Ecco il log di Combofix come mi avevi richiesto:
ComboFix 09-11-05.05 - principale 06/11/2009 14.04.28.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1396 [GMT 1:00]
Eseguito da: c:\documents and settings\principale\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\PRINCI~1\IMPOST~1\Temp\IadHide5.dll
c:\documents and settings\principale\Impostazioni locali\Temp\IadHide5.dll
.
((((((((((((((((((((((((( Files Creati Da 2009-10-06 al 2009-11-06 )))))))))))))))))))))))))))))))))))
.
2009-11-06 12:47 . 2009-11-06 12:57 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Coyotes Tale
2009-11-06 12:45 . 2009-11-06 12:47 -------- d-----w- c:\programmi\Coyote's Tale - Fire and Water
2009-11-06 08:54 . 2009-10-23 07:43 2064152 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgcorex.dll
2009-11-05 07:24 . 2009-10-23 07:43 2025752 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgtray.exe
2009-11-04 21:33 . 2009-11-05 18:50 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\TMInc
2009-11-04 21:31 . 2009-11-04 21:31 -------- d-----w- c:\windows\Treasure Masters Inc
2009-11-04 10:17 . 2009-11-04 10:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PopCap
2009-11-04 10:17 . 2009-11-04 10:17 -------- d-----w- c:\programmi\Amazing Adventures The Lost Tomb
2009-11-03 09:29 . 2009-11-03 09:29 -------- d-----w- c:\documents and settings\principale\Impostazioni locali\Dati applicazioni\JollyBear
2009-11-03 09:29 . 2009-11-03 09:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\JollyBear
2009-11-03 09:28 . 2009-11-03 09:28 -------- d-----w- c:\windows\Big City Adventure - New York
2009-10-30 20:34 . 2009-11-02 10:03 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Gold Casual Games
2009-10-30 20:34 . 2009-11-02 10:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Gold Casual Games
2009-10-29 05:59 . 2009-11-05 15:42 -------- d-----w- C:\Nostale(IT)
2009-10-28 21:10 . 2009-10-28 21:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AdventureChronicles1
2009-10-28 11:47 . 2009-10-28 11:47 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\MysteryStudio
2009-10-28 11:33 . 2009-10-28 11:33 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\SerpentOfIsis
2009-10-27 12:19 . 2009-10-27 12:19 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Big Fish Games
2009-10-27 12:19 . 2009-10-27 12:19 -------- d-----w- c:\windows\Mystery in London
2009-10-26 12:52 . 2009-11-02 12:27 -------- d-----w- c:\programmi\Games
2009-10-26 11:41 . 2009-10-26 11:41 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\cerasus
2009-10-25 15:31 . 2009-10-26 20:31 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\cerasus.media
2009-10-25 15:30 . 2009-10-25 15:30 -------- d-----w- c:\windows\Mystery Stories-Island of Hope
2009-10-25 15:22 . 2009-10-25 15:22 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Little Games Company
2009-10-25 15:22 . 2009-10-25 15:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Little Games Company
2009-10-24 13:04 . 2009-10-24 13:04 -------- d-----w- c:\windows\10 Days Under The Sea
2009-10-24 11:12 . 2009-10-24 11:12 -------- d--h--w- c:\windows\PIF
2009-10-23 11:31 . 2009-10-23 11:31 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Total Eclipse
2009-10-22 18:15 . 2009-10-22 18:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\IntDreams
2009-10-22 14:39 . 2009-10-22 14:39 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-22 14:21 . 2009-10-22 14:21 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-22 14:19 . 2009-10-22 14:19 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\SPORE
2009-10-21 19:30 . 2009-10-21 19:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Fashion Finder
2009-10-21 19:30 . 2009-10-22 14:19 -------- d-----w- c:\programmi\Fashion Finder - Secrets of Fashion
2009-10-21 19:24 . 2009-10-22 14:19 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Bluemfcdlog
2009-10-21 11:48 . 2009-10-21 11:48 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Friday's games
2009-10-21 10:37 . 2009-10-21 10:41 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\PlayFirst
2009-10-20 20:15 . 2009-10-20 20:15 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\casanova
2009-10-19 10:48 . 2009-10-19 10:48 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\ERS G-Studio
2009-10-18 19:27 . 2009-10-18 19:28 -------- d-----w- c:\documents and settings\principale\Impostazioni locali\Dati applicazioni\TimeParadox
2009-10-18 19:26 . 2009-10-22 14:20 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Zylom
2009-10-18 19:25 . 2006-09-26 10:03 98304 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2009-10-18 19:25 . 2006-09-26 10:03 161976 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Zylom\ZylomGamesPlayer\zylomgamesplayer.dll
2009-10-16 12:10 . 2009-10-16 12:11 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Becky Brogan
2009-10-16 12:05 . 2009-10-16 12:05 -------- d-----w- c:\windows\Becky Brogan The Mystery of Meane Manor
2009-10-14 08:28 . 2009-10-18 18:56 -------- d-----w- c:\programmi\Hidden Expedition Titanic
2009-10-13 20:02 . 2009-10-13 20:02 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\Meridian93
2009-10-13 09:36 . 2009-10-13 09:36 -------- d-----w- c:\documents and settings\principale\Impostazioni locali\Dati applicazioni\TheLostIncaProphecy
2009-10-13 09:34 . 2009-10-13 09:34 -------- d-----w- c:\programmi\The Lost Inca Prophecy
2009-10-13 09:34 . 2009-10-13 09:34 -------- d-----w- c:\windows\The Lost Inca Prophecy
2009-10-13 09:07 . 2009-10-13 09:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache
2009-10-13 08:35 . 2009-10-13 08:35 -------- d-----w- c:\windows\OceaniX
2009-10-08 15:49 . 2009-10-08 15:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\GameHouse
2009-10-08 15:42 . 2009-10-22 17:47 -------- d-----w- c:\programmi\RealArcade
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-06 13:13 . 2009-04-17 07:29 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-11-06 07:59 . 2009-06-05 11:43 -------- d-----w- c:\programmi\Spyware Doctor
2009-10-25 07:53 . 2004-08-30 20:00 90814 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 07:53 . 2004-08-30 20:00 504426 ----a-w- c:\windows\system32\perfh010.dat
2009-10-24 11:02 . 2009-02-05 14:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Babylon
2009-10-22 19:48 . 2008-11-14 21:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Sandlot Games
2009-10-22 14:20 . 2008-11-12 10:48 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-10-18 19:25 . 2009-07-15 09:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Zylom
2009-10-17 17:31 . 2009-03-01 15:57 7308 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-10-11 19:26 . 2009-01-07 09:08 -------- d-----w- c:\documents and settings\principale\Dati applicazioni\GameHouse
2009-10-08 15:49 . 2009-02-03 11:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Trymedia
2009-10-08 15:23 . 2008-11-12 11:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-09-27 10:48 . 2009-09-24 16:47 -------- d-----w- c:\programmi\BitTorrent Fastest Tool
2009-09-16 11:11 . 2008-11-12 16:57 69648 ----a-w- c:\documents and settings\principale\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-16 11:10 . 2009-09-16 11:10 -------- d-----w- c:\programmi\Microsoft
2009-09-16 11:10 . 2009-09-16 11:10 -------- d-----w- c:\programmi\Windows Live
2009-09-16 11:02 . 2009-09-04 11:12 3096 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-09-16 10:55 . 2009-09-16 10:55 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-09-12 07:57 . 2009-09-12 07:57 -------- d-----w- c:\programmi\PowerISO
2009-09-11 18:13 . 2009-09-11 18:13 143736 ----a-w- c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache\Upgrade\stub\hidden-expedition-titanic_s1_l1_gF1081T1L1_d661277181.exe
2009-09-11 18:12 . 2009-09-11 18:12 2541480 ----a-w- c:\documents and settings\All Users\Dati applicazioni\BigFishGamesCache\Upgrade\clientinstaller\bfgsetup_s1_l1.exe
2009-09-11 14:17 . 2004-08-30 20:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 09:12 . 2009-09-10 09:12 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-04 21:03 . 2004-08-30 20:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 08:53 . 2009-01-09 11:16 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-08-29 07:56 . 2004-08-30 20:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-30 20:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2008-10-22 11:01 . 2009-09-24 16:47 724568 ----a-w- c:\programmi\BitTorrent Fastest Toolvlnet3.com_Installer.exe
2004-03-11 12:27 . 2008-11-12 10:48 40960 ----a-w- c:\programmi\Uninstall_CDS.exe
2009-03-01 15:59 . 2009-03-01 15:57 56 --sh--r- c:\windows\system32\B14B0ECACF.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 07:56 1062144 ----a-w- c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"LDM"="c:\programmi\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2009-03-04 36864]
"AlcoholAutomount"="c:\documents and settings\principale\Documenti\Alcohol 120\axcmd.exe" [2009-04-24 203928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-05 2028312]
"LogitechCommunicationsManager"="c:\programmi\File comuni\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LVCOMSX"="c:\programmi\File comuni\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-06-06 148888]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"PWRISOVM.EXE"="c:\programmi\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]
"ISTray"="c:\programmi\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"combofix"="c:\combofix\CF7683.exe" [2009-11-06 398336]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-09-12 16264192]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2006-03-28 94208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio rapido HP Photosmart Premier.lnk - c:\programmi\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 13:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [13/11/2008 14.49.20 12552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [05/06/2009 12.52.27 130936]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [12/11/2008 16.34.06 11264]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/11/2008 14.49.17 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/11/2008 14.49.20 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [13/11/2008 14.49.04 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [13/11/2008 14.49.04 297752]
R2 sdAuxService;PC Tools Auxiliary Service;c:\programmi\Spyware Doctor\pctsAuxs.exe [05/06/2009 12.52.09 348752]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - MBR
*Deregistered* - mbr
*Deregistered* - mchInjDrv
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-06 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\programmi\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-06 14:13
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys xfilt.sys ACPI.sys hal.dll sfsync02.sys atapi.sys spzu.sys >>UNKNOWN [0x8A6FF938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netatapi.sys @ 0x0 0x0 bytes
\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF771FD60 sfsync02.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF7978B40 atapi.sys
\Driver\atapi IRP hooks detected !
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1547161642-152049171-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:6c,7b,75,18,b4,c3,f3,4c,18,04,03,58,e6,4f,7a,d3,d8,d2,5d,df,33,44,b6,
cf,3c,b1,0b,3b,0f,31,6e,7a,95,22,87,55,ac,17,7c,e6,6f,ef,af,a8,5e,8c,e5,e7,\
"??"=hex:8f,dc,f4,61,ef,f9,30,3d,ec,8a,26,9e,3d,7b,e4,ed
[HKEY_USERS\S-1-5-21-1547161642-152049171-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:9d,73,55,c7,6d,0b,1f,e6,be,62,36,dc,86,12,bb,39,b3,25,06,b3,29,
78,bd,da,1e,c7,72,a9,67,85,aa,63,13,e6,1a,e0,bc,08,d4,81,d2,51,2b,ed,75,35,\
"rkeysecu"=hex:ed,70,18,ba,75,13,ba,71,ba,44,64,fb,bf,8c,cb,4e
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(992)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Spyware Doctor\pctsSvc.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\documents and settings\principale\Documenti\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\programmi\AVG\AVG8\avgcsrvx.exe
c:\programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\programmi\HP\Digital Imaging\bin\hpqimzone.exe
c:\programmi\Logitech\QuickCam10\COCIManager.exe
c:\programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Ora fine scansione: 2009-11-06 14.18.59 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-11-06 13:18
ComboFix2.txt 2009-06-05 23:31
Pre-Run: 159.308.828.672 byte disponibili
Post-Run: 159.320.838.144 byte disponibili
- - End Of File - - C4106B525E90FA8E4FD9B6552EC17F0B