mi è tornato sfondo desktop di un mese fà,che stranoecco il log
ComboFix 09-06-09.06 - Proprietario 10/06/2009 18.37.41.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1022.601 [GMT 2:00]
Eseguito da: c:\documents and settings\Proprietario\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\setup.exe
.
((((((((((((((((((((((((( Files Creati Da 2009-05-10 al 2009-06-10 )))))))))))))))))))))))))))))))))))
.
2009-06-10 16:06 . 2009-06-10 16:22 -------- d-----w- C:\FindyKill
2009-06-09 21:16 . 2009-04-30 21:13 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-09 21:16 . 2009-04-30 21:13 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-05-23 17:42 . 2009-05-23 17:42 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Babylon
2009-05-23 17:42 . 2009-05-23 17:42 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Babylon
2009-05-23 17:20 . 2009-05-23 17:20 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Prevx
2009-05-18 16:50 . 2008-05-29 07:28 28416 ----a-w- c:\windows\system32\uxtuneup.dll
2009-05-18 16:50 . 2009-05-18 16:50 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-05-18 16:49 . 2009-06-09 22:14 -------- d-----w- c:\programmi\TuneUp Utilities 2008
2009-05-17 17:10 . 2009-05-17 17:10 -------- d-----w- c:\programmi\File comuni\PCSuite
2009-05-17 17:10 . 2009-05-17 17:10 -------- d-----w- c:\programmi\File comuni\Nokia
2009-05-17 17:09 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-05-17 17:09 . 2009-05-17 17:09 -------- d-----w- c:\programmi\PC Connectivity Solution
2009-05-17 17:08 . 2009-02-09 05:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-05-17 17:08 . 2009-02-09 05:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-05-17 17:08 . 2009-02-09 05:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-05-17 17:08 . 2009-02-09 05:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-05-17 17:08 . 2009-02-09 05:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-05-17 17:08 . 2009-02-09 05:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-05-17 17:08 . 2009-05-17 17:07 34447128 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_ita.exe
2009-05-17 17:08 . 2009-05-17 17:08 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-05-17 17:08 . 2009-05-17 17:08 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-05-17 17:08 . 2009-05-17 17:08 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-05-16 14:56 . 2009-05-16 14:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DriverScanner
2009-05-16 14:56 . 2009-05-16 14:59 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Uniblue
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 16:42 . 2009-03-16 16:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-06-10 16:40 . 2009-03-16 16:03 491552 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-10 16:40 . 2009-03-16 16:03 2760 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-10 16:40 . 2009-03-16 16:03 2519584 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-10 16:40 . 2009-03-16 16:03 21812 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-09 22:27 . 2009-03-03 19:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-06-09 21:13 . 2009-02-15 18:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-06-08 16:44 . 2009-01-06 21:23 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\uTorrent
2009-06-07 19:57 . 2009-01-30 20:22 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\TeraCopy
2009-06-06 16:18 . 2004-08-19 11:00 556916 ----a-w- c:\windows\system32\perfh010.dat
2009-06-06 16:18 . 2004-08-19 11:00 115338 ----a-w- c:\windows\system32\perfc010.dat
2009-06-05 17:13 . 2009-03-28 17:25 -------- d-----w- c:\programmi\blueMSX
2009-05-27 15:43 . 2009-01-05 23:36 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-05-27 15:42 . 2009-03-02 19:12 3371383 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-26 14:20 . 2009-01-05 19:30 -------- d-----w- c:\programmi\Google
2009-05-26 11:20 . 2009-01-05 23:36 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 11:19 . 2009-01-05 23:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-20 20:53 . 2009-03-16 16:04 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 20:53 . 2009-03-16 16:04 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-19 16:41 . 2009-04-22 15:00 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Spamihilator
2009-05-18 16:49 . 2009-01-29 18:15 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-05-17 17:10 . 2009-01-16 19:32 -------- d-----w- c:\programmi\Nokia
2009-05-17 17:08 . 2009-01-16 19:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Installations
2009-05-13 18:35 . 2009-03-21 17:39 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\dvdcss
2009-05-13 05:02 . 2004-08-19 11:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-19 11:00 347648 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 15:53 . 2009-05-05 18:53 -------- d-----w- c:\programmi\File comuni\Symantec Shared
2009-05-05 19:21 . 2009-05-05 18:53 -------- d-----w- c:\programmi\Norton Security Scan
2009-05-05 18:02 . 2009-05-05 17:32 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-05-05 17:26 . 2009-05-05 17:24 -------- d-----w- c:\programmi\Taskbar Hide
2009-05-05 17:26 . 2009-05-05 17:26 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-05-04 16:38 . 2009-05-04 16:38 -------- d-----w- c:\programmi\Glary Utilities
2009-04-27 18:09 . 2009-04-27 18:08 -------- d-----w- c:\programmi\Disk Cleaner
2009-04-27 16:10 . 2009-04-19 17:55 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-04-25 15:50 . 2009-04-25 15:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CA
2009-04-22 20:21 . 2009-04-22 20:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\FireGlow
2009-04-20 19:16 . 2009-04-20 19:16 37888 ----a-w- c:\windows\system32\setupnt.dll
2009-04-20 19:16 . 2009-04-20 19:16 82464 ----a-w- c:\windows\system32\drivers\snapman.sys
2009-04-20 19:16 . 2009-04-20 19:16 28928 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-04-20 19:16 . 2009-04-20 19:16 213888 ----a-w- c:\windows\system32\drivers\timntr.sys
2009-04-19 19:47 . 2004-08-19 11:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 20:37 . 2009-01-29 18:15 -------- d-----w- c:\programmi\AGEIA Technologies
2009-04-16 22:29 . 2009-01-28 21:28 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-16 22:28 . 2009-04-16 22:28 152576 ----a-w- c:\documents and settings\Proprietario\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-16 19:19 . 2009-03-07 15:46 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\IObit
2009-04-15 14:52 . 2004-08-19 11:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-14 17:17 . 2009-04-14 17:17 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\HP
2009-04-14 17:17 . 2009-04-14 17:17 18112 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-04-14 17:17 . 2009-04-14 17:10 123117 ----a-w- c:\windows\hpoins11.dat
2009-04-14 17:16 . 2009-04-14 17:15 -------- d-----w- c:\programmi\File comuni\HP
2009-04-14 17:14 . 2009-01-16 07:58 -------- d-----w- c:\programmi\HP
2009-04-14 16:37 . 2009-01-16 08:06 -------- d-----w- c:\programmi\Hewlett-Packard
2009-04-12 18:49 . 2009-01-06 22:19 -------- d-----w- c:\programmi\Quadra
2009-03-28 17:25 . 2009-03-28 17:25 3638 ----a-r- c:\documents and settings\Proprietario\Dati applicazioni\Microsoft\Installer\{4C9967A1-A0B9-4ADE-844F-488E0E3A1D79}\_4ae13d6c.exe
2009-03-28 17:25 . 2009-03-28 17:25 3638 ----a-r- c:\documents and settings\Proprietario\Dati applicazioni\Microsoft\Installer\{4C9967A1-A0B9-4ADE-844F-488E0E3A1D79}\_2cd672ae.exe
2009-03-28 17:25 . 2009-03-28 17:25 3638 ----a-r- c:\documents and settings\Proprietario\Dati applicazioni\Microsoft\Installer\{4C9967A1-A0B9-4ADE-844F-488E0E3A1D79}\_294823.exe
2009-03-28 17:25 . 2009-03-28 17:25 1078 ----a-r- c:\documents and settings\Proprietario\Dati applicazioni\Microsoft\Installer\{4C9967A1-A0B9-4ADE-844F-488E0E3A1D79}\_69525f90.exe
2009-03-28 17:25 . 2009-03-28 17:25 1078 ----a-r- c:\documents and settings\Proprietario\Dati applicazioni\Microsoft\Installer\{4C9967A1-A0B9-4ADE-844F-488E0E3A1D79}\_18be6784.exe
2009-03-27 06:14 . 2009-01-05 21:57 453152 ----a-w- c:\windows\system32\nvuninst.exe
2009-03-19 22:30 . 2006-01-01 02:08 18112 ----a-w- c:\documents and settings\Proprietario\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-03-16 16:48 . 2008-01-29 17:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-03-16 16:48 . 2009-03-16 16:48 33808 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\klbg.sys
2009-03-16 16:48 . 2009-03-16 16:48 213520 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\XP\klif.sys
2009-03-16 16:48 . 2009-03-16 16:48 21256 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\vkbd.dll
2009-03-16 16:47 . 2009-03-16 16:47 861448 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\updater.dll
2009-03-16 16:47 . 2009-03-16 16:47 83208 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\mzvkbd.dll
2009-03-16 16:47 . 2009-03-16 16:47 62728 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ievkbd.dll
2009-03-16 16:47 . 2009-03-16 16:47 43784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\fssync.dll
2009-03-16 16:47 . 2009-03-16 16:46 365832 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ckahum.dll
2009-03-16 16:46 . 2009-03-16 16:46 201992 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\avp.exe
2009-03-15 10:14 . 2009-03-15 10:14 4096 ----a-w- c:\windows\d3dx.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-10 39408]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"UnlockerAssistant"="c:\programmi\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-03-16 201992]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-04-16 148888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-01-11 15961088]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"=
"c:\\Programmi\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\italian\\setup.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\italian\\setup.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 19.29.38 33808]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [20/02/2009 19.47.14 55152]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [27/01/2009 21.44.17 46080]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [27/01/2009 21.44.03 56960]
S2 gupdate1c98f9ee3c86c5c;Servizio di Google Update (gupdate1c98f9ee3c86c5c);c:\programmi\Google\Update\GoogleUpdate.exe [15/02/2009 20.54.53 133104]
S3 fsssvc;Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19.08.58 533360]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-10 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2009-05-04 19:44]
2009-06-10 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-05 18:53]
2009-06-10 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-15 18:54]
2009-06-10 c:\windows\Tasks\Verifica e correzione automatica.job
- c:\programmi\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 07:27]
.
.
------- Scansione supplementare -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\programmi\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab
FF - ProfilePath - c:\documents and settings\Proprietario\Dati applicazioni\Mozilla\Firefox\Profiles\hghox8ke.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Cerca
FF - prefs.js: browser.startup.homepage - hxxp://www.fastweb.it/portale/
FF - prefs.js: keyword.URL - hxxp://mystart.hiyo.com/?loc=ff_address&search=
FF - component: c:\programmi\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-10 18:42
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1935655697-1220945662-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1F14D1D7-B391-AC45-918D-4B980785CB51}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abemkbiibhifolnloeeggflcmhnoipebce"=hex:61,61,00,00
"bbemkbiibhifolnloehgnbgicldckcklelkn"=hex:61,61,00,00
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(572)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(3288)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\rundll32.exe
c:\programmi\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Ora fine scansione: 2009-06-10 18.46.12 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-06-10 16:46
Pre-Run: 258.515.603.456 byte disponibili
Post-Run: 258.258.362.368 byte disponibili
263 --- E O F --- 2009-06-10 16:27