Log di Combo:
ComboFix 10-01-16.03 - entry 17/01/2010 15.07.17.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.511.224 [GMT 1:00]
Eseguito da: c:\documents and settings\entry\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\entry\Documenti\Claudia\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-6C25-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
FILE ::
"c:\programmi\ITALIA_version\tbITA1.dll"
"c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe"
"c:\windows\system32\lsdelete.exe"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmi\ITALIA_version
c:\programmi\ITALIA_version\INSTALL.LOG
c:\programmi\ITALIA_version\tbITA1.dll
c:\programmi\ITALIA_version\toolbar.cfg
c:\programmi\ITALIA_version\UNWISE.EXE
c:\programmi\ITALIA_version\UNWISE.INI
c:\programmi\Lavasoft
c:\programmi\Lavasoft\Ad-Aware\AAWAdmin.exe
c:\programmi\Lavasoft\Ad-Aware\aawapi.dll
c:\programmi\Lavasoft\Ad-Aware\AAWService.exe
c:\programmi\Lavasoft\Ad-Aware\AAWTray.exe
c:\programmi\Lavasoft\Ad-Aware\AAWWSC.exe
c:\programmi\Lavasoft\Ad-Aware\Ad-Aware.exe
c:\programmi\Lavasoft\Ad-Aware\Ad-Aware_manual_DE.chm
c:\programmi\Lavasoft\Ad-Aware\Ad-Aware_manual_EN.chm
c:\programmi\Lavasoft\Ad-Aware\Ad-Aware_manual_FR.chm
c:\programmi\Lavasoft\Ad-Aware\Ad-Aware_manual_JA.chm
c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
c:\programmi\Lavasoft\Ad-Aware\Ad-AwareCommand.exe
c:\programmi\Lavasoft\Ad-Aware\aebb.dll
c:\programmi\Lavasoft\Ad-Aware\aecore.dll
c:\programmi\Lavasoft\Ad-Aware\aeemu.dll
c:\programmi\Lavasoft\Ad-Aware\aegen.dll
c:\programmi\Lavasoft\Ad-Aware\aehelp.dll
c:\programmi\Lavasoft\Ad-Aware\aeheur.dll
c:\programmi\Lavasoft\Ad-Aware\aeoffice.dll
c:\programmi\Lavasoft\Ad-Aware\aepack.dll
c:\programmi\Lavasoft\Ad-Aware\aerdl.dll
c:\programmi\Lavasoft\Ad-Aware\aescn.dll
c:\programmi\Lavasoft\Ad-Aware\aescript.dll
c:\programmi\Lavasoft\Ad-Aware\aeset.dat
c:\programmi\Lavasoft\Ad-Aware\aevdf.dll
c:\programmi\Lavasoft\Ad-Aware\AutoLaunch.exe
c:\programmi\Lavasoft\Ad-Aware\avpal.dll
c:\programmi\Lavasoft\Ad-Aware\CEAPI.dll
c:\programmi\Lavasoft\Ad-Aware\dbghelp.dll
c:\programmi\Lavasoft\Ad-Aware\Download Guard for Internet Explorer.exe
c:\programmi\Lavasoft\Ad-Aware\Drivers\32\AAWDriverTool.exe
c:\programmi\Lavasoft\Ad-Aware\Drivers\32\DIFxAPI.dll
c:\programmi\Lavasoft\Ad-Aware\Drivers\32\lbd.cat
c:\programmi\Lavasoft\Ad-Aware\Drivers\32\lbd.inf
c:\programmi\Lavasoft\Ad-Aware\Drivers\32\lbd.sys
c:\programmi\Lavasoft\Ad-Aware\Drivers\64\AAWDriverTool.exe
c:\programmi\Lavasoft\Ad-Aware\Drivers\64\DIFxAPI.dll
c:\programmi\Lavasoft\Ad-Aware\Drivers\64\lbd.cat
c:\programmi\Lavasoft\Ad-Aware\Drivers\64\lbd.inf
c:\programmi\Lavasoft\Ad-Aware\Drivers\64\lbd.sys
c:\programmi\Lavasoft\Ad-Aware\Drivers\AAWDriverTool.exe
c:\programmi\Lavasoft\Ad-Aware\Drivers\DIFxAPI.dll
c:\programmi\Lavasoft\Ad-Aware\Drivers\lbd.cat
c:\programmi\Lavasoft\Ad-Aware\Drivers\lbd.inf
c:\programmi\Lavasoft\Ad-Aware\Drivers\lbd.sys
c:\programmi\Lavasoft\Ad-Aware\Drivers\sbapifs.cat
c:\programmi\Lavasoft\Ad-Aware\Drivers\sbapifsl.cat
c:\programmi\Lavasoft\Ad-Aware\Drivers\sbapx64.cat
c:\programmi\Lavasoft\Ad-Aware\Extras\Threat Work\ThreatWork.exe
c:\programmi\Lavasoft\Ad-Aware\GenoType.ows
c:\programmi\Lavasoft\Ad-Aware\hbedv.key
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_de-DE.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_en-US.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_es-ES.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_fr-FR.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_it-IT.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_ja-JP.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_nl-NL.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_pt-PT.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_sv-SE.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_zh-CN.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\resource_zh-TW.xml
c:\programmi\Lavasoft\Ad-Aware\Languages\ResourceAdmin.xml
c:\programmi\Lavasoft\Ad-Aware\lavalicense.dll
c:\programmi\Lavasoft\Ad-Aware\lavamessage.dll
c:\programmi\Lavasoft\Ad-Aware\Lavasoft Homepage.url
c:\programmi\Lavasoft\Ad-Aware\libapr-1.dll
c:\programmi\Lavasoft\Ad-Aware\libaprutil-1.dll
c:\programmi\Lavasoft\Ad-Aware\libavll.dll
c:\programmi\Lavasoft\Ad-Aware\lsdelete.exe
c:\programmi\Lavasoft\Ad-Aware\msvcp71.dll
c:\programmi\Lavasoft\Ad-Aware\msvcr71.dll
c:\programmi\Lavasoft\Ad-Aware\Neutralize.dll
c:\programmi\Lavasoft\Ad-Aware\pcre.dll
c:\programmi\Lavasoft\Ad-Aware\PrivacyClean.dll
c:\programmi\Lavasoft\Ad-Aware\Rebrand.dat
c:\programmi\Lavasoft\Ad-Aware\Resources.dll
c:\programmi\Lavasoft\Ad-Aware\Resources\aa11.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\aa14.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\Carbon.eGL
c:\programmi\Lavasoft\Ad-Aware\Resources\Default.eGL
c:\programmi\Lavasoft\Ad-Aware\Resources\Gold.eGL
c:\programmi\Lavasoft\Ad-Aware\Resources\Orange.eGL
c:\programmi\Lavasoft\Ad-Aware\Resources\Sedona.eGL
c:\programmi\Lavasoft\Ad-Aware\Resources\wa11.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wa11b.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wa12.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wa12b.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wa14b.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wa14i.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wt12.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wt12b.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wt16b.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wt16bi.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wt20b.efp
c:\programmi\Lavasoft\Ad-Aware\Resources\wt20bi.efp
c:\programmi\Lavasoft\Ad-Aware\RPAPI.dll
c:\programmi\Lavasoft\Ad-Aware\savapi3.dll
c:\programmi\Lavasoft\Ad-Aware\savapi3client.dll
c:\programmi\Lavasoft\Ad-Aware\Savapibridge.dll
c:\programmi\Lavasoft\Ad-Aware\ShellExt.dll
c:\programmi\Lavasoft\Ad-Aware\threatwork.exe
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\AutoStart Manager.exe
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Settings.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gbottompic.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gbottompicp.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gtoppic.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gtoppicp.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\skin.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\Thumbs.db
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\SO.dll
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\de.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\en.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\english.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\es.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\fr.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\it.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\ja.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\nl.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\pr.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\russian.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\zh-cmn-Hans.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\Translations\zh-cmn-Hant.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\AutoStart Manager.exe
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\de.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\en.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\english.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\es.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\fr.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\gbottompic.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\gbottompicp.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\grey\gbottompic.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\grey\gbottompicp.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\grey\gtoppic.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\grey\gtoppicp.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\grey\skin.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\grey\Thumbs.db
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\gtoppic.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\gtoppicp.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\it.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\ja.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\nl.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\pr.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\russian.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Settings.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\skin.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Skins\grey\gbottompic.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Skins\grey\gbottompicp.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Skins\grey\gtoppic.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Skins\grey\gtoppicp.bmp
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Skins\grey\skin.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Skins\grey\Thumbs.db
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\SO.dll
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Thumbs.db
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\de.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\en.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\english.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\es.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\fr.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\it.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\ja.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\nl.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\pr.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\russian.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\zh-cmn-Hans.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\Translations\zh-cmn-Hant.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\zh-cmn-Hans.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\AutoStart\zh-cmn-Hant.xml
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Extras.LGFF
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\HostFileEditor.exe
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Lang\DE.lslang
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Lang\EN.lslang
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Lang\ES.lslang
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Lang\FL.lslang
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Lang\FR.lslang
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Lang\IT.lslang
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Lang\NL.lslang
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\Lang\PT.lslang
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\ProcessWatch.dll
c:\programmi\Lavasoft\Ad-Aware\ToolBox\LT\ProcessWatch.exe
c:\programmi\Lavasoft\Ad-Aware\unacev2.dll
c:\programmi\Lavasoft\Ad-Aware\unrar.dll
c:\programmi\Lavasoft\Ad-Aware\UpdateManager.dll
c:\programmi\Lavasoft\Ad-Aware\WSCUpdate.dll
c:\windows\system32\lsdelete.exe
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_LAVASOFT_AD-AWARE_SERVICE
-------\Legacy_LBD
-------\Service_Lavasoft Ad-Aware Service
-------\Service_Lbd
((((((((((((((((((((((((( Files Creati Da 2009-12-17 al 2010-01-17 )))))))))))))))))))))))))))))))))))
.
2010-01-15 21:42 . 2010-01-15 21:42 388096 ----a-r- c:\documents and settings\entry\Dati applicazioni\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-15 21:42 . 2010-01-15 21:42 -------- d-----w- c:\programmi\TrendMicro
2010-01-06 21:09 . 2010-01-06 21:09 862040 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-01-06 21:09 . 2010-01-06 21:09 206944 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-01-06 21:09 . 2010-01-06 21:09 390288 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-01-06 21:09 . 2010-01-06 21:09 537576 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-01-06 21:09 . 2010-01-06 21:09 370744 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-01-06 21:09 . 2010-01-06 21:09 194104 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-06 21:08 . 2010-01-15 21:11 6296864 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\Resources.dll
2010-01-06 21:08 . 2010-01-06 21:08 933120 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-01-06 21:08 . 2010-01-06 21:08 816272 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-01-06 21:08 . 2010-01-06 21:08 822904 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-01-06 21:08 . 2010-01-06 21:08 1643272 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-01-06 21:08 . 2010-01-06 21:08 788880 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-01-06 21:08 . 2010-01-06 21:08 1181328 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-01-06 21:06 . 2010-01-06 21:06 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-06 21:06 . 2009-12-07 14:10 2953352 -c--a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 13:58 . 2008-12-04 19:54 -------- d-----w- c:\programmi\Alice MOBILE
2010-01-17 13:20 . 2004-02-27 13:38 -------- d-----w- c:\programmi\Ulead Systems
2010-01-17 11:02 . 2009-01-20 17:32 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-17 11:02 . 2009-07-13 18:49 5115823 ----a-w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-16 19:30 . 2008-08-18 18:56 -------- d-----w- c:\programmi\eMule
2010-01-07 15:07 . 2009-01-20 17:32 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-01-20 17:32 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 21:06 . 2009-01-10 19:11 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dati applicazioni\Lavasoft
2010-01-06 20:22 . 2009-12-08 18:00 54 ----a-w- c:\windows\system32\rp_stats.dat
2010-01-06 20:22 . 2009-12-08 18:00 39 ----a-w- c:\windows\system32\rp_rules.dat
2010-01-04 16:52 . 2009-09-02 17:56 -------- d-----w- c:\programmi\LG PC Suite II
2009-12-10 11:53 . 2009-11-11 20:02 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-03 13:14 . 2009-01-18 11:08 -------- d-----w- c:\programmi\PHPNukeIT
2009-12-02 13:19 . 2009-08-26 14:03 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-11-23 17:02 . 2009-06-23 13:57 -------- d-----w- c:\programmi\PokerStars.IT
2009-11-17 21:59 . 2001-08-31 10:00 69916 ----a-w- c:\windows\system32\perfc010.dat
2009-11-17 21:59 . 2001-08-31 10:00 437604 ----a-w- c:\windows\system32\perfh010.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-10 39408]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 577536]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"fssui"="c:\programmi\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-10 20480]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SMSTray"="c:\programmi\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-12-14 132624]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\xxx\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 1.0.1.lnk - c:\programmi\OpenOffice.org1.0.1\program\quickstart.exe [2002-7-4 61440]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R2 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\SupportAppXL\cdrom_mon.exe [16/04/2009 14.39.12 81920]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11/01/2009 0.07.32 54752]
R3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\drivers\ONDAusbmdm6k.sys [16/04/2009 14.40.19 104960]
R3 ONDAusbnet;ONDA USB-NDIS miniport;c:\windows\system32\drivers\ONDAusbnet.sys [16/04/2009 14.40.19 110080]
R3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\drivers\ONDAusbnmea.sys [16/04/2009 14.40.19 104960]
R3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\drivers\ONDAusbser6k.sys [16/04/2009 14.40.19 104960]
S3 fsssvc;Servizio Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22.48.42 704864]
.
Contenuto della cartella 'Scheduled Tasks'
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://google.com/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\programmi\PokerStars.IT\PokerStarsUpdate.exe
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
AddRemove-ITALIA_version Toolbar - c:\progra~1\ITALIA~1\UNWISE.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-17 15:15
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"0140710900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wscntfy.exe
c:\windows\SOUNDMAN.EXE
c:\programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-17 15:19:42 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-17 14:19
ComboFix2.txt 2010-01-17 11:40
ComboFix3.txt 2010-01-17 11:25
Pre-Run: 17.984.000.000 byte disponibili
Post-Run: 17.930.420.224 byte disponibili
- - End Of File - - BE882A4972E9A01BD0556DB7136671E2