ecco il log di conbofixc:
ComboFix 09-03-19.02 - xyz 2009-03-21 15:03:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.1023.560 [GMT 1:00]
Eseguito da: c:\documents and settings\xyz\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\doomily.dat
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\doomily_nav.dat
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\doomily_navps.dat
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\iljqekgci.dat
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\iljqekgci_nav.dat
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\iljqekgci_navps.dat
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\limfcya.dat
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\limfcya_nav.dat
c:\documents and settings\xyz\Impostazioni locali\Dati applicazioni\limfcya_navps.dat
c:\programmi\QUAD Utilities
c:\programmi\QUAD Utilities\QUAD Registry Cleaner\Vista Scheduler.dll
C:\uxkl0apt.bat
c:\windows\system32\command.pif
c:\windows\system32\ICON.ico
C:\yh.cmd
.
((((((((((((((((((((((((( Files Creati Da 2009-02-21 al 2009-03-21 )))))))))))))))))))))))))))))))))))
.
2009-03-20 15:35 . 2009-03-20 15:35 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-03-20 15:35 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-20 15:35 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-20 09:32 . 2009-03-20 09:32 <DIR> d-------- c:\programmi\Trend Micro
2009-03-19 19:38 . 2009-03-19 19:40 <DIR> d-------- c:\documents and settings\xyz\Dati applicazioni\Faxalo
2009-03-19 19:38 . 2007-07-25 20:53 1,382,356 --a------ c:\windows\system32\imgport.dll
2009-03-19 19:38 . 2006-03-28 19:50 376,832 --a------ c:\windows\system32\libtiff3.dll
2009-03-19 19:38 . 2005-05-15 23:08 127,488 --a------ c:\windows\system32\jpeg62.dll
2009-03-19 19:38 . 2005-07-21 03:05 75,264 --a------ c:\windows\system32\zlib1.dll
2009-03-19 19:38 . 2007-07-13 18:19 40,448 --a------ c:\windows\system32\PopFaxLocalMon.dll
2009-03-19 19:38 . 2006-03-28 19:51 36,352 --a------ c:\windows\system32\tiffcp.exe
2009-03-19 19:38 . 2007-06-27 18:38 16,896 --a------ c:\windows\system32\PopFaxLocalUI.dll
2009-03-18 19:35 . 2009-03-16 20:02 111,363 -r-hs---- C:\luk1ylq.com
2009-03-18 15:52 . 2009-03-18 21:22 <DIR> d-------- c:\programmi\SpeedFan
2009-03-18 15:52 . 2009-03-18 15:52 0 --a------ c:\windows\system32\initdebug.nfo
2009-03-18 14:54 . 2009-03-16 20:02 111,363 -r-hs---- C:\q0dhfjf.exe
2009-03-17 22:01 . 2009-03-17 22:01 3,166 --a------ c:\windows\tmp.xml
2009-03-17 19:02 . 2009-03-19 19:38 <DIR> d-------- c:\programmi\System Protect
2009-03-17 19:02 . 2009-03-17 19:02 12,288 --a------ c:\windows\system32\drivers\sp_prot.sys
2009-03-16 11:46 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2009-03-09 18:23 . 2009-03-09 18:23 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-09 18:23 . 2009-03-09 18:23 1,409 --a------ c:\windows\QTFont.for
2009-03-01 18:59 . 2009-03-01 19:11 <DIR> d--hs---- c:\documents and settings\xyz\Phone Browser
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-21 12:31 196,608 ----a-w c:\windows\system32\drivers\nStandard.bin
2009-03-21 10:13 --------- d-----w c:\documents and settings\xyz\Dati applicazioni\Spyware Terminator
2009-03-20 05:54 --------- d-----w c:\programmi\WinClamAVShield
2009-03-20 05:54 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Spyware Terminator
2009-03-17 21:27 --------- d-----w c:\programmi\Spyware Terminator
2009-03-17 21:26 --------- d-----w c:\programmi\eMule
2009-03-14 08:19 --------- d-----w c:\programmi\File comuni\Adobe
2009-03-08 09:32 --------- d-----w c:\documents and settings\xyz\Dati applicazioni\Nokia
2009-03-08 09:31 --------- d-----w c:\programmi\File comuni\Nokia
2009-03-08 09:30 --------- d-----w c:\programmi\Nokia
2009-02-20 14:22 --------- d-----w c:\documents and settings\xyz\Dati applicazioni\PC Suite
2009-02-20 14:21 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-02-20 14:21 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-02-20 14:15 --------- d-----w c:\programmi\PC Connectivity Solution
2009-02-20 14:15 --------- d-----w c:\programmi\File comuni\PCSuite
2009-02-20 14:13 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Installations
2009-02-20 14:04 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Nokia
2009-02-20 13:54 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\PC Suite
2009-02-20 13:53 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-20 13:53 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-02-20 13:50 --------- d-----w c:\documents and settings\xyz\Dati applicazioni\Nseries
2009-02-18 16:10 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\NokiaMusic
2009-02-18 16:06 --------- d-----w c:\programmi\DIFX
2009-02-18 15:54 --------- d-----w c:\programmi\Reference Assemblies
2009-02-18 15:54 --------- d-----w c:\programmi\MSBuild
2009-02-18 15:39 --------- d-----w c:\programmi\MSXML 6.0
2009-02-17 08:43 --------- d-----w c:\programmi\Messenger Plus! Live
2009-02-06 18:06 --------- d-----w c:\programmi\Dream Aquarium
2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-26 10:07 113,600 -c--a-w c:\documents and settings\xyz\Dati applicazioni\GDIPFONTCACHEV1.DAT
2008-05-07 12:56 614 ----a-w c:\programmi\BorisGraffitiUI.xml
2008-03-15 19:18 14,348 ----a-w c:\documents and settings\xyz\SkyTel(2).EXE
2008-03-15 19:18 14,348 ----a-w c:\documents and settings\xyz\SkyTel .exe
2008-03-15 19:18 14,348 ----a-w c:\documents and settings\xyz\RTHDCPL(2).EXE
2008-03-15 19:18 14,348 ----a-w c:\documents and settings\xyz\RTHDCPL .exe
2008-02-05 23:44 200,704 ----a-w c:\programmi\BorisFXUI.fex
2008-01-05 13:12 22,328 ----a-w c:\documents and settings\xyz\Dati applicazioni\PnkBstrK.sys
2006-09-07 20:08 53,606,550 -c----w c:\documents and settings\xyz\Desktop.zip
2007-11-23 18:26 2 --shatr c:\windows\winstart.bat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"NBJ"="c:\programmi\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 1957888]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"type32"="c:\programmi\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\programmi\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2006-10-25 282624]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-16 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-16 81920]
"SpywareTerminator"="c:\progra~1\SPYWAR~2\SpywareTerminatorShield.exe" [2008-05-08 1817600]
"SystemProtect"="c:\programmi\System Protect\SysProtect_Tray.exe" [2009-03-17 1223680]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2007-09-16 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2004-07-09 110592]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2003-01-21 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"= ctwdm32.dll
"aux5"= ctwdm32.dll
"aux6"= ctwdm32.dll
"aux7"= ctwdm32.dll
"VIDC.GJPG"= GJPG.DLL
"vidc.mjpg"= pvmjpg30.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\MSN\\MSNCoreFiles\\msn6.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Documents and Settings\\xyz\\Desktop\\SCARICA\\zdc\\zDCPlusPlus.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Hercules\\Classic Silver\\Station2.exe"=
"c:\\Programmi\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"c:\\Programmi\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"c:\\Programmi\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Programmi\\Pinnacle\\Studio 12\\Programs\\umi.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12800:TCP"= 12800:TCP:NortonAV
"14016:TCP"= 14016:TCP:NortonAV
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-03-16 28544]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [2005-12-06 35328]
R0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [2005-07-19 84529]
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2003-10-01 77056]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2008-04-03 141312]
R2 SP_Service;System Protect Deletion Prevention Service;c:\programmi\System Protect\SysProtect_srv.exe [2009-03-17 598528]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\drivers\l251x86.sys [2008-03-06 29696]
R3 camfilt2;camfilt2;c:\windows\system32\drivers\camfilt2.sys [2008-01-26 94208]
R3 sp_prot;System Protect Filter Driver;c:\windows\system32\drivers\sp_prot.sys [2009-03-17 12288]
S2 MtxVideo;Driver Matrox WDM capture/crossbar;c:\windows\system32\drivers\mtxvideo.sys [2004-04-09 103296]
S2 vee3ie8yafi5towy;Print Spooler Service;c:\windows\system32\prgacpckfg.exe /service --> c:\windows\system32\prgacpckfg.exe [?]
S3 Camdrv30;Philips ToUcam XS;c:\windows\system32\drivers\camdrv30.sys [2005-11-26 171264]
S3 ctlsb16;Driver Creative SB16/AWE32/AWE64 (WDM);c:\windows\system32\drivers\ctlsb16.sys [2003-11-25 96256]
S3 G200;G200;c:\windows\system32\drivers\G200m.sys [2003-11-20 320384]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\DRIVERS\pfc027.sys --> c:\windows\system32\DRIVERS\pfc027.sys [?]
S3 S3SAVAGE4M;S3SAVAGE4M;c:\windows\system32\drivers\s3sav4m.sys [2004-01-05 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0b4629f0-b2cd-11dc-8547-0013d44e1471}]
\Shell\AutoRun\command - E:\iqe68o.bat
\Shell\explore\Command - E:\iqe68o.bat
\Shell\open\Command - E:\iqe68o.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0cbcf9a0-ec5b-11dd-8b3c-001e8c14215f}]
\Shell\AutoRun\command - wx8o0bt1.com
\Shell\open\Command - wx8o0bt1.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{29db8530-d702-11dc-860a-0013d44e1471}]
\Shell\AutoRun\command - E:\2fiy.bat
\Shell\open\Command - E:\2fiy.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48c439c0-5c35-11db-be9b-0013d44e1471}]
\Shell\AutoRun\command - E:\m9ma.exe
\Shell\explore\Command - E:\m9ma.exe
\Shell\open\Command - E:\m9ma.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9d80c321-5112-11d9-9be5-806d6172696f}]
\Shell\AutoRun\command - e:\bin\Assetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1f2e6a0-fe97-11dd-8baf-001e8c14215f}]
\Shell\AutoRun\command - E:\gi2ky.exe
\Shell\open\Command - E:\gi2ky.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1f2e6a1-fe97-11dd-8baf-001e8c14215f}]
\Shell\AutoRun\command - G:\cv22.cmd
\Shell\open\Command - G:\cv22.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e199d690-00a8-11dc-81db-0013d44e1471}]
\Shell\AutoRun\command - I:\xdw.com
\Shell\open\Command - I:\xdw.com
.
Contenuto della cartella 'Scheduled Tasks'
2009-03-09 c:\windows\Tasks\At3.job
- c:\windows\system32\username.exe []
2009-03-07 c:\windows\Tasks\At4.job
- c:\windows\system32\expIorer.exe []
2009-03-15 c:\windows\Tasks\At5.job
- c:\windows\system32\sp2protect.exe []
2009-03-11 c:\windows\Tasks\Schedule Task Weekly.job
- c:\programmi\Registry Easy\RE.exe []
2009-03-21 c:\windows\Tasks\Symantec NetDetect.job
- c:\programmi\Symantec\LiveUpdate\NDETECT.EXE [2005-03-16 11:48]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-WebCamRT.exe - (no file)
Notify-AtiExtEvent - (no file)
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
IE: &eBay Search - c:\programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search - tbr:iemenu
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {321BC7BD-4D93-4424-953B-6732A6C70262} = 85.37.17.11 85.38.28.69
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\programmi\Crawler\Toolbar\ctbr.dll
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\xyz\Dati applicazioni\Mozilla\Firefox\Profiles\tkxqxsx4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://mystart.magentic.com/italian/
FF - prefs.js: keyword.URL - hxxp://mystart.magentic.com/?loc=FF_Magentic_AddressBar&search=
FF - component: c:\programmi\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\programmi\Google\Picasa3\npPicasa3.dll
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.02.10);user_pref(general.useragent.extra.zencast, .
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-21 15:06:31
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1275210071-746137067-854245398-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,41,84,ba,09,90,
26,96,5c,c8,28,51,af,b0,29,a3,98,cf,8e,aa,08,8e,27,36,f5,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,03,56,6e,1f,f2,
b4,df,a5,71,3b,04,66,8b,46,0d,96,8d,20,fd,91,0f,8f,c4,14,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,29,48,89,0f,f3,
15,ae,6e,25,da,ec,7e,55,20,c9,26,f9,8f,6b,80,2c,43,47,50,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,a6,e0,fe,67,aa,
9e,f7,ab,3e,1e,9e,e0,57,5a,93,61,89,dd,3a,c3,53,d4,57,77,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,a0,91,14,21,f8,
8b,ce,36,cd,44,cd,b9,a6,33,6c,cd,d3,8c,9f,72,39,1a,50,21,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,f0,a7,5a,48,c6,
61,18,69,b0,18,ed,a7,3f,8d,37,a4,2a,b7,f9,86,d9,ff,72,41,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,5a,cb,e2,70,62,
4c,aa,31,31,77,e1,ba,b1,f8,68,02,d6,fb,57,8f,9c,26,0f,4d,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,73,7c,d8,bc,8f,
10,ed,58,83,6c,56,8b,a0,85,96,ab,0d,26,1a,0f,50,a3,64,81,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,1b,11,06,0d,a6,
55,16,77,51,fa,6e,91,28,9e,14,cc,4f,82,aa,67,98,86,ef,55,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,37,d7,a8,c4,f3,
b0,cf,78,b1,cd,45,5a,a8,c4,f8,b9,b6,a2,65,c3,8d,16,a2,df,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,8e,84,30,7f,c2,
22,cf,7f,e3,0e,66,d5,eb,bc,2f,6b,18,e4,64,57,0f,1d,bb,ee,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,6e,40,09,8f,b9,
2b,28,43,fa,ea,66,7f,d4,3b,6b,70,44,e1,e0,81,8a,2b,06,d3,6c,43,2d,1e,aa,22,\
.
Ora fine scansione: 2009-03-21 15:10:03
ComboFix-quarantined-files.txt 2009-03-21 14:08:46
Pre-Run: 50,879,012,864 byte disponibili
Post-Run: 51,819,884,544 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
320