Fatto, ecco il log: (comunque oggi il pc va molto bene!! non è più lento)
ComboFix 10-01-04.01 - Francesca 07/01/2010 17.44.22.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.2046.667 [GMT 1:00]
Eseguito da: e:\documents and settings\Francesca\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\$recycle.bin\S-1-5-21-2671070814-4219602357-1626589432-1000
e:\documents and settings\Francesca\Documenti\salvataggio registro.reg
e:\programmi\WinPCap
e:\programmi\WinPCap\rpcapd.exe
e:\recycled\Recycled
e:\windows\AegisP.inf
e:\windows\system32\driVERs\khend.sys
e:\windows\system32\drivers\npf.sys
e:\windows\system32\Packet.dll
e:\windows\system32\pthreadVC.dll
e:\windows\system32\WanPacket.dll
e:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_npf
-------\Legacy_khend
-------\Service_khend
((((((((((((((((((((((((( Files Creati Da 2009-12-07 al 2010-01-07 )))))))))))))))))))))))))))))))))))
.
2010-01-06 21:20 . 2010-01-06 21:20 -------- d-----w- e:\documents and settings\Francesca\Dati applicazioni\Malwarebytes
2010-01-06 21:19 . 2009-12-30 13:55 38224 ----a-w- e:\windows\system32\drivers\mbamswissarmy.sys
2010-01-06 21:19 . 2010-01-06 21:19 -------- d-----w- e:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes
2010-01-06 21:19 . 2009-12-30 13:54 19160 ----a-w- e:\windows\system32\drivers\mbam.sys
2010-01-04 14:14 . 2010-01-06 21:19 -------- d-----w- e:\programmi\Malwarebytes' Anti-Malware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-07 16:56 . 2009-09-04 17:03 -------- d-----w- e:\documents and settings\Francesca\Dati applicazioni\Dropbox
2010-01-07 16:44 . 2007-10-27 15:20 -------- d-----w- e:\documents and settings\Francesca\Dati applicazioni\Skype
2010-01-07 15:08 . 2008-06-27 13:30 -------- d-----w- e:\documents and settings\Francesca\Dati applicazioni\skypePM
2010-01-07 08:21 . 2008-11-07 08:56 -------- d-----w- e:\documents and settings\All Users.WINDOWS\Dati applicazioni\avg8
2010-01-05 22:43 . 2007-10-27 10:52 -------- d-----w- e:\programmi\SUPERAntiSpyware
2010-01-04 16:35 . 2007-10-27 11:11 -------- d-----w- e:\programmi\Spybot - Search & Destroy
2010-01-04 14:23 . 2009-06-10 15:24 -------- d-----w- e:\programmi\Flock
2009-12-22 07:21 . 2009-12-12 07:56 2066200 ----a-w- e:\documents and settings\All Users.WINDOWS\Dati applicazioni\avg8\update\backup\avgcorex.dll
2009-12-18 11:39 . 2009-11-25 20:27 79488 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-17 20:10 . 2001-08-31 12:00 79712 ----a-w- e:\windows\system32\perfc010.dat
2009-12-17 20:10 . 2001-08-31 12:00 479418 ----a-w- e:\windows\system32\perfh010.dat
2009-12-15 09:01 . 2007-10-27 10:16 -------- d-----w- e:\documents and settings\All Users.WINDOWS\Dati applicazioni\Skype
2009-11-27 09:16 . 2009-04-01 13:59 81920 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connecthook.dll
2009-11-27 09:16 . 2009-04-01 13:59 190976 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectsprd.dll
2009-11-19 10:48 . 2009-12-08 15:01 872960 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Mozilla\Firefox\Profiles\rp4u1vl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-19 10:48 . 2009-12-08 15:01 43008 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Mozilla\Firefox\Profiles\rp4u1vl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-19 10:48 . 2009-12-08 15:01 340480 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Mozilla\Firefox\Profiles\rp4u1vl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-19 10:48 . 2009-12-08 15:01 346624 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Mozilla\Firefox\Profiles\rp4u1vl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-10-29 05:44 . 2002-09-09 11:51 664576 ----a-w- e:\windows\system32\wininet.dll
2009-10-21 06:00 . 2007-10-10 10:29 25088 ----a-w- e:\windows\system32\httpapi.dll
2009-10-21 06:00 . 2007-10-10 10:29 75776 ----a-w- e:\windows\system32\strmfilt.dll
2009-10-20 14:58 . 2007-10-10 10:29 263552 ----a-w- e:\windows\system32\drivers\http.sys
2009-10-13 10:51 . 2002-09-09 11:51 267776 ----a-w- e:\windows\system32\oakley.dll
2009-10-12 13:51 . 2002-09-09 11:51 69632 ----a-w- e:\windows\system32\raschap.dll
2009-10-12 13:51 . 2002-09-09 11:51 112640 ----a-w- e:\windows\system32\rastls.dll
2007-05-01 22:20 . 2009-09-22 13:46 39404 ----a-w- e:\programmi\Leggimi di Photoshop CS3.html
.
------- Sigcheck -------
[-] 2008-04-14 . FA94696C0727BD59E517C674CD6E7C72 . 579584 . . [5.1.2600.5512] . . e:\windows\system32\user32.dll
[-] 2008-04-14 . FA94696C0727BD59E517C674CD6E7C72 . 579584 . . [5.1.2600.5512] . . e:\windows\SoftwareDistribution\Download\fc12fb9dc078edc471023573f97c4e40\user32.dll
[7] 2007-03-08 . BAB4F995E526484A235A276E269AAF7F . 579072 . . [5.1.2600.3099] . . e:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[7] 2005-03-02 . 488019BFE2B0F9F8CD8394276D5B664A . 578048 . . [5.1.2600.2622] . . e:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[7] 2005-03-02 . 14B5D6B20467DBA209853D65D1F6A124 . 578048 . . [5.1.2600.2622] . . e:\windows\$NtUninstallKB925902$\user32.dll
[7] 2004-08-19 . 08447BDFCE5D1B1956F962602381F5C1 . 578048 . . [5.1.2600.2180] . . e:\windows\$NtUninstallKB890859$\user32.dll
[7] 2004-08-19 . 08447BDFCE5D1B1956F962602381F5C1 . 578048 . . [5.1.2600.2180] . . e:\windows\ServicePackFiles\i386\user32.dll
[-] 2002-09-09 . BB4A220B198767E1848FCD64D3F1B96C . 561152 . . [5.1.2600.1106] . . e:\windows\$NtServicePackUninstall$\user32.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "e:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "e:\programmi\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2008-02-22 57344]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 09:58 1107200 ----a-w- e:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-09-02 23:45 77824 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-09-02 23:45 77824 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-09-02 23:45 77824 ----a-w- e:\documents and settings\Francesca\Dati applicazioni\Dropbox\bin\DropboxExt.3.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="e:\programmi\Messenger\msmsgs.exe" [2004-10-13 1694208]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="e:\programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872]
"Nero PhotoShow Media Manager"="e:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2007-02-07 229376]
"SpybotSD TeaTimer"="e:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [2005-12-27 73728]
"StartCCC"="e:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"TPSMain"="TPSMain.exe" [2005-08-12 266240]
"SVPWUTIL"="e:\programmi\Toshiba\Windows Utilities\SVPWUTIL.exe" [2006-05-25 65536]
"CeEKEY"="e:\programmi\TOSHIBA\E-KEY\CeEKey.exe" [2007-07-06 651264]
"TPNF"="e:\programmi\TOSHIBA\TouchPad\TPTray.exe" [2007-06-01 53248]
"Apoint"="e:\programmi\Apoint2K\Apoint.exe" [2007-07-26 196608]
"SynTPEnh"="e:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2007-07-26 888832]
"Camera Assistant Software"="e:\programmi\Camera Assistant Software for Toshiba\traybar.exe" [2007-05-22 413696]
"IntelZeroConfig"="e:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2007-06-01 823296]
"IntelWireless"="e:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2007-06-01 974848]
"ACU"="e:\programmi\Atheros\ACU.exe" [2007-04-16 372825]
"SmoothView"="e:\programmi\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2007-05-11 143360]
"Zooming"="ZoomingHook.exe" [2005-06-06 24576]
"NDSTray.exe"="NDSTray.exe" [BU]
"TCtryIOHook"="TCtrlIOHook.exe" [2007-06-30 28672]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-05 16061440]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"HPHUPD08"="e:\programmi\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"HP Software Update"="e:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"FinePrint Dispatcher v4"="e:\windows\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe" [2000-05-01 321024]
"NeroFilterCheck"="e:\programmi\File comuni\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="e:\programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"HPUsageTracking"="e:\programmi\HP\HP UT\bin\hppusg.exe" [2007-03-07 36864]
"Omnipage"="e:\programmi\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"PCSuiteTrayApplication"="e:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-28 222720]
"Adobe Reader Speed Launcher"="e:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="e:\programmi\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
"ContentTransferWMDetector.exe"="e:\programmi\Sony\Content Transfer\ContentTransferWMDetector.exe" [2008-07-11 423200]
"SSBkgdUpdate"="e:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ISUSPM Startup"="e:\progra~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="e:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"DNS7reminder"="e:\programmi\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" [2007-04-16 259624]
"AVG8_TRAY"="e:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"QuickTime Task"="e:\programmi\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="e:\programmi\iTunes\iTunesHelper.exe" [2009-07-13 292128]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
"PcSync"="e:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]
e:\documents and settings\Francesca\Menu Avvio\Programmi\Esecuzione automatica\
Dropbox.lnk - e:\documents and settings\Francesca\Dati applicazioni\Dropbox\bin\Dropbox.exe [2009-9-3 26785147]
e:\documents and settings\All Users.WINDOWS\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Monitor.lnk - e:\programmi\TOSHIBA\Bluetooth Monitor\BtMon2.exe [2007-10-10 69632]
Kodak EasyShare software.lnk - e:\programmi\Kodak\Kodak EasyShare Software\bin\EasyShare.exe [2005-3-10 757760]
Kodak software updater.lnk - e:\programmi\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "e:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 11:41 294912 ----a-w- e:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 07:29 11952 ----a-w- e:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Programmi\\eMule\\emule.exe"=
"e:\\Programmi\\ScanSoft\\OmniPageSE\\EregIta\\NAVBrowser.exe"=
"e:\\Programmi\\Babelgum\\Babelgum.exe"=
"e:\\Programmi\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"e:\\Programmi\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"e:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"e:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"e:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"e:\\Programmi\\iTunes\\iTunes.exe"=
"e:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4296:TCP"= 4296:TCP:eMule_TCP
"46258:UDP"= 46258:UDP:eMule_UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;e:\windows\system32\drivers\avgldx86.sys [28/04/2009 8.52.28 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;e:\windows\system32\drivers\avgtdix.sys [28/04/2009 8.52.32 108552]
R1 SASDIFSV;SASDIFSV;e:\programmi\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 12.53.48 5632]
R1 SASKUTIL;SASKUTIL;e:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [27/02/2007 11.39.26 32256]
R2 avg8emc;AVG Free8 E-mail Scanner;e:\progra~1\AVG\AVG8\avgemc.exe [26/08/2009 8.29.16 908056]
R2 avg8wd;AVG Free8 WatchDog;e:\progra~1\AVG\AVG8\avgwdsvc.exe [28/04/2009 8.52.05 297752]
R2 GtDetectSc;GT Detect;e:\windows\system32\GtDetectSc.exe [09/11/2007 17.00.47 167936]
R3 videolive;videolive;e:\windows\system32\drivers\videolive.sys [08/04/2009 9.19.10 6144]
S3 GTFFBUS;GT FF BUS;e:\windows\system32\drivers\gtffbus.sys [09/11/2007 17.00.46 17024]
S3 GTMNDISIRPXP;GT M 3G+ IRP NDIS;e:\windows\system32\drivers\Gtm51Irp.sys [09/11/2007 17.00.47 115840]
S3 GTUQBUS;GT UQ BUS;e:\windows\system32\drivers\gtuqbus.sys [09/11/2007 17.00.47 34560]
S3 SASENUM;SASENUM;e:\programmi\SUPERAntiSpyware\SASENUM.SYS [16/02/2006 16.51.08 4096]
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-06 e:\windows\Tasks\AppleSoftwareUpdate.job
- e:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34]
2010-01-07 e:\windows\Tasks\HPpromotions journeysoftware.job
- e:\programmi\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe [2005-04-22 15:36]
2010-01-07 e:\windows\Tasks\SDMsgUpdate (SD).job
- e:\progra~1\SMARTD~1\Messages\SDNotify.exe [2008-12-18 05:29]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - e:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {6E09C7A5-41F8-411D-BD72-9462A3827EF9} = 137.204.1.15,137.204.24.45
FF - ProfilePath - e:\documents and settings\Francesca\Dati applicazioni\Mozilla\Firefox\Profiles\rp4u1vl5.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://it.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_it&p=
FF - component: e:\documents and settings\Francesca\Dati applicazioni\Mozilla\Firefox\Profiles\rp4u1vl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: e:\documents and settings\Francesca\Dati applicazioni\Mozilla\Firefox\Profiles\rp4u1vl5.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: e:\programmi\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: e:\programmi\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: e:\programmi\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: e:\programmi\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: e:\programmi\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: e:\programmi\Mozilla Firefox\plugins\npbabelgum.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - e:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - CHIAVI ORFANE RIMOSSE - - - -
URLSearchHooks-*{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
AddRemove-HijackThis - e:\docume~1\FRANCE~1\IMPOST~1\Temp\Rar$EX02.359\HijackThis.exe
AddRemove-ShockwaveFlash - e:\windows\system32\Macromed\Flash\FlashUtil9c.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-07 17:55
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140AC1900063D11C8EF10054038389C"="E?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(1104)
e:\programmi\SUPERAntiSpyware\SASWINLO.dll
e:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3372)
e:\docume~1\FRANCE~1\IMPOST~1\Temp\IadHide5.dll
e:\programmi\ScanSoft\OmniPageSE\ophook32.dll
e:\documents and settings\Francesca\Dati applicazioni\Dropbox\bin\DropboxExt.3.dll
e:\windows\system32\TDispVol.dll
e:\windows\system32\WPDShServiceObj.dll
e:\programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
e:\programmi\Nokia\Nokia PC Suite 6\PCSCM.dll
e:\programmi\PC Connectivity Solution\ConnAPI.DLL
e:\programmi\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_ita.nlr
e:\programmi\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
e:\windows\system32\PortableDeviceTypes.dll
e:\windows\system32\PortableDeviceApi.dll
e:\windows\system32\TPwrCfg.DLL
e:\windows\system32\TPwrReg.dll
e:\windows\system32\TPSTrace.DLL
.
------------------------ Altri processi in esecuzione ------------------------
.
e:\windows\system32\Ati2evxx.exe
e:\programmi\Intel\Wireless\Bin\S24EvMon.exe
e:\windows\system32\Ati2evxx.exe
e:\windows\system32\acs.exe
e:\windows\system32\agrsmsvc.exe
e:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
e:\programmi\Bonjour\mDNSResponder.exe
e:\programmi\TOSHIBA\ConfigFree\CFSvcs.exe
e:\programmi\Intel\Wireless\Bin\EvtEng.exe
e:\programmi\Java\jre6\bin\jqs.exe
e:\windows\system32\drivers\KodakCCS.exe
e:\programmi\Nero\Nero8\Nero BackItUp\NBService.exe
e:\windows\system32\HPZipm12.exe
e:\programmi\Intel\Wireless\Bin\RegSrvc.exe
e:\progra~1\AVG\AVG8\avgrsx.exe
e:\progra~1\AVG\AVG8\avgnsx.exe
e:\programmi\AVG\AVG8\avgcsrvx.exe
e:\programmi\Canon\CAL\CALMAIN.exe
e:\programmi\AVG\AVG8\avgcsrvx.exe
e:\windows\system32\wscntfy.exe
e:\windows\System32\wbem\wmiapsrv.exe
e:\windows\system32\TDispVol.exe
e:\windows\system32\TPSMain.exe
e:\programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
e:\windows\system32\ZoomingHook.exe
e:\programmi\TOSHIBA\ConfigFree\NDSTray.exe
e:\windows\system32\TCtrlIOHook.exe
e:\programmi\Synaptics\SynTP\SynToshiba.exe
e:\windows\RTHDCPL.EXE
e:\windows\system32\TPSBattM.exe
e:\programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
e:\programmi\Camera Assistant Software for Toshiba\CEC_MAIN.exe
e:\programmi\Intel\Wireless\Bin\Dot1XCfg.exe
e:\programmi\PC Connectivity Solution\ServiceLayer.exe
e:\programmi\File comuni\Nero\Lib\NMIndexingService.exe
e:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-07 18:03:33 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-07 17:03
Pre-Run: 13.607.002.112 byte disponibili
Post-Run: 13.845.557.248 byte disponibili
- - End Of File - - BA71B2EB281BA69F25AA5331C84ECD70