ComboFix 08-09-20.05 - nano 2008-09-22 15.39.54.1 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6000.0.1252.1.1040.18.2447 [GMT 2:00]
Eseguito da: C:\Users\nano\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
C:\Program Files\Mozilla Firefox\patch.exe
C:\Program Files\pppatc~1
C:\Program Files\pppatc~1\w?aclt.exe
C:\Users\nano\AppData\Local\Microsoft\Windows\Temporary Internet Files\bestwiner.stt
C:\Users\nano\AppData\Roaming\PPPATC~1
C:\Users\nano\AppData\Roaming\PPPATC~1\?ppPatch\
C:\Users\nano\AppData\Roaming\PPPATC~1\mmc.exe
C:\Users\nano\Documents\SMANTE~1
C:\Windows\system32\actskn43.ocx
C:\Windows\system32\ensgrori.ini
C:\Windows\system32\jusched.exe
C:\Windows\system32\vflxeelr.ini
C:\Windows\system32\xcfrapjy.ini
.
((((((((((((((((((((((((( Files Creati Da 2008-08-22 al 2008-09-22 )))))))))))))))))))))))))))))))))))
.
Nessun nuovo file creato in questo arco di tempo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-22 13:38 --------- d-----w C:\Users\nano\AppData\Roaming\Skype
2008-09-22 13:14 --------- d-----w C:\Program Files\Mirc
2008-09-22 13:01 --------- d-----w C:\Users\nano\AppData\Roaming\skypePM
2008-09-19 20:08 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-19 20:07 --------- d-----w C:\Users\nano\AppData\Roaming\Malwarebytes
2008-09-19 20:07 --------- d-----w C:\ProgramData\Malwarebytes
2008-09-19 16:45 40,960 ----a-w C:\Windows\system32\drivers\VIRAGTLT.SYS
2008-09-19 15:32 --------- d-----w C:\Program Files\Trend Micro
2008-09-18 21:09 --------- d-----w C:\Program Files\Manage PC Shut Down
2008-09-18 17:40 --------- d-----w C:\Program Files\eMule
2008-09-18 17:28 --------- d-----w C:\Users\nano\AppData\Roaming\uTorrent
2008-09-17 19:52 --------- d-----w C:\Program Files\BearShare
2008-09-17 19:16 --------- d-----w C:\Program Files\Soulseek
2008-09-16 18:57 --------- d-----w C:\ProgramData\DFX
2008-09-16 18:57 --------- d-----w C:\Program Files\DFX
2008-09-16 18:57 --------- d-----w C:\Program Files\Common Files\DFX
2008-09-11 13:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-10 19:26 --------- d-----w C:\Users\nano\AppData\Roaming\Spore
2008-09-10 19:03 --------- d-----w C:\Program Files\Electronic Arts
2008-09-10 16:05 --------- d-----w C:\Users\nano\AppData\Roaming\Joost
2008-09-10 15:45 --------- d-----w C:\Program Files\RadarSync
2008-09-10 15:39 --------- d-----w C:\Program Files\Joost
2008-09-09 22:04 38,528 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-09-09 22:03 17,200 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-09-09 19:42 --------- d-----w C:\Program Files\MagicISO
2008-09-09 19:29 355,584 ----a-w C:\Windows\System32\TuneUpDefragService.exe
2008-09-09 19:29 --------- d-----w C:\Users\nano\AppData\Roaming\TuneUp Software
2008-09-09 19:29 --------- d-----w C:\ProgramData\TuneUp Software
2008-09-09 19:29 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-09-09 19:27 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-08 13:31 --------- d-----w C:\ProgramData\Skype
2008-09-08 13:31 --------- d-----w C:\Program Files\Skype
2008-09-08 13:31 --------- d-----w C:\Program Files\Common Files\Skype
2008-09-08 13:28 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-27 16:44 --------- d-----w C:\Program Files\RelevantKnowledge
2008-08-27 11:07 --------- d-----w C:\Program Files\CD Mp3 Extractor
2008-08-27 11:04 --------- d-----w C:\Program Files\Wave 2 Mp3
2008-08-27 10:51 --------- d-----w C:\Program Files\SoftwareClub.ws
2008-08-25 11:45 --------- d-----w C:\Program Files\Halto
2008-08-25 11:35 --------- d-----w C:\ProgramData\Apple Computer
2008-08-25 10:09 --------- d-----w C:\Program Files\Apple Software Update
2008-08-25 10:08 --------- d-----w C:\Users\nano\AppData\Roaming\Apple Computer
2008-08-25 10:07 --------- d-----w C:\Program Files\Bonjour
2008-08-25 10:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-08-23 15:50 --------- d-----w C:\ProgramData\Roxio
2008-08-19 12:53 --------- d-----w C:\Users\nano\AppData\Roaming\Builder
2008-08-19 12:50 --------- d-----w C:\Users\nano\AppData\Roaming\qliner
2008-08-19 12:40 --------- d-----w C:\Program Files\Qliner Hotkeys
2008-08-16 01:36 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-15 15:17 --------- d---a-w C:\ProgramData\TEMP
2008-08-15 13:35 --------- d-----w C:\Users\nano\AppData\Roaming\TeraCopy
2008-08-14 23:10 --------- d-----w C:\Program Files\Mass Effect
2008-08-14 23:05 --------- d-----w C:\ProgramData\Media Center Programs
2008-08-14 23:05 --------- d-----w C:\Program Files\Common Files\BioWare
2008-08-14 10:08 --------- d-----w C:\Program Files\Empire Interactive
2008-08-14 09:19 --------- d-----w C:\Program Files\NeroInstall.bak
2008-08-14 09:17 --------- d-----w C:\Users\nano\AppData\Roaming\Nero
2008-08-14 09:15 --------- d-----w C:\Program Files\Common Files\Nero
2008-08-14 09:12 --------- d-----w C:\ProgramData\Nero
2008-08-14 09:12 --------- d-----w C:\Program Files\Nero
2008-08-14 08:23 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-14 08:13 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-08-14 07:45 --------- d-----w C:\Program Files\Extension Changer
2008-08-13 21:52 --------- d-----w C:\Users\nano\AppData\Roaming\Microsoft Games
2008-08-06 09:39 --------- d-----w C:\Program Files\CCleaner
2008-08-06 09:08 --------- d-----w C:\Program Files\Mp3 File Editor
2008-08-06 09:04 --------- d-----w C:\Program Files\Game Graphic Studio
2008-08-04 22:28 174 --sha-w C:\Program Files\desktop.ini
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-07-15 23:55 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-07-15 23:53 444,952 ----a-w C:\Windows\System32\wrap_oal.dll
2008-07-15 23:53 109,080 ----a-w C:\Windows\System32\OpenAL32.dll
2008-07-08 22:49 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
2008-06-03 13:26 22,328 ----a-w C:\Users\nano\AppData\Roaming\PnkBstrK.sys
2008-05-13 15:06 0 ----a-w C:\Users\nano\AppData\Roaming\wklnhst.dat
2008-05-15 18:38 22 --sha-w C:\Windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 36352]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 65536]
"XboxStat"="c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 734264]
"00Hotkeys"="C:\Program Files\Qliner Hotkeys\HotKeys.exe" [2006-12-02 45056]
"spc1000"="C:\Windows\vspc1000.exe" [2007-07-12 675840]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-09-19 245760]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 C:\Windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="C:\Windows\SMINST\launcher.exe" [2007-04-03 44168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWinKeys"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=pxdnoo.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-11-06 20:00 8530464 C:\Windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-11-06 20:00 81920 C:\Windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-11-06 20:00 86016 C:\Windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateReg]
--a------ 2007-04-07 02:56 54936 C:\Windows\System32\jureg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2006-11-02 14:36 201728 C:\Program Files\Windows Media Player\wmpnscfg.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"265bb3c3"=rundll32.exe "C:\Windows\system32\idrayhfk.dll",b
"runner1"=C:\Windows\faceback.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-706010174-775629330-2711164088-1001]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{06CA90DE-DFB3-4B43-91D3-1B389F234F16}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{70B69435-A063-4796-96D8-07F97B0BD198}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{E0EE8557-CAB9-47DC-B918-D1C83513B918}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{A9A72485-CFF3-4D61-A690-53C0C5D58487}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{0D9B9856-91E9-477D-BDE7-402B0252F4F7}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{8D4A32BF-3947-4945-8816-75EC9390C8F0}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{68B74467-C34B-408C-B081-4FE0EFFE93AE}"= TCP:9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{A4D2ECCE-8EBB-4961-B5C8-80086B09692D}"= TCP:1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{273F4132-6DD9-4C8B-AFD7-4137707CBDAE}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{3710DC32-2022-49A5-8962-2380D17EFE74}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{601984F3-ED3B-4EBF-857B-5CF6722C9ED2}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{EE2A7586-9463-4931-9708-38C6BB66AD75}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{1B268FC8-0D75-4F9A-92FB-674DA61F743B}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{D40C0DB1-31C5-4334-9ECB-4419EF0E30EF}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{AEC378CC-15F6-4D11-8236-63F6C7ABA5A9}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{4D8F3937-5FD0-463D-B68C-4BA61CEDC64E}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{801F2A47-4F36-4E8F-92B2-5C324E22B6FC}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{64787C58-87BD-48E7-811A-0A7CFCFAEB44}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{63C282B8-C9D5-4FD7-A5D9-577A6CCF9C52}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{6E5630CF-22EA-4E67-A7C9-C9AE9C1E8180}"= UDP:J:\Call Of Duty 4\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{5CFFB5CF-845C-459F-A0A2-FE332897EA8C}"= TCP:J:\Call Of Duty 4\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"TCP Query User{9D875CA3-885B-4D0D-B6C7-928A4BAF12B3}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC Modified By momo
"UDP Query User{EA868FAA-BD0B-4702-8C0B-63D62ECAD105}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC Modified By momo
"{992C7955-D431-4192-A49A-2057FB9AB92B}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{5F41B3CD-928D-49CF-B64F-6DC5B7576F73}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{9A4CA484-94F0-473B-93C1-6B0B56CE0366}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{AF88BD36-EAED-4B29-BEC7-3FBFC4778512}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{BCD8C334-C070-4561-9FE5-1494DE78B45C}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{CE3260F3-6B8D-4677-B63C-56D305185556}K:\\pc games\\call of duty 4\\iw3mp.exe"= UDP:K:\pc games\call of duty 4\iw3mp.exe:iw3mp
"UDP Query User{FF4D29D4-80E0-4466-AF1D-EBFD1DD9D4DE}K:\\pc games\\call of duty 4\\iw3mp.exe"= TCP:K:\pc games\call of duty 4\iw3mp.exe:iw3mp
"{4AF0EDFA-051F-4B8E-9058-F33346348614}"= UDP:K:\PC Games\Assassin's creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{B1C0276E-FC80-47B1-8521-EEF666DC1D72}"= TCP:K:\PC Games\Assassin's creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{ED214AD5-0908-41D1-855D-4C23CB27A70F}"= UDP:K:\PC Games\Assassin's creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{E479653C-C880-452B-9C98-7A1076AD934A}"= TCP:K:\PC Games\Assassin's creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{937E1C34-3E26-46F3-99C6-AEC9B2C0AA8B}"= UDP:K:\PC Games\Assassin's creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{6F1BF479-8EF7-4AD0-8C92-4E48F8C162AC}"= TCP:K:\PC Games\Assassin's creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{3117FF2F-4959-4E7C-A0D1-AE55FFE86DE9}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{5A4B6363-8FE8-4ED4-AE7A-99663E583735}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{CD160638-AC91-45B5-84C3-5F1B0FFA2F5D}C:\\program files\\soulseek\\slsk.exe"= UDP:C:\program files\soulseek\slsk.exe:SoulSeek
"UDP Query User{C4A2A781-C6E9-4E49-BDE7-D488F3ACD510}C:\\program files\\soulseek\\slsk.exe"= TCP:C:\program files\soulseek\slsk.exe:SoulSeek
"{133C210F-FAC4-4EEC-9DAF-EEED67503B8B}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{D35BED55-E1F2-4600-94FD-870926213ECD}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{3142A81D-7B54-435D-8127-7C804DE6FC5A}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{8D654DEF-6FC0-4063-864C-5DC8E311DB3D}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{DA06289E-E574-4FB2-B0D1-8CCCD3016C8D}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{59971F91-9B73-4089-AB16-D787A99714BF}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{089BAB57-7050-4589-9D91-2764A3DD72D5}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{CD758429-19AC-4C0C-930F-AE886EBF66BE}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{ED852766-F7F8-46C6-90F3-DB3FDFC84142}"= UDP:C:\Program Files\Codemasters\GRID\GRID.exe:GRID
"{30CCF783-7C0E-40AA-B4CD-16B38E8ACBFD}"= TCP:C:\Program Files\Codemasters\GRID\GRID.exe:GRID
"{F933E3CA-46AC-4EED-A561-2932FBCE262D}"= UDP:C:\Program Files\Empire Interactive\FlatOut Ultimate Carnage\Fouc.exe:FlatOut Ultimate Carnage
"{9F2DB86E-FD73-47D4-B695-419910759C26}"= TCP:C:\Program Files\Empire Interactive\FlatOut Ultimate Carnage\Fouc.exe:FlatOut Ultimate Carnage
"{E3FEB3A4-9ABC-4E82-98D2-BB37A86F7BE1}"= UDP:C:\Program Files\Mass Effect\Binaries\MassEffect.exe:Mass Effect Game
"{EE66E242-44B3-4B6B-94A5-5B577A41578C}"= TCP:C:\Program Files\Mass Effect\Binaries\MassEffect.exe:Mass Effect Game
"{646AA354-DC50-4D8C-B830-D7A9B03A32B7}"= UDP:C:\Program Files\Mass Effect\MassEffectLauncher.exe:Mass Effect Launcher
"{B68FB2B4-BD11-4B78-B8B9-C7752A5A5EDF}"= TCP:C:\Program Files\Mass Effect\MassEffectLauncher.exe:Mass Effect Launcher
"{293F0C05-A92D-4022-8109-477BA51C1695}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{20E19FF6-41E7-400B-9F6C-EB7BB7491D5C}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{4F479F5E-52C8-4906-BD69-03E4BD4413BF}"= UDP:C:\Windows\Temp\~os4663.tmp\ossproxy.exe:ossproxy.exe
"{A018893C-1CD2-4F88-B69C-60BDF9801018}"= UDP:C:\Program Files\RelevantKnowledge\rlvknlg.exe:rlvknlg.exe
"{014CF23C-C320-4E45-A76A-7E46A4E7B3B5}"= TCP:C:\Program Files\RelevantKnowledge\rlvknlg.exe:rlvknlg.exe
"{2FA5F7F4-6AE9-467C-92EA-AB0C22F2CA1B}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{EA59BD23-EE3E-415F-82C4-5D7F155ADE30}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{807911C6-1296-4F20-87D0-C74458D007E6}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{064E2CE2-7AD2-466E-BF48-D304AED3C1F4}"= Disabled:UDP:C:\Program Files\Joost\xulrunner\tvprunner.exe:tvprunner
"{4E6668FC-2747-490E-BFAD-187338A05600}"= Disabled:TCP:C:\Program Files\Joost\xulrunner\tvprunner.exe:tvprunner
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 VIRAGTLT;VIRAGTLT;C:\Windows\system32\drivers\VIRAGTLT.SYS [2008-09-19 40960]
R2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [2007-05-29 198240]
R2 RelevantKnowledge;RelevantKnowledge;C:\Program Files\RelevantKnowledge\rlservice.exe [2008-04-24 45056]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2006-11-02 22016]
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-09-19 57344]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys [2007-05-11 329728]
R3 phaudlwr;Philips Audio Filter;C:\Windows\system32\DRIVERS\phaudlwr.sys [2008-05-07 88704]
R3 SPC1000;USB2.0 PC Camera (SPC1000);C:\Windows\system32\DRIVERS\spc1000.sys [2007-12-04 3033728]
S2 DQLWinService;DQLWinService;C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 208896]
S2 IntelDHSvcConf;Intel DH Service;C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [2006-05-10 29696]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-09-09 355584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rsmsvcs REG_MULTI_SZ ntmssvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\shell\AutoRun\command - 80avp08.com
\shell\explore\Command - 80avp08.com
\shell\open\Command - 80avp08.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{732a1e32-9987-11db-a3ac-806e6f6e6963}]
\shell\AutoRun\command - E:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8a4e8696-2805-11dd-b28a-001d60e068f3}]
\shell\AutoRun\command - L:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3906ce2-1b6b-11dd-9e86-001d60e068f3}]
\shell\AutoRun\command - ntde1ect.com
\shell\explore\Command - ntde1ect.com
\shell\open\Command - ntde1ect.com
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenuto della cartella 'Scheduled Tasks'
.
- - - - ORFÃOS REMOVIDOS - - - -
BHO-{235B90D6-CB93-40A6-8F1A-AF422ADA9637} - C:\Windows\system32\iifgeDUM.dll
BHO-{DF30EE3F-26AB-0959-FF3A-7FA295CF42E5} - C:\Windows\system32\uuwcngex.dll
ShellExecuteHooks-{235B90D6-CB93-40A6-8F1A-AF422ADA9637} - C:\Windows\system32\iifgeDUM.dll
MSConfigStartUp-ABClose - C:\Program Files\Okoker Shutdown Expert\Okoker Shutdown Expert.exe
MSConfigStartUp-Steam - C:\Program Files\Steam\Steam.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\nano\AppData\Roaming\Mozilla\Firefox\Profiles\gv0wwydg.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.it/
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npJoostPlugin.dll
FF -: plugin - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-22 15:42:08
Windows 6.0.6000 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-09-22 15:42:48
ComboFix-quarantined-files.txt 2008-09-22 13:42:39
Pre-Run: Impossibile trovare il testo del messaggio per il numero di messaggio 0x2379 nel file di messaggio per Application.
Post-Run: 313,811,865,600 byte disponibili
314 --- E O F --- 2008-08-16 01:36:41