ComboFix 09-09-17.04 - ligi 18/09/2009 17.10.46.1.2 - NTFSx86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.39.1040.18.1021.307 [GMT 2:00]
Eseguito da: c:\users\ligi\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1282 [VPS 081114-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1282 [VPS 081114-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-38392920-509307625-1878902752-500
c:\users\ligi\AppData\Local\ibpqe.dat
c:\users\ligi\AppData\Local\ibpqe_nav.dat
c:\users\ligi\AppData\Local\ibpqe_navps.dat
c:\users\ligi\AppData\Roaming\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\libfn.dll
.
((((((((((((((((((((((((( Files Creati Da 2009-08-18 al 2009-09-18 )))))))))))))))))))))))))))))))))))
.
2009-09-18 15:25 . 2009-09-18 15:25 -------- d-----w- c:\users\ligi\AppData\Local\temp
2009-09-18 14:22 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-18 14:22 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-17 23:38 . 2009-09-18 11:20 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-17 23:38 . 2009-09-17 23:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-15 21:03 . 2009-09-15 21:03 -------- d-----w- c:\program files\PicoZipRT
2009-09-10 08:43 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-10 08:43 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-10 08:43 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-10 08:43 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-10 08:43 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-10 08:43 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-10 08:43 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-10 08:43 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-10 08:43 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-10 08:43 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-10 08:42 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-10 08:42 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-10 08:42 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-10 08:42 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-10 08:42 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-02 08:00 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-02 08:00 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-02 08:00 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-02 08:00 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-02 08:00 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-02 08:00 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-02 08:00 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-02 08:00 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-08-30 17:26 . 2009-08-30 17:26 -------- d-----w- c:\program files\SopCast
2009-08-27 17:52 . 2009-08-27 17:52 -------- d-----w- c:\users\ligi\AppData\Local\Drag_&_Air_S.n.c
2009-08-26 22:39 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-23 21:02 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-23 21:02 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-23 21:01 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-23 21:01 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-23 21:01 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-23 21:01 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-23 21:01 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-23 21:00 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-18 14:56 . 2007-10-11 17:18 12 ----a-w- c:\windows\bthservsdp.dat
2009-09-16 08:13 . 2009-06-18 10:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-15 19:29 . 2006-11-06 01:52 719842 ----a-w- c:\windows\system32\perfh010.dat
2009-09-15 19:29 . 2006-11-06 01:52 142438 ----a-w- c:\windows\system32\perfc010.dat
2009-09-14 13:43 . 2008-02-10 16:12 -------- d-----w- c:\program files\BurracoWeb
2009-09-14 00:05 . 2008-09-19 14:27 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-13 18:32 . 2007-03-28 02:34 -------- d-----w- c:\programdata\Microsoft Help
2009-09-10 12:54 . 2009-06-18 10:58 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-06-18 10:58 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-01 21:31 . 2008-03-24 21:35 -------- d-----w- c:\program files\Burraconline
2009-08-30 17:50 . 2007-10-28 15:31 -------- d-----w- c:\program files\Java
2009-08-17 16:10 . 2008-02-07 23:31 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:05 . 2008-04-06 16:28 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-06 16:28 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:05 . 2008-02-07 23:31 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-08-17 16:04 . 2008-02-07 23:32 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2008-02-07 23:32 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:02 . 2008-02-07 23:32 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-07 18:10 . 2008-11-15 21:39 20 ---h--w- c:\programdata\PKP_DLdu.DAT
2009-08-07 18:10 . 2009-08-07 18:10 -------- d-----w- c:\users\ligi\AppData\Roaming\Nikon
2009-08-07 13:27 . 2009-07-30 17:21 87 ----a-w- c:\users\ligi\AppData\Local\ibpqe.bat
2009-07-25 03:23 . 2009-03-02 09:53 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 21:52 . 2009-07-30 07:19 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-30 07:19 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-30 07:19 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-30 07:19 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-06-23 17:48 . 2007-10-04 23:27 52566 ----a-w- c:\users\ligi\AppData\Roaming\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-12-08 614400]
"eDSMSNfix"="c:\acer\Empowering Technology\eDSMSNfix.exe" [2007-02-08 13312]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-20 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-18 520024]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\eNetHook.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BD8FF62C-6A44-4E7D-AA14-FB686A953393}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{023982EA-9A78-4676-9FDE-D091BF6043F9}"= c:\program files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{E1F7C805-C1F0-4224-B919-984D263D68E8}"= c:\program files\Acer Arcade Deluxe\VideoMagician\MagicDirector.exe:CyberLink MagicDirector
"{E74B3364-400C-43C6-93CB-4F7789C400B9}"= c:\program files\Acer Arcade Deluxe\DV Wizard\PowerDV.exe:CyberLink PowerDV
"{421E1C1B-E2D8-4874-B8DF-6C1CEDF8C8B5}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{2B50B6A9-FFF1-4AC0-A4AE-69EE60A4DA32}c:\\users\\ligi\\clubdelgioco\\jre\\jre\\bin\\javaw.exe"= UDP:c:\users\ligi\clubdelgioco\jre\jre\bin\javaw.exe:javaw.exe
"UDP Query User{2EE3335D-64E0-489C-A666-E8953529D351}c:\\users\\ligi\\clubdelgioco\\jre\\jre\\bin\\javaw.exe"= TCP:c:\users\ligi\clubdelgioco\jre\jre\bin\javaw.exe:javaw.exe
"{386D57B6-56C5-430D-BD9A-1482BEDD0A49}"= UDP:c:\program files\BurracoWeb\BurracoWebClient.exe:BurracoWebClient
"{8D544DE2-6DF4-44F7-96AE-D3736C6EE40D}"= TCP:c:\program files\BurracoWeb\BurracoWebClient.exe:BurracoWebClient
"{0406DDA0-35C3-4196-BAB5-79B168A65C73}"= UDP:c:\program files\BurracoWeb\BurracoWebUpdater.exe:BurracoWebUpdater
"{ABB2065F-4B0A-4103-AFB7-FA15741D1EA0}"= TCP:c:\program files\BurracoWeb\BurracoWebUpdater.exe:BurracoWebUpdater
"TCP Query User{9D179734-CF75-4442-81D6-2DCB66BE4C33}c:\\program files\\java\\jre1.6.0_03\\bin\\javaw.exe"= UDP:c:\program files\java\jre1.6.0_03\bin\javaw.exe:Java(TM) Platform SE binary
"UDP Query User{D2E20BEE-63ED-4C01-895D-FAC8F4AEFF92}c:\\program files\\java\\jre1.6.0_03\\bin\\javaw.exe"= TCP:c:\program files\java\jre1.6.0_03\bin\javaw.exe:Java(TM) Platform SE binary
"TCP Query User{954CBADF-ED85-4C15-8C84-8F3C7F0E38E3}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{6F73520A-5FAC-4E24-ABA2-CDD44EBFB6C5}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7161A806-39D3-43E7-AEAA-D1946404C2BD}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{FC6690A9-B87D-4BE9-B26B-4AA5F641213C}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{9C94041C-7838-4630-917C-F980959A30A1}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{BC2BEE5C-36D6-4781-AF4B-0868F53DA646}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{92B82E15-D502-4260-8334-C889568281B6}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"{1641266F-22AB-487C-AA8F-37F6A65AE35D}"= UDP:c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe:Nokia PC Suite
"{D5335F8B-09D0-4EB0-BC38-CD56F6B83697}"= TCP:c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe:Nokia PC Suite
"TCP Query User{B53CED8C-BDEB-4C72-91BA-790882FD5110}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{9D97BAA1-BDED-41CE-A4EC-E0ACA9B95830}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{B104D980-D14F-4111-AE1F-B7BF905C3FF1}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{3BED38B2-E1CB-4ED3-B980-1D618C782D2A}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{E1CF424A-DE47-477C-BF4D-6FA56AACB017}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{71FEBD8E-6A9E-4BB7-AF16-4137A205EF7C}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{87A0CE4C-FB8C-40E7-BEDA-419B138A4ADA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{AD525174-1823-4819-9A7B-5E1D5B39F50A}e:\\setup.exe"= UDP:E:\setup.exe:setup
"UDP Query User{D59B00C1-A68E-43ED-A6DA-CB8603E454B9}e:\\setup.exe"= TCP:E:\setup.exe:setup
"TCP Query User{8D584D87-5737-49E9-A712-7D90AC1C9A53}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{30FB9120-52FD-4BFD-AD84-5B6B62B2FE03}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{DFBC0170-BD4D-4B66-9109-C1624639C564}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{457821B3-C26E-4048-9544-AFD6E8A5F399}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= c:\acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= c:\acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= c:\acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [15/06/2009 0.22.55 64160]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [06/04/2008 18.28.07 114768]
R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [28/03/2007 5.00.12 50688]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [06/04/2008 18.28.07 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [08/02/2008 1.31.46 53328]
R2 BcmSqlStartupSvc;Servizio di avvio SQL Server di Business Contact Manager;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [16/01/2008 11.41.32 30312]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [18/09/2009 1.38.40 1153368]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17/11/2008 8.40.22 3668480]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 21.06.55 1029456]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [02/11/2006 12.25.16 167936]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [24/11/2008 23.31.10 29263712]
S3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\System32\drivers\smscirda.sys [28/03/2007 4.05.57 31232]
S3 V0260VID;Live! Cam Vista IM;c:\windows\System32\drivers\V0260Vid.sys [30/06/2008 22.42.13 154784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 09:46]
2007-11-30 c:\windows\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://it.intl.acer.yahoo.com
uInternet Settings,ProxyOverride = local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\ligi\AppData\Roaming\Mozilla\Firefox\Profiles\vdtmb1xy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-Acer Tour Reminder - (no file)
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-18 17:25
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
[0] 0x00170190
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\eNetHook.dll
- - - - - - - > 'lsass.exe'(636)
c:\windows\system32\eNetHook.dll
.
Ora fine scansione: 2009-09-18 17.30.42
ComboFix-quarantined-files.txt 2009-09-18 15:30
Pre-Run: 5.306.994.688 byte disponibili
Post-Run: 5.149.638.656 byte disponibili
265 --- E O F --- 2009-09-18 14:25