Si c'e' una webcam integrata, e' un notebook, il problema(gia' mi era successo) e' che per qualche millesiimo di secondo lo schermo diventava tutto nero, poi e' uscito un avviso "programma in esecuzione non compatibli con vista aero", cmq risolto disinstallando il programma, ho fatto la scansione con combo, appena lanciato mcafee mi ha rilevato e fermato un virus, e' uscito un avviso), cmq ho atteso ed ecco il risultato:
ComboFix 09-10-01.05 - Arimondo 03/10/2009 11.35.13.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.3070.1923 [GMT 2:00]
Eseguito da: c:\users\Arimondo\Downloads\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-966093477-1798243618-2112350761-1002
c:\$recycle.bin\S-1-5-21-966093477-1798243618-2112350761-1004
c:\$recycle.bin\S-1-5-21-966093477-1798243618-2112350761-500
c:\users\Arimondo\AppData\Local\bmauht.dat
c:\users\Arimondo\AppData\Local\bmauht_nav.dat
c:\users\Arimondo\AppData\Local\bmauht_navps.dat
c:\users\Arimondo\AppData\Local\Temp\ppcrlui_5164_2
c:\users\Arimondo\AppData\Roaming\.#
c:\windows\Installer\26f58.msi
c:\windows\Installer\2ebe5.msi
c:\windows\Suyin.reg
.
((((((((((((((((((((((((( Files Creati Da 2009-09-03 al 2009-10-03 )))))))))))))))))))))))))))))))))))
.
2009-10-03 09:44 . 2009-10-03 09:44 -------- d-----w- c:\users\Guest\AppData\Local\temp
2009-10-03 09:44 . 2009-10-03 09:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-03 08:35 . 2009-10-03 08:35 -------- d-----w- c:\program files\FreeTime
2009-10-03 05:38 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-02 18:26 . 2009-07-08 11:44 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-10-02 18:26 . 2009-07-08 11:44 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-10-02 18:26 . 2009-07-08 11:44 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-10-02 18:26 . 2009-07-16 10:32 130424 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-10-02 18:26 . 2009-10-02 18:26 -------- d-----w- c:\program files\Common Files\McAfee
2009-10-02 18:26 . 2009-10-02 18:26 -------- d-----w- c:\program files\McAfee.com
2009-10-02 18:26 . 2009-10-03 07:09 -------- d-----w- c:\program files\McAfee
2009-10-02 18:14 . 2009-07-08 11:43 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-10-02 16:26 . 2009-10-02 16:26 -------- d-----w- c:\program files\QuickTime
2009-09-29 15:05 . 2009-09-30 11:14 -------- d-----w- c:\users\Arimondo\AppData\Roaming\DMCache
2009-09-29 13:43 . 2009-09-29 13:43 -------- d-----w- c:\program files\AviSynth 2.5
2009-09-28 08:29 . 2009-09-28 08:29 -------- d-----w- c:\programdata\Apple Computer
2009-09-27 07:22 . 2009-09-27 07:22 -------- d-----w- c:\users\Arimondo\AppData\Local\Thinstall
2009-09-26 16:15 . 2009-09-26 16:15 -------- d-----w- c:\users\Arimondo\AppData\Local\Broad Intelligence
2009-09-26 15:12 . 2009-09-26 15:12 -------- d-----w- c:\users\Arimondo\AppData\Roaming\OpenCandy
2009-09-26 15:12 . 2009-09-26 16:30 -------- d-----w- c:\users\Arimondo\AppData\Roaming\Broad Intelligence
2009-09-26 13:21 . 2009-09-26 13:21 -------- d-----w- c:\users\Arimondo\AppData\Roaming\ATI
2009-09-26 10:00 . 2009-09-26 10:00 -------- d-----w- c:\program files\Common Files\SWF Studio
2009-09-26 09:25 . 2009-09-26 09:34 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-09-26 09:25 . 2008-08-13 09:22 974848 ----a-w- c:\windows\system32\mfc70.dll
2009-09-26 09:25 . 2008-08-13 09:22 487424 ----a-w- c:\windows\system32\msvcp70.dll
2009-09-26 09:25 . 2008-08-13 09:22 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2009-09-26 09:25 . 2008-08-13 09:22 24576 ----a-w- c:\windows\system32\msxml3a.dll
2009-09-25 14:57 . 2009-09-30 15:17 -------- d-----w- c:\program files\CCleaner
2009-09-25 13:10 . 2009-09-25 13:10 -------- d-----w- c:\program files\Trend Micro
2009-09-25 10:24 . 2009-10-01 05:16 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-25 10:24 . 2009-09-25 10:30 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-25 05:08 . 2009-09-25 05:08 -------- d-----w- c:\users\Arimondo\AppData\Roaming\Malwarebytes
2009-09-25 05:08 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-25 05:08 . 2009-09-25 05:08 -------- d-----w- c:\programdata\Malwarebytes
2009-09-25 05:08 . 2009-09-25 05:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-25 05:08 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-24 19:58 . 2009-09-24 19:58 -------- d-----w- c:\users\Arimondo\AppData\Roaming\Media Player Classic
2009-09-24 19:57 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-09-24 19:57 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-09-24 19:57 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-09-24 19:57 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-09-24 19:57 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-09-24 19:57 . 2009-09-24 19:58 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-09-24 19:25 . 2009-09-24 19:42 -------- d-----w- c:\users\Arimondo\AppData\Local\ApplicationHistory
2009-09-24 19:25 . 2009-09-24 19:25 96 ----a-w- c:\users\Arimondo\AppData\Local\fusioncache.dat
2009-09-24 19:22 . 2009-09-24 19:22 -------- d-----w- c:\windows\system32\URTTEMP
2009-09-23 07:31 . 2009-10-02 16:46 -------- d-----w- c:\users\Arimondo\Tracing
2009-09-22 09:18 . 2009-09-24 17:05 -------- d-----w- c:\users\Arimondo\AppData\Roaming\Nokia
2009-09-22 09:18 . 2009-09-22 09:20 -------- d-----w- c:\programdata\PC Suite
2009-09-22 09:17 . 2009-09-22 09:17 -------- d-----w- c:\program files\Common Files\PCSuite
2009-09-22 09:17 . 2009-09-22 09:17 -------- d-----w- c:\program files\Common Files\Nokia
2009-09-22 09:17 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-09-22 09:16 . 2009-09-22 09:16 -------- d-----w- c:\program files\PC Connectivity Solution
2009-09-22 09:08 . 2009-02-09 06:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-09-22 09:07 . 2009-09-22 09:07 -------- d-----w- c:\programdata\Installations
2009-09-22 08:20 . 2009-09-22 09:20 -------- d-----w- c:\users\Arimondo\AppData\Roaming\PC Suite
2009-09-22 08:19 . 2009-09-22 09:17 -------- d-----w- c:\program files\Nokia
2009-09-22 08:18 . 2009-09-22 09:17 -------- d-----w- c:\program files\DIFX
2009-09-21 08:49 . 2009-09-21 08:49 -------- d-----w- c:\users\Arimondo\AppData\Roaming\JAM Software
2009-09-21 08:45 . 2009-09-21 08:45 -------- d-----w- c:\program files\JAM Software
2009-09-21 05:25 . 2009-09-21 05:26 -------- d-----w- c:\windows\system32\ca-ES
2009-09-21 05:25 . 2009-09-21 05:26 -------- d-----w- c:\windows\system32\eu-ES
2009-09-21 05:25 . 2009-09-21 05:26 -------- d-----w- c:\windows\system32\vi-VN
2009-09-20 05:27 . 2009-09-20 05:27 -------- d-----w- C:\found.000
2009-09-19 15:55 . 2009-09-19 15:55 -------- d-----w- c:\windows\system32\EventProviders
2009-09-19 15:13 . 2009-09-19 15:13 -------- d-----w- c:\users\Arimondo\Option
2009-09-19 11:47 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-09-19 11:45 . 2009-04-11 06:28 268800 ----a-w- c:\windows\system32\es.dll
2009-09-19 11:44 . 2009-04-11 06:28 61440 ----a-w- c:\windows\system32\wscsvc.dll
2009-09-19 11:43 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2009-09-19 11:43 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2009-09-19 11:43 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2009-09-19 11:43 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2009-09-19 11:43 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll
2009-09-19 11:43 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-09-19 11:43 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-09-19 11:43 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2009-09-19 11:42 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-09-19 11:42 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-09-19 11:41 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-09-19 10:13 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-19 09:34 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-19 09:34 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-09-19 09:34 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-19 09:34 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-19 09:34 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-19 09:34 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-19 09:34 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-19 09:34 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-19 09:34 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-19 09:34 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-19 09:34 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-19 08:59 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-09-19 08:39 . 2009-06-15 14:54 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-19 08:39 . 2009-06-15 14:53 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-19 08:39 . 2009-06-15 14:52 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-19 08:39 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-19 08:39 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-19 08:39 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-19 08:39 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-19 08:39 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe
2009-09-19 08:37 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-19 08:37 . 2009-04-11 06:28 98816 ----a-w- c:\windows\system32\mfps.dll
2009-09-19 08:37 . 2009-04-11 06:27 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2009-09-19 08:37 . 2009-04-11 06:27 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-09-19 08:37 . 2009-04-11 04:54 2048 ----a-w- c:\windows\system32\mferror.dll
2009-09-19 08:35 . 2009-06-10 11:42 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-09-19 08:34 . 2009-06-04 12:07 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-09-19 08:34 . 2009-04-11 06:28 53248 ----a-w- c:\windows\system32\tsgqec.dll
2009-09-19 08:34 . 2009-04-11 06:28 136192 ----a-w- c:\windows\system32\aaclient.dll
2009-09-19 08:33 . 2009-04-23 12:14 623616 ----a-w- c:\windows\system32\localspl.dll
2009-09-19 08:32 . 2009-06-10 11:38 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-09-19 08:31 . 2009-07-18 11:35 828416 ----a-w- c:\windows\system32\wininet.dll
2009-09-19 08:31 . 2009-07-18 16:01 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-09-19 08:30 . 2009-07-15 12:39 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-09-19 08:30 . 2009-07-15 12:40 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-09-19 08:30 . 2009-07-15 12:39 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-09-19 08:30 . 2009-07-15 12:39 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-09-19 08:30 . 2009-04-11 06:28 1696768 ----a-w- c:\windows\system32\gameux.dll
2009-09-19 08:30 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-19 08:30 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-19 07:37 . 2009-04-23 12:15 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-09-19 07:13 . 2008-10-16 21:13 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-09-19 07:13 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-09-19 07:13 . 2008-10-16 21:09 43544 ----a-w- c:\windows\system32\wups2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-03 09:01 . 2009-03-03 09:29 673070 ----a-w- c:\windows\system32\perfh010.dat
2009-10-03 09:01 . 2009-03-03 09:29 125374 ----a-w- c:\windows\system32\perfc010.dat
2009-10-02 18:29 . 2009-03-03 01:44 -------- d-----w- c:\programdata\McAfee
2009-09-30 15:17 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-09-30 15:17 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-09-22 09:21 . 2009-09-22 09:21 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-09-22 09:20 . 2009-09-22 09:20 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-09-22 07:14 . 2009-03-03 02:47 -------- d-----w- c:\programdata\CyberLink
2009-09-21 05:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-09-21 05:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-21 05:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-09-21 05:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-21 05:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-09-18 18:03 . 2009-09-18 18:03 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-09-14 19:31 . 2009-09-14 19:31 -------- d-----w- c:\users\Guest\AppData\Roaming\PowerCinema
2009-09-14 19:30 . 2009-09-14 19:30 70176 ----a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-09 16:48 . 2009-07-09 16:52 -------- d-----w- c:\program files\Acer
2009-09-09 16:48 . 2009-02-21 00:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-09 16:46 . 2009-09-09 16:46 -------- d-sh--we c:\programdata\Preferiti
2009-09-09 16:46 . 2009-09-09 16:46 -------- d-sh--we c:\programdata\Modelli
2009-09-09 16:46 . 2009-09-09 16:46 -------- d-sh--we c:\programdata\Menu Avvio
2009-09-09 16:46 . 2009-09-09 16:46 -------- d-sh--we c:\programdata\Documenti
2009-09-09 16:46 . 2009-09-09 16:46 -------- d-sh--we c:\programdata\Desktop
2009-09-09 16:46 . 2009-09-09 16:46 -------- d-sh--we c:\programdata\Dati applicazioni
2009-09-09 16:46 . 2009-09-09 16:46 -------- d-sh--we c:\program files\File comuni
2009-07-17 13:54 . 2009-09-19 08:36 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-11 19:01 . 2009-09-19 08:36 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:01 . 2009-09-19 08:36 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:01 . 2009-09-19 08:36 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:01 . 2009-09-19 08:36 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-07-11 17:03 . 2009-09-19 08:36 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-07-09 16:51 . 2009-07-09 16:52 855 ----a-w- c:\windows\regfile_I.cmd
2009-07-09 16:51 . 2009-07-09 16:52 256 ----a-w- c:\windows\regfile_E.cmd
2009-07-09 16:47 . 2009-07-09 16:46 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-07-09 16:41 . 2009-07-09 16:41 0 ----a-w- c:\windows\ativpsrm.bin
2009-07-08 11:44 . 2009-07-08 11:44 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-10-27 10:05 40496 ----a-w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-11-17 135168]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-09 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-18 149280]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-05 1410344]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-03-18 61440]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-11 1833504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-11 6957600]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-12-26 173288]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-02-19 866824]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-09-09 30192]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2008-10-27 199464]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2009-01-20 202024]
"BackupManagerTray"="c:\program files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2009-04-11 249600]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2009-01-20 156968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-04-03 698912]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-09 645328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Arimondo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Orion.lnk]
path=c:\users\Arimondo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orion.lnk
backup=c:\windows\pss\Orion.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):87,97,05,03,7d,3a,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-966093477-1798243618-2112350761-1000]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E4E847AB-BDC8-4971-A5F1-817A090D9D78}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{896E5400-93C8-4A61-AEF6-C4F9BFD03815}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{E154DDC9-97D6-4FEE-9143-157D739FFB7E}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{89A0E4EC-7477-4954-B2DF-B4CD571718A2}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{1FE248E7-9052-41EA-B9B3-81944F658052}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{19957F91-2E55-4CF7-9477-7A2452DF30D6}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2963CD37-3128-414A-A3AF-E832BDE735C0}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{6D7A2188-1E2E-41C1-AC4F-A47CEE3C1A97}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{7B4B48AF-53E8-4130-9D95-C2A23661CDC9}"= c:\program files\Acer Arcade Deluxe\PlayMovie\PlayMovie.exe:Acer Play Movie
"{51E2B4A0-56F4-4E56-94C4-5335397C383C}"= c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe:Acer Play Movie Resident Program
"{E877A9C0-A04F-42D5-8E24-91CD4842FA01}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:Acer HomeMedia
"{FEC773AB-89C2-4C03-BABC-EFB1E3E46B24}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [09/07/2009 19.01.32 75048]
R2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [09/07/2009 18.52.59 723488]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [21/01/2008 4.23.43 21504]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [02/10/2009 20.29.02 206112]
R2 mwlPSDFilter;mwlPSDFilter;c:\windows\System32\drivers\mwlPSDFilter.sys [09/10/2008 16.47.12 19504]
R2 mwlPSDNServ;mwlPSDNServ;c:\windows\System32\drivers\mwlPSDNserv.sys [09/10/2008 16.47.12 16432]
R2 mwlPSDVDisk;mwlPSDVDisk;c:\windows\System32\drivers\mwlPSDVDisk.sys [09/10/2008 16.47.12 59952]
R2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\MWLService.exe [27/10/2008 12.05.28 306736]
R2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [11/04/2009 19.32.00 61184]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [23/09/2008 15.11.34 144632]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [25/09/2009 12.24.24 1153368]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\k57nd60x.sys [04/09/2008 6.12.56 223232]
R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [09/07/2009 18.46.35 22072]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [21/01/2008 4.23.20 179712]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [09/09/2009 18.47.35 30192]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [23/09/2008 15.11.32 50424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HsfXAudioService REG_MULTI_SZ HsfXAudioService
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-03 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-02 19:26]
2009-10-03 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-02 19:26]
2009-10-02 c:\windows\Tasks\User_Feed_Synchronization-{68FC0B3C-5B6A-4CDB-9C02-B1AED4C6A54C}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0410&s=2&o=vp32&d=0709&m=aspire_5536
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-03 11:45
Windows 6.0.6002 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2009-10-03 11.47.49
ComboFix-quarantined-files.txt 2009-10-03 09:47
Pre-Run: 209.169.645.568 byte disponibili
Post-Run: 208.576.536.576 byte disponibili
320 --- E O F --- 2009-10-03 05:38
meglio hijack o combo?
EDIT; durante la scansione mcafee mi ha rilevato che combo mi stava cambiando il registro di sistema, ho dato cmq l'ok, infine ora non trovo combofix installato, a parte il log e l'installer, e' normale?