account alice fra l'altro dal mio indirizzo di posta predefinito inoltre ricevo mail indirizzate a chi ha un account alice ma altro username o usarname uguale al mio ma diverso indirizzo di posta elettronica
ComboFix 09-08-31.03 - Asus 31/08/2009 22.59.55.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1919.1356 [GMT 2:00]
Eseguito da: c:\documents and settings\Asus\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Asus\Impostazioni locali\Dati applicazioni\avbvjvk.dat
c:\documents and settings\Asus\Impostazioni locali\Dati applicazioni\avbvjvk_navps.dat
c:\programmi\Lphant Applications\Lphant MediaBar\LphantMediaBar.dll
c:\windows\Installer\121245.msi
c:\windows\Installer\12124b.msi
c:\windows\Installer\1d4241.msi
c:\windows\Installer\1d4242.msp
c:\windows\Installer\1d4243.msp
c:\windows\Installer\1d4244.msp
c:\windows\Installer\1d4245.msp
c:\windows\Installer\1d4246.msp
c:\windows\Installer\1d4247.msp
c:\windows\Installer\1d4248.msp
c:\windows\Installer\2d208.msp
c:\windows\Installer\2d21f.msp
c:\windows\Installer\39179.msi
c:\windows\Installer\5776e.msi
c:\windows\Installer\e7d28.msi
.
((((((((((((((((((((((((( Files Creati Da 2009-07-28 al 2009-08-31 )))))))))))))))))))))))))))))))))))
.
2009-08-31 12:05 . 2009-08-26 08:00 371248 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.018\EECTRL.SYS
2009-08-31 12:05 . 2009-08-26 08:00 2747440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.018\CCERASER.DLL
2009-08-31 12:05 . 2009-08-26 08:00 102448 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.018\ERASER.SYS
2009-08-31 12:05 . 2009-08-25 08:00 84912 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.018\NAVENG.SYS
2009-08-31 12:05 . 2009-08-25 08:00 259440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.018\ECMSVR32.DLL
2009-08-31 12:05 . 2009-08-25 08:00 177520 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.018\NAVENG32.DLL
2009-08-31 12:05 . 2009-08-25 08:00 1647984 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.018\NAVEX32A.DLL
2009-08-31 12:05 . 2009-08-25 08:00 1323568 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.018\NAVEX15.SYS
2009-08-31 11:55 . 2009-03-12 08:42 165240 ----a-r- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2009-08-28 15:47 . 2009-08-28 15:48 -------- d-----w- c:\programmi\File comuni\Canopus Shared
2009-08-28 15:47 . 2009-08-28 15:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Canopus
2009-08-27 13:13 . 2008-05-15 00:00 942080 ------w- c:\windows\system32\pavplal.dll
2009-08-27 13:13 . 2008-05-15 00:00 65536 ------w- c:\windows\system32\pavedius5db.dll
2009-08-27 13:13 . 2008-05-15 00:00 65536 ------w- c:\windows\system32\pavedius.dll
2009-08-27 13:13 . 2008-03-18 06:04 6656 ------w- c:\windows\system32\paveno.dll
2009-08-27 13:13 . 2008-03-18 06:04 462848 ------w- c:\windows\system32\pavapi.dll
2009-08-27 09:39 . 2009-08-27 09:39 29926 ----a-r- c:\documents and settings\Asus\Dati applicazioni\Microsoft\Installer\{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}\_CE4FFA1DD37E7C505AED29.exe
2009-08-27 09:39 . 2009-08-27 09:39 29926 ----a-r- c:\documents and settings\Asus\Dati applicazioni\Microsoft\Installer\{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}\_C1A9BF9D98647632ED5172.exe
2009-08-27 09:39 . 2009-08-27 09:39 29926 ----a-r- c:\documents and settings\Asus\Dati applicazioni\Microsoft\Installer\{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}\_6FEFF9B68218417F98F549.exe
2009-08-27 09:39 . 2009-08-27 09:39 -------- d-----w- c:\programmi\DesktopEarth
2009-08-25 15:01 . 2009-08-25 15:01 -------- d-----w- c:\documents and settings\Asus\Dati applicazioni\Ahead
2009-08-25 14:58 . 2009-08-25 15:01 -------- d-----w- c:\documents and settings\Asus\Impostazioni locali\Dati applicazioni\Ahead
2009-08-25 14:57 . 2009-08-25 14:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Ahead
2009-08-25 14:54 . 2009-08-25 14:56 -------- d-----w- c:\programmi\File comuni\Ahead
2009-08-25 14:54 . 2009-08-25 14:54 -------- d-----w- c:\programmi\Nero
2009-08-25 14:54 . 2009-08-25 14:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2009-08-25 13:06 . 2009-08-28 15:47 -------- d-----w- c:\programmi\Canopus
2009-08-24 08:26 . 2009-08-24 08:26 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-23 15:22 . 2009-08-23 15:22 -------- d-----w- c:\documents and settings\Asus\Dati applicazioni\Malwarebytes
2009-08-23 15:22 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-23 15:22 . 2009-08-23 15:22 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-08-23 15:22 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-16 01:11 . 2009-08-16 01:11 -------- d-----w- c:\programmi\File comuni\Skype
2009-08-14 08:15 . 2009-07-11 19:34 533880 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\Scxpx86.dll
2009-08-14 08:15 . 2009-07-11 19:34 276344 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSXpx86.sys
2009-08-14 08:15 . 2009-07-11 19:34 293424 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSvix86.sys
2009-08-14 08:15 . 2009-07-11 19:34 451960 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSxpx86.dll
2009-08-14 08:15 . 2009-07-11 19:34 397360 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSviA64.sys
2009-08-11 22:49 . 2009-08-11 22:49 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-31 20:56 . 2008-03-04 14:43 -------- d-----w- c:\documents and settings\Asus\Dati applicazioni\Skype
2009-08-31 20:55 . 2009-07-08 23:40 -------- d-----w- c:\documents and settings\Asus\Dati applicazioni\vlc
2009-08-31 19:35 . 2008-03-04 14:51 -------- d-----w- c:\documents and settings\Asus\Dati applicazioni\skypePM
2009-08-31 19:32 . 2008-03-09 15:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-08-31 13:00 . 2008-11-19 18:22 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-08-31 13:00 . 2009-06-13 17:54 -------- d-----w- c:\programmi\SpywareBlaster
2009-08-31 00:41 . 2008-03-20 18:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-08-31 00:40 . 2008-12-18 12:51 79440 -c--a-w- c:\documents and settings\Asus\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-08-30 17:51 . 2009-05-02 21:33 -------- d-----w- c:\documents and settings\Asus\Dati applicazioni\Any Video Converter
2009-08-30 17:51 . 2009-05-02 21:33 -------- d-----w- c:\programmi\Any Video Converter
2009-08-28 15:47 . 2008-01-26 08:28 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-08-28 15:40 . 2009-05-02 21:46 -------- d-----w- c:\programmi\Free Video Converter
2009-08-28 10:33 . 2009-04-04 21:14 -------- d-----w- c:\documents and settings\Asus\Dati applicazioni\dvdcss
2009-08-26 15:12 . 2008-03-09 15:44 -------- d-----w- c:\programmi\Google
2009-08-26 15:05 . 2008-02-06 16:41 -------- d-----w- c:\programmi\LG PC Suite
2009-08-16 01:11 . 2009-03-22 17:19 -------- d-----r- c:\programmi\Skype
2009-08-16 01:11 . 2008-03-04 14:41 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2009-08-05 08:59 . 2004-08-19 13:39 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 20:14 . 2009-03-09 22:57 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-07-31 16:07 . 2009-07-31 15:30 -------- d-----w- c:\programmi\Secret Maryo Chronicles
2009-07-31 16:07 . 2009-07-31 15:32 -------- d-----w- c:\documents and settings\Asus\Dati applicazioni\smc
2009-07-19 10:58 . 2009-07-19 10:57 -------- d-----w- c:\programmi\SONY
2009-07-17 19:01 . 2004-08-19 13:39 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-08-19 13:39 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-11 19:34 . 2009-07-11 19:34 276344 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-07-11 19:34 . 2009-07-11 19:34 293424 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-07-11 19:34 . 2009-07-11 19:34 533880 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34 451960 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34 397360 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-07-08 23:38 . 2009-07-08 23:38 -------- d-----w- c:\programmi\VideoLAN
2009-07-03 00:14 . 2009-06-17 16:34 554352 ----a-r- c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2009-06-29 15:55 . 2004-08-19 13:39 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:55 . 2009-07-18 19:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:54 . 2004-08-19 13:39 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-19 13:39 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-19 13:39 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-19 13:39 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-19 13:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-19 13:39 735744 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-19 13:39 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-03 20:59 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-17 16:34 . 2009-06-17 16:34 0 ----a-w- c:\windows\nsreg.dat
2009-06-16 14:36 . 2004-08-19 13:39 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2001-08-31 15:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 10:43 . 2004-08-19 13:39 78336 ----a-w- c:\windows\system32\telnet.exe
2009-06-15 10:43 . 2004-08-19 13:39 82432 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-10 14:13 . 2004-08-19 13:39 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 07:19 . 2008-01-25 15:42 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-19 13:39 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2004-08-19 13:39 1296384 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="c:\programmi\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-16 8478720]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-08-16 81920]
"RemoteControl"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2009-01-02 185872]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-04-13 1822720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Asus\Menu Avvio\Programmi\Esecuzione automatica\
DesktopEarth AutoStart.lnk - c:\documents and settings\Asus\Dati applicazioni\Microsoft\Installer\{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}\_C1A9BF9D98647632ED5172.exe [2009-8-27 29926]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Programmi\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [30/04/2009 17.24.40 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [30/04/2009 17.24.39 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [30/04/2009 17.24.01 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSXpx86.sys [14/08/2009 10.15.32 276344]
R2 Norton Internet Security;Norton Internet Security;c:\programmi\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [30/04/2009 17.24.15 115560]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:\windows\system32\StkCSrv.exe [19/04/2007 7.42.34 24576]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [26/08/2009 10.00.00 102448]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\system32\drivers\StkCMini.sys [06/06/2007 11.40.26 1260672]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\programmi\File comuni\LightScribe\LSRunOnce.exe"
.
Contenuto della cartella 'Scheduled Tasks'
2009-08-31 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-03-09 21:29]
2009-08-31 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
2009-08-31 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
mStart Page = about:blank
FF - ProfilePath - c:\documents and settings\Asus\Dati applicazioni\Mozilla\Firefox\Profiles\ybx39jav.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.lphant.com/
FF - component: c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-31 23:04
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\programmi\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\programmi\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-2000478354-879983540-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2009-08-31 23.06.25
ComboFix-quarantined-files.txt 2009-08-31 21:06
Pre-Run: 43.732.430.848 byte disponibili
Post-Run: 43.691.302.912 byte disponibili
223 --- E O F --- 2009-08-26 18:27