11-08 20:19 . 2011-11-05 07:25 89048 ----a-w- c:\programmi\Mozilla Firefox\libEGL.dll
2011-11-08 20:19 . 2011-11-05 07:25 801752 ----a-w- c:\programmi\Mozilla Firefox\mozsqlite3.dll
2011-11-08 20:19 . 2011-11-05 07:25 478168 ----a-w- c:\programmi\Mozilla Firefox\libGLESv2.dll
2011-11-08 20:19 . 2011-11-05 07:25 1989592 ----a-w- c:\programmi\Mozilla Firefox\mozjs.dll
2011-11-08 20:19 . 2011-11-05 07:25 15832 ----a-w- c:\programmi\Mozilla Firefox\mozalloc.dll
2011-11-08 20:19 . 2011-11-05 03:20 2106216 ----a-w- c:\programmi\Mozilla Firefox\D3DCompiler_43.dll
2011-11-08 20:19 . 2011-11-05 03:20 1998168 ----a-w- c:\programmi\Mozilla Firefox\d3dx9_43.dll
2011-11-02 21:52 . 2011-11-02 21:52 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Apple Computer
2011-11-01 18:27 . 2011-11-01 18:28 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Download Manager
2011-11-01 18:12 . 2011-11-01 18:12 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\PhotoSi
2011-10-31 18:14 . 2011-10-31 18:14 -------- d-----w- c:\documents and settings\All Users\Dassault Systemes
2011-10-31 18:14 . 2011-10-31 18:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Dassault Systemes
2011-10-31 18:14 . 2011-10-31 18:14 -------- d-----w- c:\programmi\Dassault Systemes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-17 09:21 . 2011-06-04 17:58 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-10 22:28 . 2009-10-11 15:30 284340 ----a-w- c:\documents and settings\Utente\Dati applicazioni\mdbu.bin
2011-10-25 14:33 . 2003-10-17 11:44 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-12 12:10 . 2011-10-12 12:10 483200 ----a-w- c:\windows\system32\drivers\AF15BDA.SYS
2011-10-10 14:22 . 2009-10-09 15:57 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 03:06 . 2010-07-24 18:56 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-03 00:37 . 2009-10-10 07:55 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2004-08-19 13:39 603136 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 613888 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-08-31 10:00 23040 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-08-31 10:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-13 13:34 . 2009-10-16 12:52 29712 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2011-09-11 16:54 . 2011-09-09 14:35 551424 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\VWDExpress\10.0\1040\ResourceCache.dll
2011-09-06 14:10 . 2004-08-19 13:31 1858944 ----a-w- c:\windows\system32\win32k.sys
2010-10-16 23:50 . 2011-01-26 12:46 3056008 ----a-w- c:\programmi\File comuni\AskToolbarInstaller.exe
2010-01-26 22:11 . 2011-01-26 12:46 444283 ----a-w- c:\programmi\File comuni\WinPcapNmap.exe
2011-11-05 07:25 . 2011-11-08 20:19 134104 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\NBHShellExt]
@="{8D2223A2-B3C6-4e32-B096-CDD11F628C60}"
[HKEY_CLASSES_ROOT\CLSID\{8D2223A2-B3C6-4e32-B096-CDD11F628C60}]
2009-05-08 15:14 97816 ----a-w- c:\programmi\Nero\Nero 9\InCD\NBHshx.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeUpdater"="c:\programmi\File comuni\Adobe\Updater5\AdobeUpdater.exe" [2011-05-13 2356088]
"Device Detection"="c:\programmi\PhotoSi\MyComposer\dd.exe" [2011-10-13 787128]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2011-10-25 2078048]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-12 196608]
"UnlockerAssistant"="c:\programmi\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2011-06-09 254696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2011-11-12 421736]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2011-10-24 421888]
"TkBellExe"="c:\programmi\real\realplayer\update\realsched.exe" [2011-10-25 273528]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Logitech SetPoint.lnk - c:\programmi\Logitech\SetPoint\SetPoint.exe [2009-10-20 813584]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-06-22 10:50 12536 ----a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 11:28 72208 ----a-w- c:\programmi\File comuni\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Windows Search.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Utente^Menu Avvio^Programmi^Esecuzione automatica^Ritaglio schermata e avvio di OneNote 2007.lnk]
path=c:\documents and settings\Utente\Menu Avvio\Programmi\Esecuzione automatica\Ritaglio schermata e avvio di OneNote 2007.lnk
backup=c:\windows\pss\Ritaglio schermata e avvio di OneNote 2007.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-06-07 09:23 136176 ----atw- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44 31072 ----a-w- c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2010-06-09 18:55 49208 ----a-w- c:\programmi\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2009-05-08 15:14 1116696 ----a-w- c:\programmi\Nero\Nero 9\InCD\InCD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-11-12 23:24 421736 ----a-w- c:\programmi\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBHGui]
2009-05-08 15:14 1593880 ----a-w- c:\programmi\Nero\Nero 9\InCD\NBHGui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-12-21 09:53 1483264 ----a-w- c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 13:28 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMASH]
2009-10-30 10:00 229411 ----a-w- c:\programmi\Ashampoo\Ashampoo Office 2010\Smash.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\DNA\\btdna.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgam.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Philips\\Wi-Fi MediaConnect\\Wi-Fi MediaConnect.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\File comuni\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22071:TCP"= 22071:TCP:BitComet 22071 TCP
"22071:UDP"= 22071:UDP:BitComet 22071 UDP
.
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [16/10/2009 13.52.00 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [16/10/2009 13.51.58 52872]
R0 MacOpen;MacOpen;c:\windows\system32\drivers\MacOpen.sys [27/10/2011 17.49.40 176709]
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [20/05/2008 8.32.40 15328]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [16/10/2009 13.52.13 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [16/10/2009 13.51.56 243152]
R2 AsSysCtrlService;ASUS System Control Service;c:\programmi\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [10/10/2009 7.42.57 86016]
R2 avg9wd;AVG WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [22/06/2010 11.50.41 308136]
R2 avgfws9;AVG Firewall;c:\programmi\AVG\AVG9\avgfws9.exe [22/06/2010 11.50.36 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\programmi\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [22/06/2010 11.50.37 5897808]
R2 NeroRegInCDSrv;Nero Registry InCD Service;c:\programmi\Nero\Nero 9\InCD\NBHRegInCDSrv.exe [08/05/2009 16.14.28 109080]
R2 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool;c:\programmi\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [03/12/2010 11.44.50 196912]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [27/01/2010 3.09.02 50704]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\programmi\Macrium\Reflect\ReflectService.exe [25/08/2009 11.16.36 220128]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [16/10/2009 13.51.42 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [16/10/2009 13.51.55 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [16/10/2009 13.51.55 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [16/10/2009 13.51.53 26192]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [11/10/2009 17.16.21 47360]
R3 WFMC_VAD;WFMC Virtual Audio Device (WDM);c:\windows\system32\drivers\wfmcvad.sys [11/02/2011 20.52.27 19328]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12.16.28 130384]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [25/01/2010 16.58.17 135664]
S2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [03/11/2006 18.19.58 13592]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\Utente\IMPOST~1\Temp\ALSysIO.sys --> c:\docume~1\Utente\IMPOST~1\Temp\ALSysIO.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [16/10/2009 13.51.42 30104]
S3 cpuz135;cpuz135;\??\c:\docume~1\Utente\IMPOST~1\Temp\cpuz135\cpuz135_x32.sys --> c:\docume~1\Utente\IMPOST~1\Temp\cpuz135\cpuz135_x32.sys [?]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [25/01/2010 16.58.17 135664]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [25/08/2009 11.16.16 32224]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12.16.28 753504]
S4 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\programmi\AVG\AVG9\Toolbar\ToolbarBroker.exe --> c:\programmi\AVG\AVG9\Toolbar\ToolbarBroker.exe [?]
S4 MSSQLServerADHelper100;Servizio SQL Server Active Directory Helper;c:\programmi\Microsoft SQL Server\100\Shared\sqladhlp.exe [03/04/2010 19.56.08 44896]
S4 RsFx0150;RsFx0150 Driver;c:\windows\system32\drivers\RsFx0150.sys [03/04/2010 10.02.54 240608]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\programmi\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [03/04/2010 19.56.08 367456]
S4 UPnPService;UPnPService;c:\programmi\File comuni\MAGIX Shared\UPnPService\UPnPService.exe [15/09/2010 23.12.00 548864]
.
--- Altri Servizi/Drivers In Memoria ---
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-04-13 13:08 451872 ----a-w- c:\programmi\File comuni\LightScribe\LSRunOnce.exe
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-25 15:58]
.
2011-11-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-25 15:58]
.
2011-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1592454029-839522115-1003Core.job
- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2011-07-05 09:23]
.
2011-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1592454029-839522115-1003UA.job
- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2011-07-05 09:23]
.
2009-10-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
.
2011-11-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
2011-11-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-1592454029-839522115-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-11-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-1592454029-839522115-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-11-27 c:\windows\Tasks\User_Feed_Synchronization-{5F65A2C9-5399-48D8-927E-6E637A1FAF9C}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Aggiungi a PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Append Link Target to Existing PDF - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti destinazione link in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti destinazione link in file PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Converti i link selezionati in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti i link selezionati in file PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in Adobe PDF - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Converti selezione in file PDF esistente - c:\programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Scarica con Free Download Manager - file://c:\programmi\Free Download Manager\dllink.htm
IE: Scarica i video con Free Download Manager - file://c:\programmi\Free Download Manager\dlfvideo.htm
IE: Scarica selezionati con Free Download Manager - file://c:\programmi\Free Download Manager\dlselected.htm
IE: Scarica tutto con Free Download Manager - file://c:\programmi\Free Download Manager\dlall.htm
IE: Scarica tutto usando BitComet - c:\documents and settings\Utente\Desktop\BitComet_1.30\BitComet.exe/AddAllLink.htm
IE: Scarica usando &BitComet - c:\documents and settings\Utente\Desktop\BitComet_1.30\BitComet.exe/AddLink.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\7iby2j0y.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&appid=242&systemid=101&sr=0&q=
FF - prefs.js: network.proxy.type - 0
.
.
------- Associazioni dei file -------
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Toolbar-10 - (no file)
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Acrobat Assistant 8 - c:\programmi\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
MSConfigStartUp-Adobe Acrobat Speed Launcher - c:\programmi\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
MSConfigStartUp-swg - c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-TurboV - c:\program files\ASUS\TurboV\TurboV.exe
AddRemove-PhotoRecord - c:\windows\IsUn0410.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Dati applicazioni\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-11-27 10:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\08\02\10\0c\07\14?"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140710900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(1160)
c:\programmi\file comuni\logitech\bluetooth\LBTWlgn.dll
c:\programmi\file comuni\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(4468)
c:\windows\system32\WININET.dll
c:\programmi\Unlocker\UnlockerHook.dll
c:\programmi\Logitech\SetPoint\lgscroll.dll
c:\programmi\Nero\Nero 9\InCD\NBHshx.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\programmi\Windows Desktop Search\deskbar.dll
c:\programmi\Windows Desktop Search\it-it\dbres.dll.mui
c:\programmi\Windows Desktop Search\dbres.dll
c:\programmi\Windows Desktop Search\wordwheel.dll
c:\programmi\Windows Desktop Search\it-it\msnlExtRes.dll.mui
c:\programmi\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\programmi\Sandboxie\SbieSvc.exe
c:\programmi\Nero\Nero 9\InCD\InCDSrv.exe
c:\programmi\AVG\AVG9\avgchsvx.exe
c:\programmi\AVG\AVG9\avgrsx.exe
c:\programmi\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\RUNDLL32.EXE
c:\programmi\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
c:\programmi\File comuni\Logishrd\KHAL2\KHALMNPR.EXE
c:\programmi\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\crypserv.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\programmi\AVG\AVG9\avgam.exe
c:\programmi\AVG\AVG9\avgnsx.exe
c:\program files\Conversions Plus\FORMATM.EXE
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\programmi\File comuni\Nero\Nero BackItUp 4\NBService.exe
c:\programmi\Photodex\ProShowProducer\ScsiAccess.exe
c:\programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\programmi\UPHClean\uphclean.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Ora fine scansione: 2011-11-27 10:43:35 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-11-27 09:43
.
Pre-Run: 942.739.316.736 byte disponibili
Post-Run: 944.759.721.984 byte disponibili
.
- - End Of File - - BBE55499128855866E930D3BD871C735