Ecco il log Combo
ComboFix 10-05-09.04 - Pinuccio 10/05/2010 13.41.12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3071.2367 [GMT 2:00]
Eseguito da: c:\documents and settings\Pinuccio\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\AutoRun.inf
c:\windows\system32\Oleopri20091.dll
c:\windows\system32\timedefw32ex.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((( Files Creati Da 2010-04-10 al 2010-05-10 )))))))))))))))))))))))))))))))))))
.
2010-05-09 17:52 . 2010-05-09 17:52 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\Apple Computer
2010-05-09 11:43 . 2007-10-23 07:27 110592 ----a-w- c:\documents and settings\Pinuccio\Dati applicazioni\U3\temp\cleanup.exe
2010-05-09 11:34 . 2008-05-02 08:41 3493888 ---ha-w- c:\documents and settings\Pinuccio\Dati applicazioni\U3\temp\Launchpad Removal.exe
2010-05-09 11:34 . 2010-05-09 11:43 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\U3
2010-04-14 19:27 . 2010-04-14 19:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Softland
2010-04-14 19:27 . 2010-02-08 15:24 173056 ----a-w- c:\documents and settings\Pinuccio\Dati applicazioni\Softland\FBackup 4\Plugins\OutlookExpressSources.dll
2010-04-14 19:27 . 2010-04-14 22:00 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-04-14 19:27 . 2010-04-14 19:27 -------- d-----w- c:\programmi\Softland
2010-04-14 19:27 . 2010-04-14 19:27 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\Softland
2010-04-13 20:44 . 2010-04-14 19:25 -------- d-----w- C:\FlashLIB
2010-04-13 20:44 . 2010-04-13 20:44 -------- d-----w- c:\windows\FlashCAD
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-10 11:46 . 2010-01-10 13:50 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\Skype
2010-05-10 11:45 . 2010-01-10 11:47 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\uTorrent
2010-05-10 08:07 . 2010-01-10 14:24 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\skypePM
2010-05-10 08:06 . 2010-01-10 13:45 -------- d-----w- c:\programmi\Glary Utilities
2010-05-09 17:49 . 2010-04-27 18:52 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\DVD Flick
2010-05-09 08:36 . 2010-01-10 12:05 -------- d-----w- c:\programmi\Java
2010-05-08 16:04 . 2010-01-10 16:05 -------- d-----w- c:\programmi\Mahjongg - Ancient Mayas
2010-05-03 12:55 . 2010-03-14 20:58 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-05-02 10:58 . 2010-01-10 11:58 893952 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-05-02 10:58 . 2010-01-10 11:58 574632 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-05-02 10:58 . 2010-01-10 11:58 443344 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-05-02 10:58 . 2010-01-10 11:58 866224 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-05-02 10:58 . 2010-01-10 11:58 871320 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-05-02 10:58 . 2010-01-10 11:58 1598464 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-05-02 10:58 . 2010-01-10 11:58 834248 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-05-02 10:58 . 2010-01-10 11:58 1285864 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-05-01 12:11 . 2010-04-03 13:18 -------- d-----w- c:\programmi\123 Free Solitaire
2010-05-01 09:33 . 2010-05-01 09:33 -------- d-----w- c:\programmi\eMule
2010-04-29 13:39 . 2010-03-14 20:58 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-03-14 20:58 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-28 14:47 . 2010-01-10 12:12 -------- d-----w- c:\programmi\uTorrent
2010-04-27 19:13 . 2010-02-18 17:53 566432 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-04-27 19:13 . 2010-01-10 12:11 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-04-27 19:13 . 2010-01-10 11:58 15880 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-04-27 19:13 . 2010-01-10 11:58 397480 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-04-27 19:13 . 2010-01-10 11:58 211600 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-04-27 19:13 . 2010-02-18 17:53 221920 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-04-27 19:13 . 2010-01-10 11:58 167824 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-04-27 19:13 . 2010-01-10 11:58 6306640 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Resources.dll
2010-04-27 19:13 . 2010-01-10 11:58 335728 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-04-27 19:13 . 2010-01-10 11:58 95248 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-04-27 19:13 . 2010-02-18 17:53 16456 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-04-27 19:13 . 2010-01-10 11:58 967640 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-04-27 19:12 . 2010-04-27 19:12 755096 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2010-04-27 18:57 . 2010-01-10 11:18 -------- d-----w- c:\programmi\CCleaner
2010-04-27 18:51 . 2010-04-27 18:51 -------- d-----w- c:\programmi\DVD Flick
2010-04-27 16:03 . 2010-04-27 16:03 -------- d-----w- c:\programmi\TorrentFetcher
2010-04-25 18:49 . 2010-01-10 13:50 -------- d-----r- c:\programmi\Skype
2010-04-23 10:34 . 2010-04-23 10:34 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PhotoMail
2010-04-23 10:34 . 2010-04-23 10:34 -------- d-----w- c:\programmi\PhotoMail Maker
2010-04-21 10:56 . 2010-04-21 10:56 242696 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgtdix.sys
2010-04-21 10:56 . 2010-01-10 11:37 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-21 10:55 . 2010-04-21 10:55 1689952 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.dll
2010-04-16 14:40 . 2010-04-16 14:40 -------- d-----w- c:\programmi\Auslogics
2010-04-13 20:51 . 2004-08-19 12:00 80382 ----a-w- c:\windows\system32\perfc010.dat
2010-04-13 20:51 . 2004-08-19 12:00 482022 ----a-w- c:\windows\system32\perfh010.dat
2010-04-12 15:29 . 2010-05-09 08:36 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-09 13:12 . 2010-02-09 14:22 -------- d-----w- c:\programmi\IncrediMail
2010-04-05 07:54 . 2010-04-05 07:54 516480 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\EmailScannerAddin.dll
2010-04-05 07:54 . 2010-04-05 07:54 17632 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
2010-04-03 13:18 . 2010-04-03 13:18 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\123 Free Solitaire
2010-04-03 13:07 . 2010-04-03 12:39 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\TreeCardGames
2010-03-31 12:10 . 2010-03-31 12:10 -------- d-----w- c:\programmi\File comuni\Java
2010-03-31 12:10 . 2010-03-31 12:10 503808 ----a-w- c:\documents and settings\Pinuccio\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a98f2b5-n\msvcp71.dll
2010-03-31 12:10 . 2010-03-31 12:10 499712 ----a-w- c:\documents and settings\Pinuccio\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a98f2b5-n\jmc.dll
2010-03-31 12:10 . 2010-03-31 12:10 348160 ----a-w- c:\documents and settings\Pinuccio\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a98f2b5-n\msvcr71.dll
2010-03-31 12:10 . 2010-03-31 12:10 61440 ----a-w- c:\documents and settings\Pinuccio\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-29177348-n\decora-sse.dll
2010-03-31 12:10 . 2010-03-31 12:10 12800 ----a-w- c:\documents and settings\Pinuccio\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-29177348-n\decora-d3d.dll
2010-03-30 12:49 . 2010-03-30 12:49 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\Canneverbe Limited
2010-03-30 12:49 . 2010-01-14 14:44 64744 ----a-w- c:\documents and settings\Pinuccio\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-03-30 12:49 . 2010-03-30 12:49 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Canneverbe Limited
2010-03-30 12:48 . 2010-03-30 12:48 -------- d-----w- c:\programmi\CDBurnerXP
2010-03-30 12:45 . 2010-03-30 12:45 -------- d-----w- c:\programmi\MSBuild
2010-03-30 12:45 . 2010-03-30 12:45 -------- d-----w- c:\programmi\Reference Assemblies
2010-03-28 14:02 . 2010-03-28 12:56 -------- d--h--w- c:\programmi\FX Uninstall Information
2010-03-28 12:16 . 2010-03-28 12:16 -------- d-----w- c:\programmi\Eusing Free Registry Cleaner
2010-03-28 11:19 . 2010-02-21 11:22 -------- d-----w- c:\programmi\BoontyGames
2010-03-28 10:51 . 2010-03-28 10:51 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\HdO Adventure
2010-03-25 13:46 . 2010-03-25 13:46 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\MetaProducts
2010-03-25 13:46 . 2010-03-25 13:46 -------- d-----w- c:\programmi\Download Express
2010-03-20 19:51 . 2010-01-10 13:46 -------- d-----w- c:\documents and settings\Pinuccio\Dati applicazioni\GlarySoft
2010-03-19 18:57 . 2010-03-14 19:53 -------- d-----w- c:\programmi\Trend Micro
2010-03-17 10:50 . 2010-03-17 10:50 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-17 10:50 . 2010-01-10 11:37 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-17 10:49 . 2010-01-10 11:37 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-16 19:04 . 2010-03-16 19:04 -------- d-----w- c:\programmi\p-nand-q.com
2010-02-24 13:11 . 2008-04-13 10:17 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-24 09:43 . 2010-03-15 13:31 352256 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{FD28B3FA-74C5-4F4F-9C6E-A303AB888DAF}\OFFLINE\BB22A901\76AC2E42\Scan.dll
2010-02-18 17:53 . 2010-02-18 17:53 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-18 17:53 . 2010-02-18 17:53 95024 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-02-18 17:53 . 2010-02-18 17:53 566608 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\sbap.dll
2010-02-18 17:53 . 2010-02-18 17:53 1230160 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-02-18 17:53 . 2010-02-18 17:53 247120 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-02-16 19:05 . 2008-04-13 16:54 2149888 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2008-04-13 18:55 2028032 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2010-03-11 14:51 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2008-04-13 17:13 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-13 10:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 13:04 1664256 ----a-w- c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programmi\Skype\\Phone\Skype.exe" [2010-04-20 26192680]
"IncrediMail"="c:\programmi\IncrediMail\bin\IncMail.exe" [2010-04-23 353736]
"uTorrent"="c:\programmi\uTorrent\uTorrent.exe" [2010-04-27 321328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 16248320]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"MULTIMEDIA KEYBOARD"="c:\programmi\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-12 167936]
"Sunkist2k"="c:\programmi\Multimedia Card Reader\shwicon2k.exe" [2004-12-10 139264]
"LifeCam"="c:\programmi\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"VIRIT LITE MONITOR"="c:\vexplite\MONLITE.EXE" [2010-05-07 278528]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\Pinuccio\Menu Avvio\Programmi\Esecuzione automatica\
MRU-Blaster Silent Clean.lnk - c:\programmi\MRU-Blaster\mrublaster.exe [2004-3-28 1216512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-17 10:50 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Programmi\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Programmi\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Documents and Settings\\Pinuccio\\Impostazioni locali\\Dati applicazioni\\TVLC\\Sandbox\\2009.12.14T00.29\\Virtual\\STUBEXE\\@PROGRAMFILES@\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmi\\Download Express\\dep.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\eMule\\eMule.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"41748:TCP"= 41748:TCP:emule
"43755:UDP"= 43755:UDP:emule
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10/01/2010 13.59.00 64288]
R0 VIRAGTLT;VIRAGTLT;c:\windows\system32\drivers\VIRAGTLT.sys [11/11/2009 9.53.20 45312]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/01/2010 13.37.33 216200]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/01/2010 13.37.37 242896]
R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [10/01/2010 14.12.59 6656]
R2 avg9wd;AVG Free WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [17/03/2010 12.50.19 308064]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 17.52.57 1285864]
R2 nhksrv;Netropa NHK Server;c:\programmi\Netropa\Multimedia Keyboard\nhksrv.exe [10/01/2010 14.12.59 28672]
R2 viritsvclite;VirIT eXplorer Lite;c:\vexplite\VIRITSVC.EXE [27/11/2009 16.10.32 69632]
.
Contenuto della cartella 'Scheduled Tasks'
2010-05-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 10:58]
2010-05-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-05-10 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2010-01-10 19:36]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.tiscali.it/
mWindow Title =
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Scarica con Download &Express - c:\programmi\Download Express\Add_Url.htm
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
FF - ProfilePath - c:\documents and settings\Pinuccio\Dati applicazioni\Mozilla\Firefox\Profiles\kljc6mur.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Cerca
FF - prefs.js: browser.startup.homepage - hxxp://www.tiscali.it/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search=
FF - component: c:\documents and settings\Pinuccio\Dati applicazioni\Mozilla\Firefox\Profiles\kljc6mur.default\extensions\{D249FD00-4DF9-11D9-9FDC-0080481ADA61}\components\mpint.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-10 13:45
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2544)
c:\windows\system32\WININET.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\AVG\AVG9\avgchsvx.exe
c:\programmi\AVG\AVG9\avgrsx.exe
c:\programmi\AVG\AVG9\avgcsrvx.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Microsoft LifeCam\MSCamS32.exe
c:\programmi\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\AVG\AVG9\avgnsx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\programmi\Skype\Phone\Skype.exe
c:\programmi\Netropa\Multimedia Keyboard\TrayMon.exe
c:\programmi\Netropa\Onscreen Display\OSD.exe
c:\programmi\IncrediMail\bin\IMApp.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\Skype\Plugin Manager\skypePM.exe
c:\programmi\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Ora fine scansione: 2010-05-10 13:48:17 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-05-10 11:48
Pre-Run: 184.001.974.272 byte disponibili
Post-Run: 184.007.905.280 byte disponibili
- - End Of File - - 1F87998BA79B0FAC85C86D85E4A7A6CA