log combofix
ComboFix 11-07-29.03 - Franco 31/07/2011 9:13.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.8191.6527 [GMT 2:00]
Eseguito da: c:\users\Franco\Desktop\ComboFix.exe
Opzioni usate :: c:\users\Franco\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
AV: AVG Internet Security 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: AVG Internet Security 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
FILE ::
"c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll"
"c:\windows\SysWow64\2f1ed5f2.exe"
"c:\windows\SysWow64\xgyfjifmrbhbd.exe"
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
c:\windows\SysWow64\2f1ed5f2.exe
c:\windows\SysWow64\xgyfjifmrbhbd.exe
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ASWFSBLK
-------\Legacy_ASWMONFLT
-------\Legacy_ASWSP
-------\Service_aswFsBlk
-------\Service_aswMonFlt
-------\Service_aswSP
.
.
((((((((((((((((((((((((( Files Creati Da 2011-06-28 al 2011-07-31 )))))))))))))))))))))))))))))))))))
.
.
2011-07-31 07:18 . 2011-07-31 07:18 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2011-07-31 07:18 . 2011-07-31 07:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-30 21:25 . 2011-07-30 21:25 -------- d-----w- c:\users\Franco\AppData\Roaming\Convivea
2011-07-30 21:25 . 2011-07-30 21:25 -------- d-----w- c:\program files (x86)\Bit Che
2011-07-30 09:50 . 2011-07-30 09:50 -------- d-----w- c:\program files (x86)\Digital Photo Software
2011-07-30 08:31 . 2011-07-06 17:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-30 08:31 . 2011-07-30 08:31 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-29 17:11 . 2011-07-29 17:11 -------- d-----w- c:\program files (x86)\AKVIS
2011-07-29 16:25 . 2011-07-29 16:26 -------- d-----w- c:\users\Franco\AppData\Roaming\Photo! Web Album
2011-07-29 16:25 . 2011-07-29 16:25 -------- d-----w- c:\program files (x86)\Photo!
2011-07-29 16:24 . 2011-07-29 16:25 -------- d-----w- c:\program files (x86)\Web Photo Album
2011-07-29 16:24 . 2011-07-29 16:24 -------- d-----w- c:\program files (x86)\Mobile Photo Enhancer
2011-07-29 09:33 . 2011-07-29 09:33 -------- d-----w- c:\program files (x86)\Alberosa
2011-07-29 09:27 . 2011-07-29 09:27 -------- d-----w- c:\program files (x86)\VirtualDJ
2011-07-29 08:13 . 2011-07-29 08:13 -------- d-----w- c:\users\Franco\AppData\Roaming\WordWeb
2011-07-29 08:12 . 2011-07-29 08:12 -------- d-----w- c:\program files (x86)\WordWeb
2011-07-29 08:12 . 2011-05-23 11:37 1196800 ------w- c:\windows\wweb32.dll
2011-07-29 07:40 . 2011-07-29 07:41 -------- d-----w- c:\users\Franco\AppData\Roaming\Marine Aquarium 3
2011-07-29 06:52 . 2011-07-29 06:52 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-29 06:39 . 2011-07-29 06:39 -------- d-----w- c:\program files (x86)\File Scavenger 3.2
2011-07-28 14:56 . 2011-07-28 14:56 -------- d-----w- c:\programdata\Readon
2011-07-28 14:53 . 2011-07-28 14:53 -------- d-----w- c:\users\Franco\AppData\Local\Readon_Technology
2011-07-28 14:53 . 2011-07-28 14:53 -------- d-----w- c:\program files (x86)\Readon Technology
2011-07-28 14:47 . 2011-07-28 14:47 -------- d-----w- c:\program files (x86)\Photo Story 3 for Windows
2011-07-28 06:23 . 2011-07-28 06:23 -------- d-----w- c:\users\Franco\AppData\Roaming\Babylon
2011-07-28 06:23 . 2011-07-28 06:23 -------- d-----w- c:\users\Franco\AppData\Local\Babylon
2011-07-28 06:23 . 2011-07-28 06:23 -------- d-----w- c:\programdata\Babylon
2011-07-28 06:23 . 2011-07-28 06:24 -------- d-----w- c:\program files (x86)\SafeMule
2011-07-27 16:37 . 2011-07-27 16:38 -------- d-----w- c:\programdata\AVG Security Toolbar
2011-07-27 15:55 . 2011-07-27 16:49 -------- d-----w- c:\users\Franco\AppData\Roaming\AVG
2011-07-27 15:47 . 2011-07-27 15:47 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2011-07-27 15:47 . 2011-07-30 22:00 -------- d-----w- c:\windows\system32\drivers\AVG
2011-07-27 14:40 . 2011-07-29 07:55 -------- d-----w- c:\program files (x86)\PCPremiumTV
2011-07-25 17:28 . 2011-07-25 17:28 -------- d-----w- c:\users\Franco\DoctorWeb
2011-07-25 17:15 . 2011-07-30 08:31 -------- d-----w- c:\program files (x86)\MALWAREBYTES ANTI-MALWARE
2011-07-24 17:38 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-23 21:55 . 2011-07-23 21:55 -------- d-----w- c:\program files (x86)\MagicISO
2011-07-23 17:04 . 2011-07-23 17:04 -------- d-----w- c:\users\Franco\AppData\Roaming\DVDVideoSoftIEHelpers
2011-07-21 19:23 . 2011-07-30 06:06 -------- d-----w- c:\program files (x86)\Aurora
2011-07-19 17:33 . 2011-07-19 17:33 -------- d-----w- c:\users\Franco\.gem
2011-07-19 17:33 . 2011-07-19 17:33 -------- d-----w- C:\cuperativa
2011-07-19 17:07 . 2011-07-19 17:07 -------- d-----w- c:\program files (x86)\Inpaint
2011-07-18 18:36 . 2011-07-23 22:09 -------- d-----w- c:\users\Franco\AppData\Local\Halite
2011-07-18 16:55 . 2011-07-18 16:56 -------- d-----w- c:\users\Franco\AppData\Roaming\Software Informer
2011-07-18 16:55 . 2011-07-18 16:55 -------- d-----w- c:\program files (x86)\Software Informer
2011-07-18 16:54 . 2011-07-24 17:10 -------- d-----w- c:\users\Franco\AppData\Local\Garbage Finder
2011-07-17 15:52 . 2011-07-17 15:51 476904 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-07-17 15:41 . 2011-07-17 15:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-17 08:07 . 2011-07-17 08:10 -------- d-----w- c:\program files (x86)\Allok Video Joiner
2011-07-16 22:41 . 2010-11-20 13:24 2872320 ----a-w- c:\windows\explorer.exe
2011-07-16 22:41 . 2009-07-14 01:06 23555072 ----a-w- c:\windows\SysWow64\imageres.dll
2011-07-16 22:41 . 2010-11-20 12:19 1492992 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2011-07-16 22:41 . 2010-11-20 12:18 1791488 ----a-w- c:\windows\SysWow64\authui.dll
2011-07-16 22:41 . 2011-07-16 22:41 245760 ----a-w- c:\windows\SysWow64\uxtheme.dll.tmp
2011-07-16 22:41 . 2009-07-14 01:11 245760 ----a-w- c:\windows\SysWow64\uxtheme.dll.backup
2011-07-16 22:41 . 2009-07-14 01:41 44544 ----a-w- c:\windows\system32\themeservice.dll.backup
2011-07-16 22:41 . 2009-07-14 01:41 332288 ----a-w- c:\windows\system32\uxtheme.dll.backup
2011-07-16 22:41 . 2011-07-16 22:41 -------- d--h--w- c:\windows\8 Skin Pack
2011-07-16 19:50 . 2011-07-16 19:50 -------- d-----w- c:\program files (x86)\Common Files\Autodesk Shared
2011-07-16 19:50 . 2011-07-16 19:51 -------- d-----w- c:\program files\AutoCAD 2010
2011-07-16 09:11 . 2010-11-03 13:47 139264 ----a-w- c:\windows\SysWow64\MIHDBG.exe
2011-07-16 09:10 . 2006-11-14 09:31 22784 ----a-w- c:\windows\SysWow64\drivers\afc.sys
2011-07-15 12:11 . 2011-07-15 12:11 -------- d-----w- c:\program files (x86)\DsNET Corp
2011-07-10 17:23 . 2011-07-24 17:13 -------- d-----w- c:\programdata\OneUpIndustries
2011-07-10 17:23 . 2005-06-15 01:00 102400 ----a-w- c:\windows\SysWow64\tsccvid.dll
2011-07-10 17:22 . 2011-07-25 05:05 -------- d-----w- c:\program files\OneUpIndustries
2011-07-10 15:39 . 2011-07-10 15:39 -------- d-----w- c:\users\Franco\AppData\Local\SoundSpectrum
2011-07-10 15:36 . 2011-07-10 15:37 -------- d-----w- c:\program files (x86)\Morphyre
2011-07-05 18:07 . 2011-07-05 18:07 -------- d-----w- c:\programdata\Licenses
2011-07-05 18:06 . 2011-07-05 18:06 -------- d-----w- c:\program files (x86)\CDRWIN 9
2011-07-05 17:39 . 2011-07-30 17:07 -------- d-----w- c:\programdata\CDRWIN 9
2011-07-05 05:16 . 2011-07-05 05:16 -------- d-----w- c:\windows\system32\SPReview
2011-07-04 18:28 . 2011-04-25 08:25 4603616 ----a-w- c:\windows\SysWow64\DevComponents.DotNetBar2.dll
2011-07-04 17:27 . 2011-06-09 09:33 24912 ----a-w- c:\windows\system32\dopdfmn7.dll
2011-07-04 17:27 . 2011-06-09 09:33 21328 ----a-w- c:\windows\system32\dopdfmi7.dll
2011-07-04 17:27 . 2010-02-05 13:00 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2011-07-04 16:27 . 2010-11-20 13:33 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-04 16:26 . 2010-11-20 13:27 221696 ----a-w- c:\windows\system32\OnLineIDCpl.dll
2011-07-04 16:24 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-07-03 22:19 . 2011-07-03 22:19 -------- d-----w- c:\users\Franco\AppData\Roaming\qBittorrent
2011-07-03 22:11 . 2011-07-03 22:21 -------- d-----w- c:\users\Franco\AppData\Roaming\BitTorrent
2011-07-03 22:09 . 2011-07-03 22:09 -------- d-----w- c:\programdata\IsolatedStorage
2011-07-03 22:03 . 2011-06-16 04:44 142296 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2011-07-03 22:03 . 2011-06-16 04:44 89048 ----a-w- c:\program files (x86)\Mozilla Firefox\libEGL.dll
2011-07-03 22:03 . 2011-06-16 04:44 781272 ----a-w- c:\program files (x86)\Mozilla Firefox\mozsqlite3.dll
2011-07-03 22:03 . 2011-06-16 04:44 719832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozcpp19.dll
2011-07-03 22:03 . 2011-06-16 04:44 465880 ----a-w- c:\program files (x86)\Mozilla Firefox\libGLESv2.dll
2011-07-03 22:03 . 2011-06-16 04:44 1850328 ----a-w- c:\program files (x86)\Mozilla Firefox\mozjs.dll
2011-07-03 22:03 . 2011-06-16 04:44 16856 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-container.exe
2011-07-03 22:03 . 2011-06-16 04:44 15832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozalloc.dll
2011-07-03 22:03 . 2010-01-01 08:00 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-07-03 22:03 . 2010-01-01 08:00 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-07-03 19:54 . 2011-07-03 19:54 -------- d-----w- c:\windows\SysWow64\Wat
2011-07-03 19:54 . 2011-07-03 19:54 -------- d-----w- c:\windows\system32\Wat
2011-07-03 19:34 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-07-03 19:16 . 2011-07-03 19:16 -------- d-----w- c:\program files (x86)\Pirelli
2011-07-03 19:15 . 2004-10-22 00:16 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2011-07-03 18:48 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-03 18:48 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-03 18:48 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-07-03 18:48 . 2011-04-09 07:02 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-07-03 18:48 . 2011-04-09 06:02 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-07-03 18:48 . 2011-04-09 06:02 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-07-03 18:48 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-07-03 18:48 . 2011-05-24 10:39 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-07-03 18:48 . 2011-05-24 10:37 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-07-03 18:48 . 2010-11-20 13:25 207872 ----a-w- c:\windows\system32\cfgmgr32.dll
2011-07-03 18:48 . 2011-05-24 10:40 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-07-03 18:48 . 2011-05-24 10:40 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-07-03 18:46 . 2011-03-11 06:34 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2011-07-03 18:46 . 2011-03-11 06:34 1395712 ----a-w- c:\windows\system32\mfc42.dll
2011-07-03 18:46 . 2011-03-11 05:33 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
2011-07-03 18:46 . 2011-03-11 05:33 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
2011-07-03 18:44 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-07-03 18:44 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-07-03 18:44 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-07-03 18:33 . 2011-06-20 06:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DE08FB18-106D-4985-8207-D1F3B0EE977F}\mpengine.dll
2011-07-03 18:32 . 2011-07-27 16:49 -------- d-----w- c:\users\UpdatusUser.Franco-PC
2011-07-03 18:32 . 2011-05-21 04:01 739432 ----a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-07-02 22:02 . 2011-07-03 18:05 -------- d-----w- c:\program files (x86)\Metal Gear Solid
2011-07-01 21:24 . 2011-07-01 21:24 -------- d-----w- c:\program files (x86)\Blue Label
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 22:41 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll
2011-07-16 22:41 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll
2011-07-05 05:23 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-07-05 05:23 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-05-24 17:14 . 2010-01-24 08:17 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-21 04:01 . 2011-05-21 04:01 8863336 ----a-w- c:\windows\system32\nvwgf2umx.dll
2011-05-21 04:01 . 2011-05-21 04:01 7123560 ----a-w- c:\windows\system32\nvcuda.dll
2011-05-21 04:01 . 2011-05-21 04:01 67176 ----a-w- c:\windows\system32\OpenCL.dll
2011-05-21 04:01 . 2011-05-21 04:01 6555240 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2011-05-21 04:01 . 2011-05-21 04:01 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-05-21 04:01 . 2011-05-21 04:01 5301352 ----a-w- c:\windows\SysWow64\nvcuda.dll
2011-05-21 04:01 . 2011-05-21 04:01 2943592 ----a-w- c:\windows\system32\nvcuvid.dll
2011-05-21 04:01 . 2011-05-21 04:01 2804328 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2011-05-21 04:01 . 2011-05-21 04:01 2335848 ----a-w- c:\windows\SysWow64\nvapi.dll
2011-05-21 04:01 . 2011-05-21 04:01 22286952 ----a-w- c:\windows\system32\nvoglv64.dll
2011-05-21 04:01 . 2011-05-21 04:01 2212968 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-05-21 04:01 . 2011-05-21 04:01 2082408 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2011-05-21 04:01 . 2011-05-21 04:01 18583144 ----a-w- c:\windows\system32\nvcompiler.dll
2011-05-21 04:01 . 2011-05-21 04:01 16456296 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2011-05-21 04:01 . 2011-05-21 04:01 15223912 ----a-w- c:\windows\system32\nvd3dumx.dll
2011-05-21 04:01 . 2011-05-21 04:01 1496168 ----a-w- c:\windows\system32\nvdispco6420150.dll
2011-05-21 04:01 . 2011-05-21 04:01 1427048 ----a-w- c:\windows\system32\nvgenco642090.dll
2011-05-21 04:01 . 2011-05-21 04:01 13206120 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-05-21 04:01 . 2011-05-21 04:01 13011560 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2011-05-21 04:01 . 2011-05-21 04:01 11992680 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2011-05-21 04:01 . 2010-01-11 22:19 6300776 ----a-w- c:\windows\system32\nvcpl.dll
2011-05-21 04:01 . 2010-01-11 22:19 3040872 ----a-w- c:\windows\system32\nvsvc64.dll
2011-05-21 04:01 . 2010-01-11 22:19 2560616 ----a-w- c:\windows\system32\nvsvcr.dll
2011-05-21 04:01 . 2010-01-11 22:19 117864 ----a-w- c:\windows\system32\nvmctray.dll
2011-05-21 04:01 . 2010-01-11 22:19 1016936 ----a-w- c:\windows\system32\nvvsvc.exe
2011-05-21 04:01 . 2009-08-28 04:35 2644584 ----a-w- c:\windows\system32\nvapi64.dll
2011-05-21 04:01 . 2009-07-14 07:51 61544 ----a-w- c:\windows\system32\nvshext.dll
2011-05-14 06:24 . 2011-07-13 05:28 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 67E5725A1907E6F72074F2AB8CB2B946 . 2872320 . . [6.1.7600.16385] .. c:\windows\explorer.exe
[7] 2010-11-20 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\8 Skin Pack\Backup\explorer.exe
[7] 2010-11-20 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[7] 2009-10-31 . B8EC4BD49CE8F6FC457721BFC210B67F . 2870272 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[7] 2009-10-31 . 9AAAEC8DAC27AA17B053E6352AD233AE . 2870272 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[7] 2009-08-03 . 700073016DAC1C3D2E7E2CE4223334B6 . 2868224 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[7] 2009-08-03 . F170B4A061C9E026437B193B4D571799 . 2868224 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[7] 2009-07-14 . C235A51CB740E45FFA0EBFB9BAFCDA64 . 2868224 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
.
(((((((((((((((((((((((((((((
SnapShot@2011-07-30_10.34.36 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-07-30 05:38 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-07-31 07:16 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-07-30 05:38 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-31 07:16 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-30 05:38 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-31 07:16 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-08-28 03:47 . 2011-07-31 06:37 97666 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-07-31 06:37 38834 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-01-23 16:43 . 2011-07-31 06:37 15948 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3373818867-907296849-2200420771-1001_UserData.bin
+ 2009-09-27 07:08 . 2011-07-30 11:13 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-09-27 07:08 . 2011-07-29 17:48 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-27 07:08 . 2011-07-30 11:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-09-27 07:08 . 2011-07-29 17:48 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-30 11:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-29 17:48 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-07-30 10:33 . 2011-07-30 10:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-31 07:21 . 2011-07-31 07:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-31 07:21 . 2011-07-31 07:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-30 10:33 . 2011-07-30 10:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-09-25 16:58 . 2011-07-30 05:42 689234 c:\windows\system32\perfh010.dat
+ 2009-09-25 16:58 . 2011-07-31 06:39 689234 c:\windows\system32\perfh010.dat
+ 2009-07-14 02:36 . 2011-07-31 06:39 606992 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-07-30 05:42 606992 c:\windows\system32\perfh009.dat
- 2009-09-25 16:58 . 2011-07-30 05:42 124420 c:\windows\system32\perfc010.dat
+ 2009-09-25 16:58 . 2011-07-31 06:39 124420 c:\windows\system32\perfc010.dat
+ 2009-07-14 02:36 . 2011-07-31 06:39 103370 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-07-30 05:42 103370 c:\windows\system32\perfc009.dat
+ 2009-07-14 05:01 . 2011-07-31 07:20 497112 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-07-30 10:32 497112 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-07-16 19:50 . 2011-07-29 07:14 460288 c:\windows\Installer\{5783F2D7-8001-0410-0102-0060B0CE6BBA}\Acad162_icon.exe
+ 2011-07-16 19:50 . 2011-07-30 21:26 460288 c:\windows\Installer\{5783F2D7-8001-0410-0102-0060B0CE6BBA}\Acad162_icon.exe
+ 2011-07-03 22:44 . 2011-07-31 07:20 20970072 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3373818867-907296849-2200420771-1001-8192.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Packard Bell Photo Frame"="c:\program files (x86)\Packard Bell Photo Frame\ButtonMonitor.exe" [2009-07-20 124416]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2011-07-06 1047656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\SafeMule\safemule.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer9"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart
.
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-05-30 1025352]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database_123b3ca\bin\fbserver.exe [2008-08-07 3276800]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-07-16 1030600]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-08 169312]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG10\avgfws.exe [2011-03-09 2708024]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database_123b3ca\bin\FABS.exe [2009-08-27 1253376]
S2 Greg_Service;GRegService;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-07-04 240160]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y62x64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF10373.cfxxe" [X]
.
------- Scansione supplementare -------
.
uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0410&m=ixtreme_m5722&r=173601106006p0325v1k5y48111322
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.poony.info/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = local
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Franco\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\Franco\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Salva oggetto con NetXfer - c:\program files (x86)\Xi\NetXfer\NXAddLink.html
IE: Salva tutti gli oggetti con NetXfer - c:\program files (x86)\Xi\NetXfer\NXAddList.html
IE: Scarica con Mipony - file://k:\jdownloader\Mipony\Browser\IEContext.htm
TCP: DhcpNameServer = 62.101.93.101 83.103.25.250
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\users\Franco\AppData\Roaming\Mozilla\Firefox\Profiles\9tadoyc4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.yahoo.itFF - prefs.js: keyword.URL - hxxp://search.avg.com/?d=4e10eca8&i=23&tp=ab&nt=1&q=
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
c:\program files (x86)\AVG\AVG10\avgam.exe
.
**************************************************************************
.
Ora fine scansione: 2011-07-31 09:26:10 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-07-31 07:26
ComboFix2.txt 2011-07-30 10:38
.
Pre-Run: 188.148.887.552 byte disponibili
Post-Run: 187.859.415.040 byte disponibili
.
- - End Of File - - 3374C1AAEC544EE4460E94DE321B5555