ComboFix 11-09-02.04 - Totero 03/09/2011 10.22.13.8.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1391 [GMT 2:00]
Eseguito da: c:\documents and settings\Totero\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
.
((((((((((((((((((((((((( Files Creati Da 2011-08-03 al 2011-09-03 )))))))))))))))))))))))))))))))))))
.
.
2011-09-02 15:47 . 2011-09-02 16:26 -------- d-----w- c:\documents and settings\Totero\Dati applicazioni\HP
2011-09-02 15:47 . 2011-09-02 15:47 -------- d-----w- c:\documents and settings\Totero\Impostazioni locali\Dati applicazioni\HP
2011-09-02 15:46 . 2009-08-05 15:22 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2011-09-02 15:46 . 2009-08-05 15:22 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2011-09-02 15:46 . 2009-10-22 00:55 452736 ----a-r- c:\windows\system32\hpzids01.dll
2011-09-02 15:46 . 2009-10-21 13:29 125440 ----a-w- c:\windows\system32\hpf3l101.dll
2011-09-02 15:46 . 2009-10-21 13:29 320512 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp101.dll
2011-09-02 15:46 . 2009-08-05 15:22 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2011-09-02 15:46 . 2009-10-30 04:15 372736 ----a-r- c:\windows\system32\hppldcoi.dll
2011-09-02 15:46 . 2009-09-10 17:44 966656 ----a-r- c:\windows\system32\hpost_p04b.dll
2011-09-02 15:46 . 2009-09-10 17:44 887296 ----a-r- c:\windows\system32\hposwia_p04b.dll
2011-09-02 15:46 . 2009-09-10 17:44 315392 ----a-r- c:\windows\system32\hposc_p04a.dll
2011-09-02 15:46 . 2009-08-05 15:22 309760 ----a-r- c:\windows\system32\difxapi.dll
2011-09-02 15:45 . 2011-09-02 15:45 -------- d-----w- c:\programmi\MSN Toolbar
2011-09-02 15:44 . 2011-09-02 15:45 -------- d-----w- c:\programmi\MSN Toolbar Installer
2011-09-02 15:44 . 2011-09-02 15:44 -------- d-----w- c:\documents and settings\Totero\Dati applicazioni\HpUpdate
2011-09-02 15:43 . 2011-09-02 15:43 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP Product Assistant
2011-09-02 15:41 . 2011-09-02 15:48 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP
2011-09-02 15:41 . 2011-09-02 15:41 -------- d-----w- c:\programmi\File comuni\HP
2011-09-02 15:41 . 2011-09-02 15:41 -------- d-----w- c:\programmi\File comuni\Hewlett-Packard
2011-09-02 15:37 . 2011-09-02 15:44 -------- d-----w- c:\programmi\HP
2011-09-02 15:36 . 2008-04-13 09:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2011-09-02 15:36 . 2008-04-13 09:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-09-02 07:45 . 2011-08-12 02:44 7152464 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Windows Defender\Definition Updates\{78758BAD-D4B3-4892-9954-455602B3B3E0}\mpengine.dll
2011-08-31 19:36 . 2011-08-31 19:36 -------- d-----w- c:\documents and settings\Totero\Impostazioni locali\Dati applicazioni\PIXELA
2011-08-30 21:24 . 2011-08-30 21:24 -------- d-----w- c:\documents and settings\Totero\Dati applicazioni\thecleaner
2011-08-30 20:46 . 2011-08-30 20:46 -------- d-----w- c:\programmi\Trend Micro
2011-08-27 19:03 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-27 19:02 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 19:02 . 2011-08-27 19:07 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-08-27 12:47 . 2011-08-27 12:47 -------- d-----w- c:\windows\system32\wbem\Repository
2011-08-27 11:22 . 2011-08-27 18:10 -------- d-----w- c:\documents and settings\Totero\Dati applicazioni\Remote
2011-08-27 09:13 . 2011-08-27 09:13 -------- d-----r- c:\documents and settings\NetworkService\Preferiti
2011-08-27 09:02 . 2011-08-27 09:02 -------- d-----w- c:\documents and settings\LocalService\IETldCache
2011-08-20 21:43 . 2011-08-20 21:43 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-19 09:32 . 2008-04-13 09:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2011-08-19 09:32 . 2008-04-13 09:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-08-10 08:13 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 08:13 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 02:44 . 2008-10-17 20:13 7152464 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-07-19 16:43 . 2011-07-19 16:43 29696 ----a-w- c:\windows\mickey32.dll
2011-07-19 16:43 . 2011-07-19 16:43 232784 ----a-w- c:\windows\Matrix Code.scr
2011-07-19 16:43 . 2011-07-19 16:43 2285222 ----a-w- c:\windows\Matrix Code.exe
2011-07-15 13:29 . 2004-09-07 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2004-09-07 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2008-10-10 12:14 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:30 . 2004-09-07 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:30 . 2004-09-07 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:30 . 2004-09-07 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-09-07 12:00 385024 ------w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2004-09-07 12:00 293888 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 11:35 . 2004-09-07 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2008-07-15 23:09 . 2010-12-14 11:34 2003456 ----a-w- c:\programmi\File comuni\Boris RED.msi
.
.
((((((((((((((((((((((((((((( SnapShot_2011-08-27_18.25.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-29 23:13 . 2010-01-29 23:13 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfcm80u.dll
+ 2010-01-29 23:13 . 2010-01-29 23:13 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfcm80.dll
+ 2010-01-29 23:13 . 2010-01-29 23:13 96256 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_6e85597b\ATL80.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 62976 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90rus.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 46080 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90kor.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 46592 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90jpn.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 64512 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90ita.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 66048 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90fra.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 65024 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90esp.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 65024 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90esn.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 56832 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90enu.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 66560 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90deu.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 39936 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90cht.dll
+ 2010-03-26 23:36 . 2010-03-26 23:36 38912 c:\windows\WinSxS\amd64_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_e2e562e3\mfc90chs.dll
+ 2010-01-29 21:40 . 2010-01-29 21:40 67072 c:\windows\WinSxS\amd64_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_7264ef23\mfcm90u.dll
+ 2010-01-29 21:40 . 2010-01-29 21:40 67072 c:\windows\WinSxS\amd64_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_7264ef23\mfcm90.dll
+ 2011-09-03 08:29 . 2011-09-03 08:29 16384 c:\windows\temp\Perflib_Perfdata_780.dat
+ 2010-01-18 10:28 . 2010-01-18 10:28 20480 c:\windows\system32\hpzisn12.dll
+ 2010-01-18 10:28 . 2010-01-18 10:28 29696 c:\windows\system32\hpzipt12.dll
+ 2010-01-18 10:28 . 2010-01-18 10:28 33792 c:\windows\system32\HPZipr12.dll
+ 2010-01-18 10:28 . 2010-01-18 10:28 53760 c:\windows\system32\HPZipm12.dll
+ 2010-01-18 10:28 . 2010-01-18 10:28 44032 c:\windows\system32\HPZinw12.dll
+ 2010-01-18 10:28 . 2010-01-18 10:28 49152 c:\windows\system32\HPZidr12.dll
+ 2010-01-19 13:10 . 2010-01-19 13:10 63488 c:\windows\system32\HPBWSDR.DLL
+ 2010-01-19 13:18 . 2010-01-19 13:18 41472 c:\windows\system32\hpbpro.dll
+ 2010-01-19 13:18 . 2010-01-19 13:18 25600 c:\windows\system32\hpboid.dll
+ 2010-01-19 13:18 . 2010-01-19 13:18 24576 c:\windows\system32\hpbmiapi.dll
+ 2011-09-02 15:39 . 2009-08-05 15:22 16800 c:\windows\system32\DRVSTORE\hpzius13_8D1976013E2E7C9CB02B04985FF5761CF0F1837E\drivers\dot4\WinxP\Hppaufd0.sys
+ 2011-09-02 15:39 . 2009-08-05 15:22 21568 c:\windows\system32\DRVSTORE\hpzius13_8D1976013E2E7C9CB02B04985FF5761CF0F1837E\drivers\dot4\Win2000\HPZius12.sys
+ 2011-09-02 15:39 . 2009-08-05 15:22 16496 c:\windows\system32\DRVSTORE\hpzius13_8D1976013E2E7C9CB02B04985FF5761CF0F1837E\drivers\dot4\Win2000\hpzipr12.sys
+ 2011-09-02 15:39 . 2009-08-05 15:22 49920 c:\windows\system32\DRVSTORE\hpzius13_8D1976013E2E7C9CB02B04985FF5761CF0F1837E\drivers\dot4\Win2000\hpzid412.sys
+ 2011-09-02 15:39 . 2009-08-05 15:22 16496 c:\windows\system32\DRVSTORE\hpzipr13_2850F885EE53D2B4462EF066D31F5A4875C6CD73\drivers\dot4\Win2000\HPZipr12.sys
+ 2011-09-02 15:39 . 2009-08-05 15:22 21568 c:\windows\system32\DRVSTORE\hpzipa13_EE3CF537F4EE3307971BE58371D43829AAE8CFDE\drivers\dot4\Win2000\HPZius12.sys
+ 2011-09-02 15:39 . 2009-08-05 15:22 16496 c:\windows\system32\DRVSTORE\hpzipa13_EE3CF537F4EE3307971BE58371D43829AAE8CFDE\drivers\dot4\Win2000\HPzipr12.sys
+ 2011-09-02 15:38 . 2009-08-05 15:22 49920 c:\windows\system32\DRVSTORE\hpzipa13_EE3CF537F4EE3307971BE58371D43829AAE8CFDE\drivers\dot4\Win2000\HPZid412.sys
+ 2011-09-02 15:38 . 2009-08-05 15:22 49920 c:\windows\system32\DRVSTORE\hpzid413_901BE655A04916440384FFED97293B9BD1537C92\drivers\dot4\Win2000\HPZid412.sys
+ 2011-09-02 15:37 . 2011-09-02 15:37 66048 c:\windows\Installer\b24bd.msi
+ 2011-09-02 15:43 . 2011-09-02 15:43 65536 c:\windows\Installer\{CD31E63D-47FD-491C-8117-CF201D0AFAB5}\NewShortcut1.A6CC6977_F7B4_4C0B_9510_BCD847D4BDB2.exe
+ 2010-01-19 13:18 . 2010-01-19 13:18 7680 c:\windows\system32\hpbprops.dll
+ 2010-01-19 13:18 . 2010-01-19 13:18 7680 c:\windows\system32\hpboidps.dll
+ 2010-01-29 23:13 . 2010-01-29 23:13 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcr80.dll
+ 2010-01-29 23:13 . 2010-01-29 23:13 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcp80.dll
+ 2010-01-29 23:13 . 2010-01-29 23:13 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcm80.dll
+ 2010-01-29 21:40 . 2010-01-29 21:40 626688 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcr90.dll
+ 2010-01-29 21:40 . 2010-01-29 21:40 856576 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcp90.dll
+ 2010-01-29 21:40 . 2010-01-29 21:40 245760 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcm90.dll
+ 2011-09-02 15:46 . 2009-07-14 04:37 762368 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\UNIRES.DLL
+ 2011-09-02 15:46 . 2009-07-14 04:46 747520 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\UNIDRVUI.DLL
+ 2011-09-02 15:46 . 2009-07-14 04:46 375296 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\UNIDRV.DLL
+ 2011-09-02 15:46 . 2009-10-21 13:28 636416 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpob1103.dll
+ 2011-09-02 15:46 . 2009-10-21 13:28 209408 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpfvu101.dll
+ 2011-09-02 15:46 . 2009-09-03 08:50 115712 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpfrs101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:29 309760 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpfpr101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:29 472064 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpfpa101.dll
+ 2011-09-02 15:46 . 2009-09-03 08:48 221696 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpfie101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:29 534016 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpfev101.dll
+ 2008-11-01 14:04 . 2009-07-14 04:37 762368 c:\windows\system32\spool\drivers\w32x86\3\UNIRES.DLL
+ 2008-11-01 14:04 . 2009-07-14 04:46 747520 c:\windows\system32\spool\drivers\w32x86\3\UNIDRVUI.DLL
+ 2008-11-01 14:04 . 2009-07-14 04:46 375296 c:\windows\system32\spool\drivers\w32x86\3\UNIDRV.DLL
+ 2011-09-02 15:46 . 2009-10-21 13:28 636416 c:\windows\system32\spool\drivers\w32x86\3\hpob1103.dll
+ 2011-09-02 15:46 . 2009-10-21 13:28 209408 c:\windows\system32\spool\drivers\w32x86\3\hpfvu101.dll
+ 2011-09-02 15:46 . 2009-09-03 08:50 115712 c:\windows\system32\spool\drivers\w32x86\3\hpfrs101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:29 309760 c:\windows\system32\spool\drivers\w32x86\3\hpfpr101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:29 472064 c:\windows\system32\spool\drivers\w32x86\3\hpfpa101.dll
+ 2011-09-02 15:46 . 2009-09-03 08:48 221696 c:\windows\system32\spool\drivers\w32x86\3\hpfie101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:29 534016 c:\windows\system32\spool\drivers\w32x86\3\hpfev101.dll
+ 2009-11-27 10:16 . 2009-11-27 10:16 180224 c:\windows\system32\hplbddrv.dll
+ 2011-09-02 15:39 . 2009-08-05 15:22 282624 c:\windows\system32\DRVSTORE\hpzius13_8D1976013E2E7C9CB02B04985FF5761CF0F1837E\HPZc3212.dll
+ 2011-09-02 15:39 . 2009-10-30 04:15 372736 c:\windows\system32\DRVSTORE\hpzius13_8D1976013E2E7C9CB02B04985FF5761CF0F1837E\drivers\dot4\Win2000\hppldcoi.dll
+ 2011-09-02 15:39 . 2009-08-05 15:22 309760 c:\windows\system32\DRVSTORE\hpzius13_8D1976013E2E7C9CB02B04985FF5761CF0F1837E\drivers\dot4\Win2000\difxapi.dll
+ 2011-09-02 15:39 . 2009-08-05 15:22 282624 c:\windows\system32\DRVSTORE\hpzipa13_EE3CF537F4EE3307971BE58371D43829AAE8CFDE\HPZc3212.dll
+ 2011-09-02 15:39 . 2009-10-30 04:15 372736 c:\windows\system32\DRVSTORE\hpzipa13_EE3CF537F4EE3307971BE58371D43829AAE8CFDE\drivers\dot4\Win2000\hppldcoi.dll
+ 2011-09-02 15:39 . 2009-08-05 15:22 309760 c:\windows\system32\DRVSTORE\hpzipa13_EE3CF537F4EE3307971BE58371D43829AAE8CFDE\drivers\dot4\Win2000\difxapi.dll
+ 2011-09-02 15:39 . 2009-09-10 17:44 887296 c:\windows\system32\DRVSTORE\hpob110_sc_A949E55243CEA7576E3DAD3E7D2A083AC2EC20F1\drivers\scanner\x32\hposwia_p04b.dll
+ 2011-09-02 15:39 . 2009-09-10 17:44 966656 c:\windows\system32\DRVSTORE\hpob110_sc_A949E55243CEA7576E3DAD3E7D2A083AC2EC20F1\drivers\scanner\x32\hpost_p04b.dll
+ 2011-09-02 15:39 . 2009-09-10 17:44 315392 c:\windows\system32\DRVSTORE\hpob110_sc_A949E55243CEA7576E3DAD3E7D2A083AC2EC20F1\drivers\scanner\x32\hposc_p04a.dll
+ 2011-09-02 15:39 . 2009-10-30 04:15 372736 c:\windows\system32\DRVSTORE\hpob110_sc_A949E55243CEA7576E3DAD3E7D2A083AC2EC20F1\drivers\dot4\Win2000\hppldcoi.dll
+ 2011-09-02 15:39 . 2009-08-05 15:22 309760 c:\windows\system32\DRVSTORE\hpob110_sc_A949E55243CEA7576E3DAD3E7D2A083AC2EC20F1\drivers\dot4\Win2000\difxapi.dll
+ 2011-09-02 15:38 . 2009-10-22 00:55 452736 c:\windows\system32\DRVSTORE\hpb110_059AF5BED3758FDFEB7367E29299A6824469E7A7\hpzids01.dll
+ 2011-09-02 15:45 . 2011-09-02 15:45 164864 c:\windows\Installer\b2570.msi
+ 2011-09-02 15:45 . 2011-09-02 15:45 203776 c:\windows\Installer\b255f.msi
+ 2011-09-02 15:44 . 2011-09-02 15:44 822784 c:\windows\Installer\b2549.msi
+ 2011-09-02 15:44 . 2011-09-02 15:44 855040 c:\windows\Installer\b2541.msi
+ 2011-09-02 15:44 . 2011-09-02 15:44 482304 c:\windows\Installer\b253b.msi
+ 2011-09-02 15:43 . 2011-09-02 15:43 571904 c:\windows\Installer\b252f.msi
+ 2011-09-02 15:43 . 2011-09-02 15:43 273408 c:\windows\Installer\b2529.msi
+ 2011-09-02 15:43 . 2011-09-02 15:43 828928 c:\windows\Installer\b2523.msi
+ 2011-09-02 15:43 . 2011-09-02 15:43 697344 c:\windows\Installer\b251a.msi
+ 2011-09-02 15:42 . 2011-09-02 15:42 522752 c:\windows\Installer\b2513.msi
+ 2011-09-02 15:42 . 2011-09-02 15:42 583680 c:\windows\Installer\b250d.msi
+ 2011-09-02 15:42 . 2011-09-02 15:42 678400 c:\windows\Installer\b2507.msi
+ 2011-09-02 15:42 . 2011-09-02 15:42 241152 c:\windows\Installer\b2501.msi
+ 2011-09-02 15:42 . 2011-09-02 15:42 241664 c:\windows\Installer\b24fa.msi
+ 2011-09-02 15:42 . 2011-09-02 15:42 390144 c:\windows\Installer\b24f4.msi
+ 2011-09-02 15:41 . 2011-09-02 15:41 944640 c:\windows\Installer\b24e7.msi
+ 2011-09-02 15:41 . 2011-09-02 15:41 395264 c:\windows\Installer\b24e1.msi
+ 2011-09-02 15:41 . 2011-09-02 15:41 818688 c:\windows\Installer\b24db.msi
+ 2011-09-02 15:41 . 2011-09-02 15:41 312320 c:\windows\Installer\b24ce.msi
+ 2011-09-02 15:40 . 2011-09-02 15:40 457216 c:\windows\Installer\b24c4.msi
+ 2011-09-02 15:44 . 2011-09-02 15:44 102400 c:\windows\Installer\{74DC0593-6BC6-4001-AD5F-D810AFB68D86}\NewShortcut1_47F36D92E58E456DB73C3382737E4C42.exe
+ 2011-09-02 15:31 . 2011-09-02 15:44 213846 c:\windows\hpoins47.dat
+ 2010-01-29 23:13 . 2010-01-29 23:13 1079808 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfc80u.dll
+ 2010-01-29 23:13 . 2010-01-29 23:13 1093632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfc80.dll
+ 2011-09-02 15:41 . 2011-09-02 15:41 1230336 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\msxml4.dll
+ 2010-01-29 21:40 . 2010-01-29 21:40 5105656 c:\windows\WinSxS\amd64_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_7264ef23\mfc90u.dll
+ 2010-01-29 21:40 . 2010-01-29 21:40 5086712 c:\windows\WinSxS\amd64_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_7264ef23\mfc90.dll
+ 2011-09-02 15:46 . 2009-10-21 13:28 1787392 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpfui101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:27 1224192 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpfst101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:29 1482752 c:\windows\system32\spool\drivers\w32x86\hpphotosmart_b110_sea82b\hpf3r101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:28 1787392 c:\windows\system32\spool\drivers\w32x86\3\hpfui101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:27 1224192 c:\windows\system32\spool\drivers\w32x86\3\hpfst101.dll
+ 2011-09-02 15:46 . 2009-10-21 13:29 1482752 c:\windows\system32\spool\drivers\w32x86\3\hpf3r101.dll
+ 2008-10-10 12:56 . 2011-09-02 16:03 1608424 c:\windows\system32\FNTCACHE.DAT
+ 2011-09-02 15:45 . 2011-09-02 15:45 2693632 c:\windows\Installer\b2565.msp
+ 2011-09-02 15:45 . 2011-09-02 15:45 2317312 c:\windows\Installer\b2559.msi
+ 2011-09-02 15:44 . 2011-09-02 15:44 1058304 c:\windows\Installer\b2535.msi
+ 2011-09-02 15:42 . 2011-09-02 15:42 1326080 c:\windows\Installer\b24ee.msi
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D286E828-E6B9-484d-A058-D7323666DE33}]
2009-03-09 23:46 139264 ------w- c:\programmi\RecFree.com\RecFreeToolbar\1.0.23.0\escort.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0508F8F1-08E3-43EE-AAA8-09AD09803084}"= "c:\programmi\RecFree.com\RecFreeToolbar\1.0.23.0\escorTlbr.dll" [2009-03-09 172032]
.
[HKEY_CLASSES_ROOT\clsid\{0508f8f1-08e3-43ee-aaa8-09ad09803084}]
[HKEY_CLASSES_ROOT\escorTlbr.DskBnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
[HKEY_CLASSES_ROOT\escorTlbr.DskBnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-18 39408]
"OM2_Monitor"="c:\programmi\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2008-11-07 95536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-17 64512]
"ATICCC"="c:\programmi\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-01 16208384]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2007-06-01 257088]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"egui"="c:\programmi\ESET\ESET NOD32 Antivirus\egui.exe" [2009-10-07 1461080]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"TkBellExe"="c:\programmi\Real\RealPlayer\update\realsched.exe" [2011-01-25 274608]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2011-04-08 254696]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"MSN Toolbar"="c:\programmi\MSN Toolbar\Platform\4.0.0357.1\mswinext.exe" [2009-11-16 240992]
"Microsoft Default Manager"="c:\programmi\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
.
c:\documents and settings\Totero\Menu Avvio\Programmi\Esecuzione automatica\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\programmi\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio Veloce di WinZip.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2008-10-17 106560]
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
ImageMixer 3 SE Camera Monitor Ver.4.5.lnk - c:\programmi\PIXELA\ImageMixer 3 SE Ver.4.5\Transfer Utility\CameraMonitor.exe [2010-11-12 406896]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\TipicIM\\TipicIM.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Programmi\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23834:TCP"= 23834:TCP:spport
"24850:TCP"= 24850:TCP:spport
"12593:TCP"= 12593:TCP:spport
"12849:TCP"= 12849:TCP:spport
"5187:TCP"= 5187:TCP:spport
"8170:TCP"= 8170:TCP:spport
.
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [08/10/2008 9.50.14 35168]
R2 DriverX;DriverX;c:\windows\system32\drivers\DRIVERX.SYS [12/03/1997 14.57.58 25792]
R2 ekrn;Eset Service;c:\programmi\Eset\ESET NOD32 Antivirus\ekrn.exe [07/10/2009 9.16.50 472280]
R2 MBAMService;MBAMService;c:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe [27/08/2011 21.03.02 366640]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [03/11/2006 19.19.58 13592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [27/08/2011 21.02.58 22712]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [23/05/2011 9.08.41 136176]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [23/05/2011 9.08.41 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [27/08/2011 21.03.00 41272]
S3 MSHUSBVideo;NX6000/NX3000/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [18/10/2008 16.43.10 34136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-08-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2011-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-05-23 07:08]
.
2011-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-05-23 07:08]
.
2011-09-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
.
2011-09-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
.
2011-09-03 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
.
2011-09-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-789336058-725345543-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-789336058-725345543-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Translate with &Babylon - c:\programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{D0E81AC4-1399-4215-AFEE-5347842DD7F7}: NameServer = 62.94.0.1,62.94.0.2
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-09-03 10:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE6D14D4-1530-9097-4BB4-B1C54F726FCB}\InProcServer32*]
"oapclnkjillkchgamcpacjckanemfa"=hex:6a,61,61,6f,63,6e,66,66,64,6d,70,68,6f,69,
6f,61,68,65,6f,6e,00,f9
"napcjndpdmhbmobbndokbkfckjil"=hex:6a,61,6a,6e,6b,6e,6d,69,6e,68,69,6e,66,66,
67,65,64,67,6d,6e,00,68
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\cscdll.dll
.
- - - - - - - > 'explorer.exe'(7756)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\programmi\ATI Technologies\ATI.ACE\CLI.EXE
c:\windows\RTHDCPL.EXE
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\ehome\mcrdsvc.exe
c:\programmi\File comuni\Logishrd\LQCVFX\COCIManager.exe
c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\dllhost.exe
c:\programmi\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
c:\programmi\HP\Digital Imaging\bin\hpqSTE08.exe
c:\programmi\ATI Technologies\ATI.ACE\cli.exe
c:\programmi\ATI Technologies\ATI.ACE\cli.exe
c:\programmi\HP\Digital Imaging\bin\hpqbam08.exe
c:\programmi\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Ora fine scansione: 2011-09-03 10:34:37 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-09-03 08:34
ComboFix2.txt 2011-09-02 08:22
ComboFix3.txt 2011-08-30 20:02
ComboFix4.txt 2011-08-28 08:55
ComboFix5.txt 2011-09-03 08:14
.
Pre-Run: 66.323.206.144 byte disponibili
Post-Run: 66.382.360.576 byte disponibili
.
- - End Of File - - 0A5F9CFE0FCF8ED420CB7A76BB6E1AC6