ComboFix 10-04-21.01 - 'ntunucciu 22/04/2010 0.37.19.2.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1023.277 [GMT 2:00]
Eseguito da: c:\documents and settings\'ntunucciu\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\'ntunucciu\Desktop\CFScript.txt
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___a1_twimg_com_profile_images_199307186_EOL_Eentertainment_thumb_normal_jpg.jpg
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___a1_twimg_com_profile_images_334357688_onion_logo_03_L_normal_png.png
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___a3_twimg_com_profile_images_67263363_icon_cnnbrk_normal_png.png
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___a3_twimg_com_profile_images_784227851_BarackObama_twitter_photo_normal_jpg.jpg
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674648687637500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674649190293750_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656274200000_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656376543750_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656432637500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656508106250_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656602325000_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656709825000_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656776075000_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656834512500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674656905918750_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657190918750_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657262481250_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657327637500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657395293750_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657581856250_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657650762500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657721387500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657821075000_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674657885918750_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633674658010762500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633776614270550000_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633776614512268750_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633776623349143750_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633776624984456250_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633795393080931250_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633795393206712500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633795393354212500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_633795402156087500_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_41_244_CT2442941_Images_634006387039680000_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_64_230_CT2304564_Images_Twitter_xml-4-Twitter-633795413884681250_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_chevron_menu_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_display_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_equalizer_dead_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_Equalizer_GIF.GIF
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_Error_GIF.GIF
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_Loading_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_maxi_dn_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_maxi_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_maxi_over_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_minimize_dn_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_minimize_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_minimize_over_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_pause_dn_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_pause_dn_mini_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_pause_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_pause_mini_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_pause_over_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_pause_over_mini_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_play_chevron_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_play_dn_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_play_dn_mini_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_play_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_play_mini_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_play_over_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_play_over_mini_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_slider_bg_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_slider_dn_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_slider_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_slider_over_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_stop_chevron_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_stop_dn_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_stop_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_stop_over_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_vol_dn_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_vol_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Midnight_vol_over_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_ClientImages_radio_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_about_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_clear_history_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_contact_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_help_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_home_page_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_options_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_privacy_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_refresh_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_shrink_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_tell_a_friend_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_main_menu_upgrade_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_SearchEngines_images_search_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_SearchEngines_news_icon_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_SearchEngines_site_search_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_searchengines_softonic_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___storage_conduit_com_images_SearchEngines_tfd_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\CacheIcons\http___weather_conduit_com_images_weather_Default_partly_cloudy_night_gif.gif
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\EmailNotifier\AccountTypes.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\EmailNotifier\aol.com.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\EmailNotifier\comcast.net.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\EmailNotifier\google.com.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\EmailNotifier\hotmail.com.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\EmailNotifier\yahoo.com.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\LanguagePack\en\LanguagePack.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\LocalSettings.txt
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\RadioPlayer\IP_Stations_Media_List.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\RadioPlayer\Predefined_Media_List.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\RadioPlayer\Skins\http___storage_conduit_com_BankImages_RadioSkins_Midnight_display_xml.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Rss\http___twitter_com_statuses_user_timeline_14075928_rss.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Rss\http___twitter_com_statuses_user_timeline_14075928_rss_structured.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Rss\http___twitter_com_statuses_user_timeline_2883841_rss.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Rss\http___twitter_com_statuses_user_timeline_2883841_rss_structured.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Rss\http___twitter_com_statuses_user_timeline_428333_rss.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Rss\http___twitter_com_statuses_user_timeline_428333_rss_structured.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Rss\http___twitter_com_statuses_user_timeline_813286_rss.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Rss\http___twitter_com_statuses_user_timeline_813286_rss_structured.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\SearchInNewTab\SearchInNewTabContent.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\ThirdPartyComponents.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Twitter\14075928.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Twitter\2883841.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Twitter\428333.xml
c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Soft-Search\Twitter\813286.xml
.
((((((((((((((((((((((((( Files Creati Da 2010-03-21 al 2010-04-21 )))))))))))))))))))))))))))))))))))
.
2010-04-21 10:25 . 2010-04-21 10:25 242696 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgtdix.sys
2010-04-21 10:24 . 2010-04-21 10:24 1689952 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.dll
2010-04-20 23:48 . 2010-04-20 23:48 -------- d-----w- c:\programmi\Trend Micro
2010-04-19 14:30 . 2010-04-12 15:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-17 11:18 . 2001-08-30 21:08 99328 ----a-w- c:\windows\system32\srusd.dll
2010-04-17 11:18 . 2001-08-30 21:08 99328 ----a-w- c:\windows\system32\dllcache\srusd.dll
2010-04-17 11:18 . 2001-08-30 20:28 6912 ----a-w- c:\windows\system32\drivers\serscan.sys
2010-04-17 11:18 . 2001-08-30 20:28 6912 ----a-w- c:\windows\system32\dllcache\serscan.sys
2010-04-17 11:18 . 2001-08-30 21:07 71680 ----a-w- c:\windows\system32\fnfilter.dll
2010-04-17 11:18 . 2001-08-30 21:07 71680 ----a-w- c:\windows\system32\dllcache\fnfilter.dll
2010-04-14 19:45 . 2010-04-14 19:45 503808 ----a-w- c:\documents and settings\Guest\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-564a0483-n\msvcp71.dll
2010-04-14 19:45 . 2010-04-14 19:45 499712 ----a-w- c:\documents and settings\Guest\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-564a0483-n\jmc.dll
2010-04-14 19:45 . 2010-04-14 19:45 348160 ----a-w- c:\documents and settings\Guest\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-564a0483-n\msvcr71.dll
2010-04-14 19:45 . 2010-04-14 19:45 61440 ----a-w- c:\documents and settings\Guest\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-183c2f21-n\decora-sse.dll
2010-04-14 19:45 . 2010-04-14 19:45 12800 ----a-w- c:\documents and settings\Guest\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-183c2f21-n\decora-d3d.dll
2010-04-14 18:18 . 2010-04-14 18:18 -------- d-----w- c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\Conduit
2010-04-08 17:23 . 2008-04-13 17:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-04-08 17:23 . 2008-04-13 17:45 10368 ----a-w- c:\windows\system32\dllcache\hidusb.sys
2010-04-08 08:20 . 2010-04-08 08:20 4255072 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgcorex.dll
2010-04-07 17:34 . 2010-04-07 17:34 -------- d-----w- c:\programmi\QuickTime
2010-04-07 17:34 . 2010-04-07 17:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2010-04-06 08:50 . 2010-04-06 08:50 -------- d-----w- c:\programmi\File comuni\Java
2010-04-06 08:49 . 2010-04-06 08:49 503808 ----a-w- c:\documents and settings\'ntunucciu\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4ebdf2e9-n\msvcp71.dll
2010-04-06 08:49 . 2010-04-06 08:49 499712 ----a-w- c:\documents and settings\'ntunucciu\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4ebdf2e9-n\jmc.dll
2010-04-06 08:49 . 2010-04-06 08:49 12800 ----a-w- c:\documents and settings\'ntunucciu\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3b3d7417-n\decora-d3d.dll
2010-04-06 08:49 . 2010-04-06 08:49 61440 ----a-w- c:\documents and settings\'ntunucciu\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3b3d7417-n\decora-sse.dll
2010-04-06 08:49 . 2010-04-06 08:49 348160 ----a-w- c:\documents and settings\'ntunucciu\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4ebdf2e9-n\msvcr71.dll
2010-04-05 22:22 . 2010-04-05 22:22 5918776 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-02 09:29 . 2010-04-02 09:29 4076824 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgui.exe
2010-04-02 09:29 . 2010-04-02 09:29 2059544 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgtray.exe
2010-04-02 09:29 . 2010-04-02 09:29 598296 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgsrmx.dll
2010-04-02 09:29 . 2010-04-02 09:29 341272 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgxch32.dll
2010-04-02 09:29 . 2010-04-02 09:29 313112 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avglogx.dll
2010-04-02 09:29 . 2010-04-02 09:29 1598744 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgssie.dll
2010-04-02 09:29 . 2010-04-02 09:29 1515224 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgwd.dll
2010-04-02 09:29 . 2010-04-02 09:29 1274136 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgfrw.exe
2010-04-02 09:29 . 2010-04-02 09:29 556824 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgchjwx.dll
2010-04-02 09:29 . 2010-04-02 09:29 459544 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgcclix.dll
2010-04-02 09:29 . 2010-04-02 09:29 301336 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgchclx.dll
2010-04-02 09:29 . 2010-04-02 09:29 1086744 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgchsvx.exe
2010-04-02 09:28 . 2010-04-02 09:28 1035032 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-21 10:25 . 2009-12-27 14:41 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-29 22:46 . 2009-12-28 17:01 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 22:45 . 2009-12-28 17:01 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-23 08:55 . 2009-12-28 12:41 54768 ----a-w- c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-03-16 22:55 . 2010-03-16 22:55 1924976 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NOS\Adobe_Downloads\install_flash_player.exe
2010-03-16 22:54 . 2010-03-16 22:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2010-03-13 09:07 . 2010-03-13 09:07 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-13 09:07 . 2009-12-27 14:41 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-13 09:07 . 2009-12-27 14:41 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-10 06:15 . 2004-09-16 13:31 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 19:00 . 2010-03-09 19:00 -------- d-----w- c:\documents and settings\'ntunucciu\Dati applicazioni\VoipStunt
2010-02-25 23:09 . 2004-09-16 13:31 80688 ----a-w- c:\windows\system32\perfc010.dat
2010-02-25 23:09 . 2004-09-16 13:31 482274 ----a-w- c:\windows\system32\perfh010.dat
2010-02-25 06:16 . 2004-09-16 13:31 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-09-16 13:31 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 19:05 . 2004-08-19 13:34 2149888 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2004-08-19 13:34 2028032 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 09:03 . 2010-03-11 16:10 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2004-09-16 13:30 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 19:15 . 2009-12-27 12:47 54768 ----a-w- c:\documents and settings\'ntunucciu\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-02-11 12:02 . 2004-09-16 13:31 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
(((((((((((((((((((((((((((((
SnapShot@2010-04-21_21.59.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 1601-01-01 00:00 . 1601-01-01 00:00 0 c:\windows\system32\drivers\GETPADD.sys
+ 2010-04-21 22:42 . 2010-04-21 22:42 16384 c:\windows\temp\Perflib_Perfdata_594.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-04-21 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-21 544768]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-03 16206848]
"ASUS Live Update"="c:\programmi\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\programmi\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"ATKMEDIA"="c:\programmi\ASUS\ATK Media\DMEDIA.EXE" [2006-02-15 49152]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"ATICCC"="c:\programmi\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Power_Gear"="c:\programmi\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-14 90112]
"ACMON"="c:\programmi\ASUS\Splendid\ACMON.exe" [2006-02-21 17920]
"IntelZeroConfig"="c:\programmi\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 667718]
"IntelWireless"="c:\programmi\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 602182]
"EOUApp"="c:\programmi\Intel\Wireless\Bin\EOUWiz.exe" [2006-04-14 569413]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-03-17 421888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\'ntunucciu\Menu Avvio\Programmi\Esecuzione automatica\
My Vodafone.it.lnk - c:\documents and settings\'ntunucciu\Dati applicazioni\mioObjects\[objects]\69GWEU9386MTAR08.mio [2009-12-27 104184]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 09:07 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [27/12/2009 16.41.35 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [27/12/2009 16.41.46 242896]
R2 avg9wd;AVG Free WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [13/03/2010 11.07.19 308064]
S3 SynMini;ASUS WebCam, 1.3M, USB2.0, FF;c:\windows\system32\drivers\SynMini.sys [27/12/2009 13.37.16 841110]
S3 SynScan;ASUS WebCam Still Image;c:\windows\system32\drivers\SynScan.sys [27/12/2009 13.37.23 8278]
.
Contenuto della cartella 'Scheduled Tasks'
2009-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\'ntunucciu\Dati applicazioni\Mozilla\Firefox\Profiles\j1xr1m37.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:it:official
FF - component: c:\programmi\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-22 00:42
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ñw*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(864)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1396)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\AVG\AVG9\avgchsvx.exe
c:\programmi\AVG\AVG9\avgrsx.exe
c:\programmi\AVG\AVG9\avgcsrvx.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\programmi\AVG\AVG9\avgnsx.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\ACEngSvr.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\windows\ATK0100\ATKOSD.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\mioengine.exe
.
**************************************************************************
.
Ora fine scansione: 2010-04-22 00:46:22 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-04-21 22:46
ComboFix2.txt 2010-04-21 22:00
Pre-Run: 16.630.022.144 byte disponibili
Post-Run: 16.598.564.864 byte disponibili