ComboFix 09-10-06.04 - Vale - Mary 08/10/2009 10.41.55.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.3066.1946 [GMT 2:00]
Eseguito da: c:\users\Vale - Mary\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Creati Da 2009-09-08 al 2009-10-08 )))))))))))))))))))))))))))))))))))
.
2009-10-08 08:48 . 2009-10-08 08:48 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-10-08 08:48 . 2009-10-08 08:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-07 08:06 . 2009-10-07 08:06 -------- d-----w- c:\program files\Trend Micro
2009-10-06 13:29 . 2009-10-06 13:29 -------- d-----w- c:\programdata\WindowsSearch
2009-10-04 12:16 . 2009-10-04 12:16 -------- d-----w- c:\users\Vale - Mary\AppData\Roaming\Malwarebytes
2009-10-04 12:16 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-04 12:16 . 2009-10-04 12:16 -------- d-----w- c:\programdata\Malwarebytes
2009-10-04 12:16 . 2009-10-04 12:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-04 12:16 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-02 17:42 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-02 16:40 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-02 16:40 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-02 16:40 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-02 16:40 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-02 16:39 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-02 16:39 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-02 16:39 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-02 16:39 . 2009-08-06 17:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-02 16:39 . 2009-08-06 16:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-02 16:30 . 2009-06-15 14:52 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2009-10-02 16:30 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-10-02 16:30 . 2009-06-15 14:54 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-10-02 16:30 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2009-10-02 16:30 . 2009-06-15 14:53 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-02 16:30 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-10-02 16:30 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll
2009-10-02 16:30 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe
2009-10-01 17:51 . 2009-10-01 17:51 -------- d-----w- c:\users\Vale - Mary\AppData\Local\Panda Security
2009-10-01 17:51 . 2009-10-01 17:51 262 ----a-w- c:\windows\system32\PavCPL.dat
2009-10-01 17:51 . 2003-10-22 16:23 446464 ----a-w- c:\windows\system32\HHActiveX.dll
2009-10-01 17:51 . 2009-03-30 16:23 193792 ----a-w- c:\windows\system32\TpUtil.dll
2009-10-01 17:51 . 2009-03-30 16:22 87296 ----a-w- c:\windows\system32\PavLspHook.dll
2009-10-01 17:51 . 2009-03-30 16:22 55552 ----a-w- c:\windows\system32\pavipc.dll
2009-10-01 17:51 . 2007-02-08 08:53 107568 ----a-w- c:\windows\system32\SYSTOOLS.DLL
2009-10-01 17:51 . 2009-03-30 16:22 518400 ----a-w- c:\windows\system32\PavSHook.dll
2009-09-25 19:30 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-09-25 19:30 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll
2009-09-25 19:30 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe
2009-09-25 19:30 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2009-09-25 19:30 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe
2009-09-25 19:30 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-09-25 19:28 . 2009-04-11 06:28 99840 ----a-w- c:\windows\system32\ulib.dll
2009-09-09 17:03 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-09 17:03 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-09 17:03 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-09 17:03 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-09 17:03 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-09-09 17:03 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-09 17:03 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-09 17:03 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-09 17:03 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-09 17:03 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-09 17:03 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-09 17:02 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 17:02 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 17:02 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 17:02 . 2009-07-11 17:03 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 17:02 . 2009-04-11 06:28 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2009-09-09 17:02 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-09 17:02 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-09 17:02 . 2009-04-11 06:28 98816 ----a-w- c:\windows\system32\mfps.dll
2009-09-09 17:02 . 2009-04-11 06:27 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2009-09-09 17:02 . 2009-04-11 06:27 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-09-09 17:02 . 2009-04-11 04:54 2048 ----a-w- c:\windows\system32\mferror.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 08:45 . 2008-01-21 06:30 662846 ----a-w- c:\windows\system32\perfh010.dat
2009-10-08 08:45 . 2008-01-21 06:30 120326 ----a-w- c:\windows\system32\perfc010.dat
2009-10-08 08:22 . 2009-04-02 18:44 28409 ----a-w- c:\programdata\nvModes.dat
2009-10-08 08:05 . 2009-07-03 17:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-08 08:04 . 2009-07-03 17:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-08 07:57 . 2008-10-30 03:53 -------- d-----w- c:\programdata\NVIDIA
2009-10-01 17:51 . 2009-09-28 17:25 -------- d-----w- c:\program files\Panda Security
2009-10-01 17:51 . 2009-10-01 17:51 -------- d-----w- c:\users\Vale - Mary\AppData\Roaming\Panda Security
2009-10-01 17:51 . 2009-10-01 17:51 -------- d-----w- c:\programdata\Panda Security
2009-10-01 17:51 . 2008-07-31 16:13 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-01 17:48 . 2009-10-01 17:48 -------- d-----w- c:\program files\Common Files\Panda Security
2009-09-30 18:19 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-09-30 18:19 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-09-30 18:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-30 18:19 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-30 18:19 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-09-30 18:19 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-09-30 18:19 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-09-28 19:07 . 2009-01-18 16:14 -------- d-----w- c:\program files\eMule
2009-09-27 09:57 . 2008-10-30 03:27 -------- d-----w- c:\programdata\CyberLink
2009-09-27 09:36 . 2009-06-16 09:10 96 ----a-w- c:\users\Vale - Mary\AppData\Local\muougsy.bat
2009-09-19 20:51 . 2009-06-20 12:21 680 ----a-w- c:\users\Vale - Mary\AppData\Local\d3d9caps.dat
2009-09-11 21:22 . 2009-01-21 17:44 -------- d-----w- c:\users\Vale - Mary\AppData\Roaming\Skype
2009-09-11 14:09 . 2009-01-21 17:49 -------- d-----w- c:\users\Vale - Mary\AppData\Roaming\skypePM
2009-08-29 00:27 . 2009-09-03 12:26 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-03 12:26 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-07-21 21:52 . 2009-08-06 21:23 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-06 21:23 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-06 21:23 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-06 21:23 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 06:04 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-12 06:03 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 06:03 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 06:03 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 06:03 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-02-15 12:43 . 2009-02-15 12:43 60526 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-02-15 12:43 . 2009-02-15 12:43 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-02-15 12:43 . 2009-02-15 12:43 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-10-08_08.23.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-10-08 08:39 77688 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-10-08 08:39 96016 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-18 17:20 . 2009-10-08 08:39 13474 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3329225437-4125545599-1431583979-1000_UserData.bin
+ 2009-01-18 22:46 . 2009-10-08 08:38 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-18 22:46 . 2009-10-08 08:08 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-18 22:46 . 2009-10-08 08:38 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-18 22:46 . 2009-10-08 08:08 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-18 22:46 . 2009-10-08 08:38 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-18 22:46 . 2009-10-08 08:08 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-08 08:37 . 2009-10-08 08:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-10-08 08:22 . 2009-10-08 08:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-10-08 08:37 . 2009-10-08 08:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-10-08 08:45 587178 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-10-08 08:13 587178 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-10-08 08:13 101250 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-10-08 08:45 101250 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-14 15:05 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-18 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-14 526896]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-05-30 544768]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-18 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-18 92704]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-06-04 817672]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-10-30 3676160]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-01-18 24064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"FLMOFFICE4DMOUSE"="c:\program files\Labtec\Mouse\V3.0\moffice.exe" [2009-01-26 958464]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2007-04-19 74672]
"lxczbmgr.exe"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2007-04-19 74672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-25 148888]
"APVXDWIN"="c:\program files\Panda Security\Panda Antivirus for Netbooks\APVXDWIN.EXE" [2009-06-05 574720]
"SCANINICIO"="c:\program files\Panda Security\Panda Antivirus for Netbooks\Inicio.exe" [2009-04-21 56064]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-07 6139904]
c:\users\Vale - Mary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-27 384512]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2008-10-30 1216512]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-2-8 394856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-10-30 03:25 3197952 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spba]
2008-03-25 14:24 567560 ----a-w- c:\program files\Common Files\SPBA\homefus2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):95,8f,84,26,fb,41,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{17B795B1-9461-4B94-AC29-589A7540E4EC}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{00A8FEC5-44DC-4DD8-B586-5C55A6332F6C}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{D6E6B9FE-ADE8-4829-8990-39E989560F6E}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{C91912F1-4D86-4ADD-94AC-9058ADEACFC5}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{7D44E950-2500-4CCB-81F3-401DDBD9B505}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{A320A392-61F5-4929-BB44-15345EFCB2DA}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{69844D45-B6BC-4B48-BBC6-766C8CFA8B99}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4DF7C58E-DA48-4A43-8B26-4F321801885F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A8791673-B0E8-4FEF-8D24-1081A3B0DFC6}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{A696EC6E-E438-4EE8-9474-1AAAF53A6DF5}"= c:\program files\Acer\Acer VCM\VC.exe:Acer VCM
"{A2F2E661-3695-4F4C-A876-5F1037B1DD58}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{36982F78-FE1A-4B10-BEE5-A93063E63518}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CADA6BC9-8049-4CC1-8BA1-16E55D20CB03}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{73E97E60-CD72-4D3A-AADF-6CB4E6B55EA3}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{9AD3D4A9-1B18-434B-A6A4-90AC4D4E00B8}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{066D1F5F-099E-4A6B-B47C-B87D0AC0EB93}"= UDP:c:\windows\System32\lxczcoms.exe:Lexmark Communications System
"{70E2CB36-7F9D-4CCF-A322-39D47EE6A96B}"= TCP:c:\windows\System32\lxczcoms.exe:Lexmark Communications System
"{C27AAB66-00B1-4CF5-9B36-2BD081306023}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{8A669F84-49D6-479C-A576-5AEA508DA91E}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"TCP Query User{0FACD38B-19B7-4A03-B4E6-3086A5C219D9}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{A3A8659E-927A-4964-A929-B31979346802}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\System32\drivers\AlfaFF.sys [30/10/2008 5.25.39 42608]
R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [28/09/2009 19.25.05 28544]
R1 ShldDrv;Panda File Shield Driver;c:\windows\System32\drivers\ShlDrv51.sys [01/10/2009 19.48.20 41144]
R2 AmFSM;AmFSM;c:\windows\System32\drivers\amm8660.sys [01/10/2009 19.51.05 49208]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03/03/2008 13.11.14 16384]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [31/07/2008 18.26.32 24576]
R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda --> c:\windows\system32\svchost -k Panda [?]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [25/04/2008 21.36.20 45056]
R2 PavProc;Panda Process Protection Driver;c:\windows\System32\drivers\PavProc.sys [01/10/2009 19.48.20 177416]
R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Antivirus for Netbooks\psksvc.exe [01/10/2009 19.51.26 28928]
R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [30/10/2008 5.48.04 233472]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [01/08/2008 3.32.49 47104]
R3 NETw5v32;Driver scheda Intel(R) Wireless WiFi Link per Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [01/08/2008 3.32.58 3658752]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [25/06/2008 7.05.06 44064]
R3 winbondcir;Winbond IR Transceiver;c:\windows\System32\drivers\winbondcir.sys [28/03/2007 7.51.40 43008]
S2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [30/10/2008 5.25.42 3602432]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [25/04/2008 21.36.02 131072]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [18/01/2009 17.45.50 24064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0410&s=2&o=vp32&d=1008&m=aspire_6930g
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0410&s=2&o=vp32&d=1008&m=aspire_6930g
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Vale - Mary\AppData\Roaming\Mozilla\Firefox\Profiles\53nelibw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0410&s=2&o=vp32&d=1008&m=aspire_6930g
FF - component: c:\progra~1\MOZILL~1\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-08 10:48
Windows 6.0.6002 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'Explorer.exe'(5128)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\System32\SysHook.dll
.
Ora fine scansione: 2009-10-08 10.50.08
ComboFix-quarantined-files.txt 2009-10-08 08:50
ComboFix2.txt 2009-10-08 08:28
Pre-Run: 58.703.224.832 byte disponibili
Post-Run: 58.664.226.816 byte disponibili
292 --- E O F --- 2009-10-06 12:29