r16 ha scritto:Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.
Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exeSalvalo sul
desktop.
Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione
è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt.
Postalo qui.
ECCOLO:
ComboFix 09-06-13.03 - Marco 14/06/2009 0.21.04.3 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.39.1040.18.1022.509 [GMT 2:00]
Eseguito da: c:\users\Marco\Documents\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\lurrwbjp.job
.
((((((((((((((((((((((((( Files Creati Da 2009-05-13 al 2009-06-13 )))))))))))))))))))))))))))))))))))
.
2009-06-11 21:57 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-11 21:57 . 2009-03-24 14:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-11 21:57 . 2009-06-11 21:57 -------- d-----w- c:\programdata\Avira
2009-06-11 21:57 . 2009-06-11 21:57 -------- d-----w- c:\program files\Avira
2009-06-11 21:51 . 2009-06-11 21:51 -------- d-----w- c:\programdata\Avg7
2009-06-10 10:20 . 2009-04-21 11:55 2033152 ----a-w- c:\windows\system32\win32k.sys
2009-06-10 10:20 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
2009-06-10 10:20 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-06-08 08:57 . 2009-06-09 10:37 -------- d-----w- c:\users\Marco\io&minu
2009-05-30 22:42 . 2009-05-30 22:47 -------- d-----w- c:\users\Marco\cellulare marco
2009-05-30 18:19 . 2009-06-08 09:00 -------- d-----w- c:\users\Marco\vita mia
2009-05-22 09:55 . 2009-05-22 09:55 -------- d-----w- c:\windows\system32\IOSUBSYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-13 13:58 . 2009-01-11 15:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-13 13:57 . 2009-05-05 17:29 3371383 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-13 12:27 . 2008-01-10 08:58 -------- d-----w- c:\program files\eMule
2009-06-11 04:08 . 2007-10-31 18:36 -------- d-----w- c:\programdata\Microsoft Help
2009-06-04 17:40 . 2008-02-15 14:18 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-05-31 01:49 . 2008-11-03 00:33 -------- d-----w- c:\users\Marco\AppData\Roaming\uTorrent
2009-05-26 11:20 . 2009-01-11 15:09 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 11:19 . 2009-01-11 15:09 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-25 18:50 . 2008-01-10 18:21 -------- d-----w- c:\program files\Nokia
2009-05-20 21:15 . 2009-04-26 09:57 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-05-13 22:13 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-26 10:02 . 2009-04-26 10:02 -------- d-----w- c:\users\Marco\AppData\Roaming\Samsung
2009-04-26 09:56 . 2007-10-31 18:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-04-26 09:46 . 2009-04-26 09:46 -------- d-----w- c:\program files\Samsung
2009-04-26 09:45 . 2008-10-05 09:32 -------- d-----w- c:\program files\Common Files\Adobe
2009-04-24 16:05 . 2009-06-10 10:19 827904 ----a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-10 10:19 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-10 10:19 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-04-20 17:23 . 2008-01-10 18:20 -------- d-----w- c:\programdata\Installations
2009-04-20 17:21 . 2009-04-20 17:21 3351812 ----a-w- c:\programdata\Installations\{EF4F620F-F295-41D7-92C0-6B635709C850}\Installer\CommonCustomActions\msxml6Exec.exe
2009-04-20 17:21 . 2009-04-20 17:21 36864 ----a-w- c:\programdata\Installations\{EF4F620F-F295-41D7-92C0-6B635709C850}\Installer\CommonCustomActions\Sleep.exe
2009-04-20 17:21 . 2009-04-20 17:21 3181612 ----a-w- c:\programdata\Installations\{EF4F620F-F295-41D7-92C0-6B635709C850}\Installer\CommonCustomActions\vcredistExec.exe
2009-04-20 17:20 . 2009-04-20 17:21 24521320 ----a-w- c:\programdata\Installations\{EF4F620F-F295-41D7-92C0-6B635709C850}\NokiaSoftwareUpdaterSetup_1.4.98IT.exe
2009-04-20 16:26 . 2009-04-20 16:26 8192 ----a-w- c:\programdata\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-04-20 16:26 . 2009-04-20 16:26 61440 ----a-w- c:\programdata\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-04-20 16:26 . 2009-04-20 16:26 10240 ----a-w- c:\programdata\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-04-20 16:24 . 2006-11-06 01:52 665464 ----a-w- c:\windows\system32\perfh010.dat
2009-04-20 16:24 . 2006-11-06 01:52 121096 ----a-w- c:\windows\system32\perfc010.dat
2009-04-20 16:23 . 2009-04-20 16:26 34447128 ----a-w- c:\programdata\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_ita.exe
2009-03-17 03:38 . 2009-04-17 17:28 13824 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-17 17:28 24064 ----a-w- c:\windows\system32\amxread.dll
2007-08-29 09:07 . 2007-03-06 10:32 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-04-23 4435968]
c:\users\Marco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FreePOPs.lnk - c:\program files\FreePOPs\freepopsd.exe [2007-11-17 49152]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-11-3 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3461380361-3916217333-806040310-1003]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{420F1B7A-5344-4D94-85A0-3E0531689767}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{A84FC36D-B7D8-451B-86DA-E7D924E88930}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{DF96124E-BB35-4018-A869-2A4CF01E3AAA}"= TCP:4672:Emule UDP
"{5AFA74E0-3DB6-48A6-BAC1-612D8FAD0EA8}"= UDP:4662:Emule TCP
"{9710076C-4179-458D-92D2-431A0458B644}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{F9AA9B36-AC07-4A81-B883-3BA415984441}"= UDP:c:\program files\FreePOPs\freepopsd.exe:FreePOPs
"{E5DC226B-F7A2-4362-B1CE-497DA98591A9}"= TCP:c:\program files\FreePOPs\freepopsd.exe:FreePOPs
"TCP Query User{9570C4C0-B3C5-412F-ACD6-CF09B6F2AB49}c:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= UDP:c:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"UDP Query User{40347A36-1F44-42EF-A910-0C67321880D5}c:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= TCP:c:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"TCP Query User{20F24DC4-BECF-4F89-AD3A-EAFA4F516F4F}c:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= UDP:c:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"UDP Query User{F6B9B592-BE78-4959-9A92-14A3E0626362}c:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= TCP:c:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"{20874C13-5A95-4E58-85A4-B8E8331CF5C4}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{3740886E-2BB9-4147-8BB1-316BB1FA083E}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"TCP Query User{8005B82F-7A5D-4B3A-A960-497FC632DD9C}c:\\program files\\sports interactive\\football manager 2008\\fm (2).exe"= UDP:c:\program files\sports interactive\football manager 2008\fm (2).exe:Football Manager 2008
"UDP Query User{B0790109-F6C5-44DF-8771-2E52F630B093}c:\\program files\\sports interactive\\football manager 2008\\fm (2).exe"= TCP:c:\program files\sports interactive\football manager 2008\fm (2).exe:Football Manager 2008
"TCP Query User{D37F2C8D-78E6-41E4-ADF7-B40636846CCE}c:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= UDP:c:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"UDP Query User{69EFB253-8E07-422F-A27E-A2A4F3A3B1BC}c:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= TCP:c:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"TCP Query User{6EA28D51-1D03-4B36-9208-7B7CCE350340}c:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= UDP:c:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"UDP Query User{8E9834D3-4DFF-4BE6-95B9-5B78C9BFCF89}c:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= TCP:c:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"TCP Query User{761996CC-2EEF-498B-AC4E-AB22DB8018B1}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{95771CD2-9737-4C19-8AD8-5689C8266BCB}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"{B1DBDC82-05D0-46C5-B7EE-FCC14302208A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{0D0C2935-44A6-49C6-A034-81BA1B1CF63A}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{F4084069-FCD6-4010-BA8C-4B4FACD9ACA6}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{26FB2B81-2DF5-427A-99CE-9EC6336C97FC}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{94D07FE7-7C79-4750-A8BB-1A85EBD5F49D}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\System32\drivers\xfilt.sys [01/11/2007 5.03.08 17920]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [28/03/2009 13.45.24 1153368]
S3 digitran;Microsoft Input Tablet;c:\windows\System32\drivers\digitran.sys [01/11/2007 5.03.22 23528]
S4 smscir;SMSCIR Infrared Receiver;c:\windows\System32\drivers\smscir.sys [01/11/2007 5.03.50 62752]
S4 vhiddigi;Microsoft HID Digitizer Driver;c:\windows\System32\drivers\vhiddigi.sys [01/11/2007 5.03.37 23936]
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-13 c:\windows\Tasks\User_Feed_Synchronization-{D7B70733-77C3-4D66-8CEB-0CB058008DFB}.job
- c:\windows\system32\msfeedssync.exe [2008-08-02 07:33]
.
.
------- Scansione supplementare -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-14 00:25
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.032"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ani"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.bay"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Bitmap"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.bw"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.cs1"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.cur"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.dcx"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.dib"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.djv"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.djvu"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.emf"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.eps"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.erf"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.fff"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.fpx"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Gif"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.hdr"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.icl"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.icn"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ico"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.iff"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ilbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.int"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.inta"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.iw4"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.j2c"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.j2k"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jfif"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jif"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jp2"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jpc"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jpk"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.jpx"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.lbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.mef"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.mos"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pcd"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pct"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pcx"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pgm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pic"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pict"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.pix"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Png"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ppm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.psd"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.psp"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ras"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.rgb"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.rgba"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.rle"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.rsb"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.sgi"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.tga"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.thm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Tiff"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (S-1-5-21-3461380361-3916217333-806040310-1003)
@Denied: (2) (LocalSystem)
"Progid"="PhotoViewer.FileAssoc.Tiff"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ttc"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.ttf"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.wbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.wbmp"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.wmf"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.xbm"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.xif"
[HKEY_USERS\S-1-5-21-3461380361-3916217333-806040310-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.0.xpm"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2009-06-13 0.27.58
ComboFix-quarantined-files.txt 2009-06-13 22:27
ComboFix2.txt 2009-01-11 19:13
Pre-Run: 140.487.393.280 byte disponibili
Post-Run: 140.526.137.344 byte disponibili
425 --- E O F --- 2009-06-12 09:11