ComboFix 09-11-16.05 - Lino 16/11/2009 21.03.12..1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.502.337 [GMT 1:00]
Eseguito da: c:\documents and settings\Lino\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lino\php.exe
c:\recycler\S-1-5-21-0243556031-888888379-781863308-1455
c:\recycler\S-1-5-21-0243936033-3052116371-381863308-1811
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\sys32.exe
c:\windows\system32\pwdmon.dll
.
((((((((((((((((((((((((( Files Creati Da 2009-10-16 al 2009-11-16 )))))))))))))))))))))))))))))))))))
.
2009-11-16 19:31 . 2009-11-16 19:31 -------- d-----w- c:\programmi\Trend Micro
2009-11-14 16:13 . 2009-11-14 16:13 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\PlayFirst
2009-11-14 16:13 . 2009-11-14 16:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PlayFirst
2009-11-14 16:12 . 2009-11-14 16:12 -------- d-----w- c:\programmi\PopCap Games
2009-11-13 13:27 . 2009-11-16 19:51 43520 ----a-w- c:\documents and settings\Lino\pxxy.exe
2009-11-10 17:52 . 2009-11-10 17:52 -------- d-----w- c:\windows\system32\QuickTime
2009-11-10 17:51 . 2009-11-10 17:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TechSmith
2009-11-10 17:51 . 2009-11-10 17:51 -------- d-----w- c:\programmi\QuickTime
2009-11-10 17:50 . 2009-11-10 17:50 -------- d-----w- c:\programmi\File comuni\TechSmith Shared
2009-11-10 17:50 . 2009-11-10 17:50 -------- d-----w- c:\programmi\TechSmith
2009-11-09 20:37 . 2009-11-09 20:37 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\dvdcss
2009-11-09 19:49 . 2005-06-15 02:00 102400 ----a-w- c:\windows\system32\tsccvid.dll
2009-11-09 19:25 . 2009-11-09 19:25 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AVS4YOU
2009-11-09 19:24 . 2009-11-09 19:24 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\AVS4YOU
2009-11-09 19:23 . 2009-11-09 19:41 -------- d-----w- c:\programmi\File comuni\AVSMedia
2009-11-09 19:22 . 2009-11-09 19:42 -------- d-----w- c:\programmi\AVS4YOU
2009-11-06 08:18 . 2009-11-12 14:38 43520 ----a-w- c:\documents and settings\Lino\p4xy.exe
2009-11-05 09:56 . 2009-11-09 19:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\file joy proc deaf
2009-11-05 09:56 . 2009-11-05 10:03 684032 ----a-w- c:\documents and settings\All Users\Dati applicazioni\file joy proc deaf\first move.exe
2009-11-05 09:56 . 2009-11-05 09:59 -------- d-----w- c:\programmi\TorrentSpeeder
2009-11-05 09:45 . 2009-11-05 09:46 -------- d-----w- c:\programmi\PartyGaming
2009-10-28 22:31 . 2009-10-28 22:31 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-10-27 19:25 . 2009-10-28 22:28 -------- d-----w- c:\programmi\Total Video Converter
2009-10-27 12:03 . 2009-10-27 12:03 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-27 12:03 . 2009-11-06 16:33 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\skypePM
2009-10-27 12:02 . 2009-11-06 16:51 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\Skype
2009-10-27 12:00 . 2009-10-27 12:00 -------- d-----w- c:\programmi\File comuni\Skype
2009-10-27 12:00 . 2009-10-27 12:01 -------- d-----r- c:\programmi\Skype
2009-10-27 12:00 . 2009-10-27 12:00 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2009-10-21 15:17 . 2009-10-21 15:17 -------- d-----w- c:\windows\Sun
2009-10-21 15:15 . 2009-10-21 15:15 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-21 15:15 . 2009-10-21 15:15 -------- d-----w- c:\programmi\Java
2009-10-21 15:14 . 2009-10-21 15:14 152576 ----a-w- c:\documents and settings\Lino\Dati applicazioni\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-20 12:20 . 2009-10-21 12:19 45056 ----a-w- c:\documents and settings\Lino\ndp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-11 15:16 . 2008-09-06 14:16 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-11-11 00:42 . 2009-03-22 19:41 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\U3
2009-11-10 17:53 . 2009-10-02 14:19 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\vlc
2009-11-09 19:45 . 2008-08-19 20:52 71120 ----a-w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-11-09 19:43 . 2008-11-04 20:11 -------- d-----w- c:\programmi\TeamViewer3
2009-11-07 14:08 . 2009-01-21 20:18 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\DataCast
2009-11-07 14:08 . 2008-08-19 20:54 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-11-07 14:05 . 2008-08-19 19:55 -------- d-----w- c:\programmi\Microsoft Works
2009-11-07 14:02 . 2009-10-03 16:59 -------- d-----w- c:\programmi\File comuni\HP
2009-11-06 09:15 . 2008-08-20 15:51 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\uTorrent
2009-11-04 00:21 . 2009-10-16 12:16 24064 ----a-w- c:\documents and settings\Lino\pxy.exe
2009-10-28 22:27 . 2008-08-20 20:51 -------- d-----w- c:\programmi\Sony
2009-10-28 22:26 . 2009-01-21 20:35 -------- d-----w- c:\programmi\MyFree Codec
2009-10-27 21:45 . 2009-10-09 17:31 -------- d-----w- c:\programmi\eMule
2009-10-27 08:36 . 1980-01-01 07:00 85330 ----a-w- c:\windows\system32\perfc010.dat
2009-10-27 08:36 . 1980-01-01 07:00 492504 ----a-w- c:\windows\system32\perfh010.dat
2009-10-15 17:35 . 2009-10-08 12:59 45056 ----a-w- c:\documents and settings\Lino\p3xy.exe
2009-10-09 15:44 . 2009-10-09 15:44 -------- d-----w- c:\programmi\Sega
2009-10-09 14:08 . 2009-10-09 14:08 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\Creative
2009-10-09 14:05 . 2009-10-09 14:05 -------- d-----w- c:\programmi\Creative
2009-10-07 15:36 . 2009-10-07 15:36 -------- d-----w- c:\programmi\KaraFun
2009-10-07 15:36 . 2009-10-07 15:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Recisio
2009-10-07 13:17 . 2009-10-06 13:07 47616 ----a-w- c:\documents and settings\Lino\nd.exe
2009-10-04 07:27 . 2009-10-03 15:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-10-03 17:15 . 2009-10-03 14:47 119853 ----a-w- c:\windows\hpoins11.dat
2009-10-03 17:05 . 2009-10-03 17:05 -------- d-----w- c:\documents and settings\Lino\Dati applicazioni\HP
2009-10-03 17:05 . 2008-09-21 21:17 -------- d-----w- c:\programmi\HP
2009-10-03 17:05 . 2009-10-03 17:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\HP
2009-10-03 17:01 . 2009-10-03 17:01 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Sonic
2009-10-03 16:56 . 2008-09-21 21:15 -------- d-----w- c:\programmi\Hewlett-Packard
2009-10-03 16:54 . 2009-10-03 16:54 -------- d-----w- c:\programmi\File comuni\Hewlett-Packard
2009-10-02 14:30 . 2009-10-02 14:30 -------- d-----w- c:\programmi\Microsoft
2009-10-02 14:29 . 2009-10-02 14:28 -------- d-----w- c:\programmi\Windows Live
2009-10-02 14:29 . 2009-10-02 14:29 -------- d-----w- c:\programmi\Windows Live SkyDrive
2009-10-02 14:22 . 2009-10-02 14:22 0 ----a-w- c:\windows\nsreg.dat
2009-10-02 14:22 . 2009-10-02 14:22 -------- d-----w- c:\programmi\Ask.com
2009-10-02 14:21 . 2009-10-02 14:21 -------- d-----w- c:\programmi\File comuni\DVDVideoSoft
2009-10-02 14:21 . 2009-10-02 14:21 -------- d-----w- c:\programmi\DVDVideoSoft
2009-10-02 14:19 . 2009-10-02 14:19 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-10-02 14:16 . 2009-10-02 14:16 -------- d-----w- c:\programmi\VideoLAN
2009-10-02 13:53 . 2009-10-02 13:53 -------- d-----w- c:\programmi\Google
2009-10-02 13:37 . 2008-11-04 20:53 -------- d-----w- c:\programmi\ESET
2009-10-02 13:35 . 2008-08-19 21:05 -------- d-----w- c:\programmi\File comuni\Symantec Shared
2009-10-02 13:18 . 2009-10-02 13:18 19 ----a-w- c:\windows\system32\drivers\adidsl.cfg
2009-10-02 13:18 . 2009-10-02 13:18 -------- d-----w- c:\programmi\ARESCOM
2009-10-02 13:11 . 2008-09-03 15:23 -------- d-----w- c:\programmi\DivX
2009-09-23 14:37 . 2009-10-03 15:13 34112 ----a-w- c:\documents and settings\Lino\Dati applicazioni\Mozilla\Firefox\Profiles\4o4qyhzi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-09-23 14:37 . 2009-10-03 15:13 32448 ----a-w- c:\documents and settings\Lino\Dati applicazioni\Mozilla\Firefox\Profiles\4o4qyhzi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-09-23 14:37 . 2009-10-03 15:13 22352 ----a-w- c:\documents and settings\Lino\Dati applicazioni\Mozilla\Firefox\Profiles\4o4qyhzi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-09-11 14:17 . 1980-01-01 07:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 1980-01-01 07:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 1980-01-01 07:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 1980-01-01 07:00 247326 ----a-w- c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-06-16 15:22 1144712 ----a-w- c:\programmi\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\programmi\Ask.com\GenericAskToolbar.dll" [2009-06-16 1144712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\programmi\Ask.com\GenericAskToolbar.dll" [2009-06-16 1144712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\programmi\IBM\Messages By IBM\ibmmessages.exe" [2004-08-06 442368]
"Creative WebCam Tray"="c:\programmi\Creative\Shared Files\CamTray.exe" [2005-10-27 299008]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-02 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-30 118784]
"TPKMAPHELPER"="c:\programmi\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-05 897024]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-08-07 94208]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2003-12-25 208896]
"UC_Start"="c:\programmi\IBM\Updater\\ucstartup.exe" [2004-06-25 36864]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-09-02 127035]
"ibmmessages"="c:\programmi\IBM\Messages By IBM\\ibmmessages.exe" [2004-08-06 442368]
"IBMPRC"="c:\ibmtools\UTILS\ibmprc.exe" [2004-03-19 90112]
"QCTRAY"="c:\programmi\ThinkPad\ConnectUtilities\QCTRAY.EXE" [2004-08-18 708608]
"QCWLICON"="c:\programmi\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2004-08-18 81920]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-07-29 110592]
"BMMLREF"="c:\programmi\ThinkPad\Utilities\BMMLREF.EXE" [2004-07-29 20480]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-07-29 397312]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"ANIWZCS2Service"="c:\programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"D-Link D-Link Wireless N DWA-140"="c:\programmi\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe" [2007-06-21 1658880]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-21 149280]
"S3TRAY2"="S3Tray2.exe" - c:\windows\system32\S3Tray2.exe [2001-10-12 69632]
"TrackPointSrv"="tp4serv.exe" - c:\windows\system32\tp4serv.exe [2003-11-13 94208]
"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2002-09-04 53248]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\DLink\Software Bluetooth\BTTray.exe [2003-10-29 503875]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-19 24576]
DSLMON.lnk - c:\programmi\ARESCOM\Modem Telindus Arescom ND220\dslmon.exe [2009-10-2 917600]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
2004-08-18 10:30 258048 ----a-w- c:\windows\system32\QConGina.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Avvio rapido HP Photosmart Premier.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Avvio rapido HP Photosmart Premier.lnk
backup=c:\windows\pss\Avvio rapido HP Photosmart Premier.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Lino^Menu Avvio^Programmi^Esecuzione automatica^Utilità controllo supporti di Cyber-shot Viewer.lnk]
path=c:\documents and settings\Lino\Menu Avvio\Programmi\Esecuzione automatica\Utilità controllo supporti di Cyber-shot Viewer.lnk
backup=c:\windows\pss\Utilità controllo supporti di Cyber-shot Viewer.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"%ProgramFiles%\\IBM\\Updater\\jre\\bin\\java.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Programmi\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [19/08/2008 22.18.47 16384]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [24/09/2004 1.39.58 64256]
R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [01/01/1980 8.00.00 13904]
S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [09/10/2009 19.16.12 91830]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.sys [19/08/2008 22.16.16 12288]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [02/01/2009 17.50.38 476416]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - mbr
.
Contenuto della cartella 'Scheduled Tasks'
2008-08-19 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2008-08-19 08:37]
2009-11-15 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-11-16 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-11-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\programmi\Ask.com\UpdateTask.exe [2009-06-16 15:22]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Invia a &Bluetooth - c:\programmi\DLink\Software Bluetooth\btsendto_ie_ctx.htm
TCP: {05022B30-4853-4CA2-A5CB-490089087408} = 192.168.1.1
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Lino\Dati applicazioni\Mozilla\Firefox\Profiles\4o4qyhzi.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.google.itFF - component: c:\programmi\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Lino\Dati applicazioni\Mozilla\Firefox\Profiles\4o4qyhzi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-Microsoft WinUpdate - c:\windows\system32\msupdte.exe
HKLM-Run-UC_SMB - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-16 21:21
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2416)
c:\windows\system32\WININET.dll
c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\System32\ibmpmsvc.exe
c:\windows\system32\S24EvMon.exe
c:\programmi\DLink\Software Bluetooth\bin\btwdins.exe
c:\programmi\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\System32\QCONSVC.EXE
c:\windows\system32\RegSrvc.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RunDll32.exe
c:\programmi\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Ora fine scansione: 2009-11-16 21:29 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-11-16 20:28
Ecco il log:
Pre-Run: 3.115.491.328 byte disponibili
Post-Run: 3.565.850.624 byte disponibili
- - End Of File - - FB30FB7BDB6AAFB9897D3E9888360453