Grazie r16 e grazie anche a te Paolo.
Allego il log di Malwarebytes e combofix.
Il problema era che questo portatile si riavviava continuamente,però dopo la prima scansione in mod.provvisoria con l'antivirus scaduto(McAfee),lo svuotamento dei file temporanei e disattivato il ripristino questo non si è più verificato.
Ho eliminato i 4 problemi trovati da Malwarebytes.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.orgVersione database: 4180
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
08/06/2010 20.46.42
mbam-log-2010-06-08 (20-46-42).txt
Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi esaminati: 205837
Tempo trascorso: 54 minuti, 31 secondi
Processi infetti in memoria: 0
Moduli di memoria infetti: 0
Chiavi di registro infette: 1
Valori di registro infetti: 2
Voci infette nei dati di registro: 0
Cartelle infette: 0
File infetti: 1
Processi infetti in memoria:
(Non sono stati rilevati elementi nocivi)
Moduli di memoria infetti:
(Non sono stati rilevati elementi nocivi)
Chiavi di registro infette:
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rolxtqu (Trojan.Agent.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\csrcs (Trojan.Agent) -> Quarantined and deleted successfully.
Voci infette nei dati di registro:
(Non sono stati rilevati elementi nocivi)
Cartelle infette:
(Non sono stati rilevati elementi nocivi)
File infetti:
c:\documents and settings\matilde\impostazioni locali\dati applicazioni\rolxtqu.exe (Trojan.Agent.H) -> Delete on reboot.
ComboFix 10-06-08.01 - matilde 08/06/2010 21.05.53.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2038.1435 [GMT 2:00]
Eseguito da: c:\documents and settings\matilde\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\matilde\Impostazioni locali\Dati applicazioni\rolxtqu.dat
c:\documents and settings\matilde\Impostazioni locali\Dati applicazioni\rolxtqu_nav.dat
c:\documents and settings\matilde\Impostazioni locali\Dati applicazioni\rolxtqu_navps.dat
.
((((((((((((((((((((((((( Files Creati Da 2010-05-08 al 2010-06-08 )))))))))))))))))))))))))))))))))))
.
2010-06-08 17:19 . 2010-06-08 17:19 -------- d-----w- c:\documents and settings\matilde\Dati applicazioni\Malwarebytes
2010-06-08 17:19 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-08 17:18 . 2010-06-08 17:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-06-08 17:18 . 2010-06-08 17:19 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-06-08 17:18 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-08 15:00 . 2009-11-25 09:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-06-08 15:00 . 2009-03-30 07:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-06-08 15:00 . 2009-02-13 09:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-06-08 15:00 . 2009-02-13 09:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-06-08 15:00 . 2010-06-08 15:00 -------- d-----w- c:\programmi\Avira
2010-06-08 15:00 . 2010-06-08 15:00 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-06-08 13:14 . 2010-06-08 19:05 -------- d-----w- c:\windows\system32\CatRoot2
2010-06-08 12:22 . 2010-06-08 12:22 -------- d-----w- c:\windows\system32\it
2010-06-08 12:22 . 2010-06-08 12:22 -------- d-----w- c:\windows\system32\bits
2010-06-08 12:22 . 2010-06-08 12:22 -------- d-----w- c:\windows\l2schemas
2010-06-08 10:09 . 2001-08-30 18:41 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-06-08 10:09 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-05-17 12:41 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-05-17 12:41 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-16 18:08 . 2010-06-08 18:48 -------- d-----w- c:\documents and settings\matilde\Tracing
2010-05-16 18:06 . 2010-06-08 12:01 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-05-16 18:04 . 2010-05-16 18:04 -------- d-----w- c:\programmi\Microsoft Office Outlook Connector
2010-05-16 18:00 . 2010-04-28 05:44 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2010-05-16 17:54 . 2010-05-16 17:54 -------- d-----w- c:\programmi\Microsoft Sync Framework
2010-05-16 17:45 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-05-16 17:44 . 2010-05-16 17:44 -------- d-----w- c:\programmi\Microsoft SQL Server Compact Edition
2010-05-16 17:37 . 2010-05-16 18:05 -------- d-----w- c:\programmi\Microsoft
2010-05-16 17:36 . 2010-05-16 17:36 -------- d-----w- c:\programmi\Windows Live SkyDrive
2010-05-16 17:35 . 2010-05-16 17:59 -------- d-----w- c:\programmi\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-08 18:57 . 2010-04-11 17:37 -------- d-----w- c:\documents and settings\matilde\Dati applicazioni\HPAppData
2010-06-08 18:53 . 2009-06-01 20:42 -------- d-----w- c:\documents and settings\matilde\Dati applicazioni\Free Download Manager
2010-06-08 17:13 . 2009-06-01 20:42 -------- d-----w- c:\programmi\Free Download Manager
2010-06-08 14:55 . 2008-03-31 08:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee
2010-06-08 14:31 . 2008-12-25 22:11 -------- d-----w- c:\programmi\Launch Manager
2010-06-08 13:13 . 2010-06-08 13:13 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-06-08 12:42 . 2008-03-23 16:38 548226 ----a-w- c:\windows\system32\perfh010.dat
2010-06-08 12:42 . 2008-03-23 16:38 107530 ----a-w- c:\windows\system32\perfc010.dat
2010-05-19 12:09 . 2008-03-31 09:23 -------- d-----w- c:\programmi\Microsoft Works
2010-05-17 17:56 . 2010-01-25 16:29 -------- d-----w- c:\programmi\Google
2010-05-03 15:50 . 2010-05-03 15:50 -------- d-----w- c:\programmi\File comuni\Windows Live
2010-04-18 11:26 . 2010-04-18 11:26 -------- d-----w- c:\programmi\EA SPORTS
2010-04-17 00:24 . 2010-04-17 00:24 306544 ----a-w- c:\windows\WLXPGSS.SCR
2010-04-16 20:12 . 2010-04-16 20:12 48464 ----a-w- c:\windows\system32\sirenacm.dll
2010-04-15 12:59 . 2008-03-23 15:49 90344 ----a-w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-04-11 17:44 . 2010-04-11 17:32 -------- d-----w- c:\documents and settings\matilde\Dati applicazioni\HP
2010-04-11 17:35 . 2010-04-11 17:35 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WEBREG
2010-04-11 17:35 . 2010-04-11 17:20 168903 ----a-w- c:\windows\hpoins36.dat
2010-04-11 17:29 . 2010-04-11 17:23 -------- d-----w- c:\programmi\HP
2010-04-11 17:28 . 2010-04-11 17:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP
2010-04-11 17:28 . 2010-04-11 17:28 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP Product Assistant
2010-04-11 17:26 . 2010-04-11 17:26 -------- d-----w- c:\programmi\File comuni\HP
2010-04-11 17:24 . 2010-04-11 17:24 -------- d-----w- c:\programmi\File comuni\Hewlett-Packard
2010-04-11 15:03 . 2010-04-11 15:03 0 ----a-w- c:\windows\nsreg.dat
2010-04-11 13:29 . 2009-12-25 10:47 20 ---h--w- c:\documents and settings\All Users\Dati applicazioni\PKP_DLdu.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MyWirelessCard"="c:\programmi\PHD\3G HSDPA Wireless Modem MD-@\WirelessCard.exe" [2008-02-22 757760]
"Messenger (Yahoo!)"="c:\programmi\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-04 4363504]
"Free Download Manager"="c:\programmi\Free Download Manager\fdm.exe" [2009-02-27 3399727]
"IncrediMail"="c:\programmi\IncrediMail\bin\IncMail.exe" [2010-03-20 349568]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"preload"="c:\windows\RUNXMLPL.exe" [2007-04-21 20480]
"IAAnotif"="c:\programmi\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"SynTPStart"="c:\programmi\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-28 16132608]
"AzMixerSel"="c:\programmi\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-08 68640]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-19 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-13 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-13 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-13 138008]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2007-02-20 61440]
"Acer ePresentation HPD"="c:\acer\Empowering Technology\ePresentation\ePresentation.exe" [2007-03-02 208896]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2007-07-04 475136]
"Boot"="c:\acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 579584]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-05-28 342528]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2007-07-11 421888]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-10-17 858632]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"ISUSPM Startup"="c:\progra~1\FILECO~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-08-09 221184]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"Nikon Transfer Monitor"="c:\programmi\File comuni\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2008-12-26 45056]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-03-08 03:38 40048 ----a-w- c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24 54840 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-08 21:17 52256 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\programmi\QuickTime\QTTask.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Programmi\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Programmi\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Programmi\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [25/01/2010 18.29.58 135664]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;c:\windows\system32\drivers\bsusbser.sys [27/12/2008 23.25.20 94848]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
2010-03-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-25 16:29]
2010-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-25 16:29]
2010-06-08 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
mStart Page = hxxp://it.yahoo.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://it.rd.yahoo.com/customize/ycomp/defaults/su/*http://it.yahoo.com
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Scarica con Free Download Manager - file://c:\programmi\Free Download Manager\dllink.htm
IE: Scarica i video con Free Download Manager - file://c:\programmi\Free Download Manager\dlfvideo.htm
IE: Scarica selezionati con Free Download Manager - file://c:\programmi\Free Download Manager\dlselected.htm
IE: Scarica tutto con Free Download Manager - file://c:\programmi\Free Download Manager\dlall.htm
FF - ProfilePath - c:\documents and settings\matilde\Dati applicazioni\Mozilla\Firefox\Profiles\52qzpv9c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSeymour.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\programmi\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
AddRemove-FASTWEB Installer - E:\Setup.exe
AddRemove-Free Download Manager - c:\programmi\Free Download Manager\uninst.exe
AddRemove-rolxtqu - c:\documents and settings\matilde\impostazioni locali\dati applicazioni\rolxtqu.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-08 21:09
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
c:\docume~1\matilde\IMPOST~1\Temp\Perflib_Perfdata_898.dat
Scansione completata con successo
Files nascosti: 1
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2010-06-08 21:10:25
ComboFix-quarantined-files.txt 2010-06-08 19:10
Pre-Run: 57.927.725.056 byte disponibili
Post-Run: 57.938.907.136 byte disponibili
- - End Of File - - 9F1670E535BCE4ACD0C16F38E2642DCD