Ho fatto tutto come indicato e invio i log Combofix
ComboFix 09-10-11.01 - Proprietario 12/10/2009 3.18.12.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1024.600 [GMT 2:00]
Eseguito da: c:\documents and settings\Proprietario\Desktop\ComboFix.exe
FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Proprietario\Dati applicazioni\02000000e751b0e8660C.manifest
c:\documents and settings\Proprietario\Dati applicazioni\02000000e751b0e8660O.manifest
c:\documents and settings\Proprietario\Dati applicazioni\02000000e751b0e8660P.manifest
c:\documents and settings\Proprietario\Dati applicazioni\02000000e751b0e8660S.manifest
c:\programmi\\setup.exe
c:\programmi\autorun.inf
c:\windows\GnuHashes.ini
c:\windows\Installer\65d12f.msi
c:\windows\Installer\f562.msi
c:\windows\system32\29MF0.vbs
c:\windows\system32\9.tmp
c:\windows\system32\A.tmp
c:\windows\system32\aN9tz6L91lEOe.vbs
c:\windows\system32\DHCPMON32.DLL
c:\windows\system32\DPVOICE32.DLL
c:\windows\system32\DPWSOCKX32.DLL
c:\windows\system32\DSSEC32.DLL
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\hjpPS.vbs
c:\windows\system32\LocalService\313.crack.zip.kwd
c:\windows\system32\LocalService\314.keygen.zip.kwd
c:\windows\system32\LocalService\315.serial.zip.kwd
c:\windows\system32\LocalService\316.setup.zip.kwd
c:\windows\system32\LocalService\317.music.au
c:\windows\system32\LocalService\317.music.au.kwd
c:\windows\system32\LocalService\318.music2.au
c:\windows\system32\LocalService\318.music2.au.kwd
c:\windows\system32\LocalService\319.music3.au
c:\windows\system32\LocalService\319.music3.au.kwd
c:\windows\system32\LocalService\320.music4.au
c:\windows\system32\LocalService\320.music4.au.kwd
c:\windows\system32\lUP4K7MSpXnyF.vbs
c:\windows\system32\mCsIqXT5RC3MH.vbs
c:\windows\system32\MtcJw.vbs
c:\windows\system32\nbUK5gM.vbs
c:\windows\system32\oDScgoqCfMuTDBO.vbs
c:\windows\system32\QzI9Y.vbs
c:\windows\system32\RhSUcMs9N9OzMij.vbs
c:\windows\system32\u3HTW.vbs
c:\windows\system32\vKPRRWKZPQAJN.vbs
c:\windows\system32\VX86mb1.vbs
D:\resycled
d:\resycled\boot.com
.
((((((((((((((((((((((((( Files Creati Da 2009-09-12 al 2009-10-12 )))))))))))))))))))))))))))))))))))
.
2010-04-28 13:32 . 2010-04-28 13:32 -------- d-----w- c:\programmi\AVG
2010-04-28 13:23 . 2010-04-28 13:23 65950560 ----a-w- c:\programmi\avg_free_stf_eu_85_287a1483.exe
2009-10-12 01:07 . 2009-10-12 01:07 116736 ----a-w- c:\windows\system32\csseqchk32.dll
2009-10-11 20:51 . 2009-10-11 20:51 116736 ----a-w- c:\windows\system32\fontext32.dll
2009-10-11 14:22 . 2009-10-11 14:22 -------- d-----w- c:\programmi\Trend Micro
2009-10-11 14:21 . 2009-10-11 14:21 812344 ----a-w- c:\programmi\HJTInstall.exe
2009-10-11 07:34 . 2009-10-11 07:34 -------- d-----w- c:\programmi\File comuni\Macrovision Shared
2009-10-11 06:38 . 2009-10-11 14:52 -------- d-----w- c:\programmi\Bonjour
2009-10-08 21:27 . 2009-10-12 01:23 -------- d-sh--w- c:\windows\system32\LocalService
2009-09-26 13:33 . 2009-09-26 13:33 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-12 01:27 . 2008-09-28 17:43 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-10-12 01:26 . 2008-09-26 16:21 24 ----a-w- c:\windows\system32\DVCStateBkp-{00000000-00000000-0000000A-00001102-00000004-005A1102}.dat
2009-10-12 01:26 . 2008-09-26 16:21 24 ----a-w- c:\windows\system32\DVCState-{00000000-00000000-0000000A-00001102-00000004-005A1102}.dat
2009-10-12 01:25 . 2009-08-12 14:02 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Skype
2009-10-12 01:14 . 2008-09-26 16:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-10-11 18:21 . 2009-08-07 20:02 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\skypePM
2009-10-11 14:35 . 2009-08-25 08:41 129 ----a-w- c:\documents and settings\Proprietario\udpcrawl.tmp
2009-10-11 07:45 . 2008-09-26 16:53 -------- d-----w- c:\programmi\File comuni\Adobe
2009-10-11 07:26 . 2008-09-28 22:45 -------- d-----w- c:\programmi\Java
2009-10-11 06:46 . 2008-09-26 16:06 74984 ----a-w- c:\documents and settings\Proprietario\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-06 17:55 . 2009-02-09 21:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-10-02 18:21 . 2008-09-28 22:50 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\LimeWire
2009-09-05 21:27 . 2009-09-05 21:27 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\Leadertech
2009-08-30 19:53 . 2009-08-30 19:53 -------- d-----w- c:\programmi\File comuni\PAC7311
2009-08-30 19:53 . 2009-08-30 19:53 -------- d-----w- c:\programmi\Trust
2009-08-30 10:05 . 2009-08-30 10:05 -------- d-----w- c:\documents and settings\Proprietario\Dati applicazioni\GlarySoft
2009-08-30 10:01 . 2009-08-30 10:01 -------- d-----w- c:\programmi\Glary Utilities
2009-08-30 10:00 . 2009-08-30 10:00 -------- d-----w- c:\programmi\Glary_Utilities
2009-08-30 09:56 . 2009-08-30 09:56 5488957 ----a-w- c:\programmi\Glary_Utilities.zip
2009-08-30 09:39 . 2009-08-30 09:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Fighters
2009-08-24 23:38 . 2009-08-24 23:37 -------- d-----w- c:\programmi\Paint.NET
2009-08-24 21:13 . 2009-08-24 21:13 1603760 ----a-w- c:\programmi\Paint.NET.3.36.zip
2009-08-24 15:57 . 2009-08-24 15:57 -------- d-----w- c:\programmi\File comuni\Adobe Systems Shared
2009-08-24 05:49 . 2009-08-24 05:22 -------- d-----w- c:\programmi\PhotoScape
2009-08-24 05:21 . 2009-08-24 05:21 15063882 ----a-w- c:\programmi\PhotoScapeSetup_V3.3.exe
2009-08-23 19:53 . 2009-08-23 19:53 119296 ----a-w- c:\windows\system32\expsrv32.dll
2009-08-23 14:56 . 2009-08-23 14:56 52636 ---ha-w- c:\windows\system32\mlfcache.dat
2009-08-23 13:47 . 2009-08-23 13:46 -------- d-----w- c:\programmi\Informazioni Tecniche
2009-08-23 13:47 . 2009-08-23 13:46 -------- d-----w- c:\programmi\Extra
2009-08-23 13:47 . 2009-08-23 13:46 -------- d-----w- c:\programmi\AutoPlay
2009-08-23 13:46 . 2009-08-23 13:46 -------- d-----w- c:\programmi\Assistenza clienti
2009-08-23 13:46 . 2009-08-23 13:46 -------- d-----w- c:\programmi\Adobe Solutions Network
2009-08-23 13:46 . 2009-08-23 13:46 -------- d-----w- c:\programmi\Adobe Reader 7.0
2009-08-23 08:15 . 2009-08-23 08:15 -------- d-----w- c:\programmi\Alice ti aiuta
2009-08-19 22:25 . 2009-08-19 22:25 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Adobe Systems
2009-08-16 06:33 . 2009-08-16 06:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Motive
2009-08-15 05:01 . 2009-08-15 05:01 -------- d-----w- c:\programmi\Microsoft CAPICOM 2.1.0.2
2009-08-14 10:37 . 2008-11-23 18:33 -------- d-----w- c:\programmi\Virtual Earth 3D
2009-08-12 14:01 . 2009-08-12 14:00 2032936 ----a-w- c:\programmi\SkypeSetup.exe
2009-08-12 13:53 . 2009-08-12 13:53 8599101 ----a-w- c:\programmi\15355_01.exe
2009-08-07 20:02 . 2009-08-07 20:02 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-06 17:24 . 2008-09-26 15:43 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2008-09-26 15:43 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2008-09-26 15:43 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2008-07-18 20:10 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2008-09-26 15:43 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2006-03-02 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2008-09-26 15:43 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2009-08-15 04:07 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 17:23 . 2009-08-15 04:07 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 17:23 . 2008-09-26 15:43 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 08:59 . 2006-03-02 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-19 23:35 . 2009-07-19 23:34 22962563 ----a-w- c:\programmi\Rubrica.exe
2009-07-19 16:48 . 2009-07-19 16:48 71540 ----a-w- c:\programmi\CalendarPrint.zip
2009-07-17 19:01 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-06-09 17:07 . 2009-06-09 17:07 3342809 ----a-w- c:\programmi\eMule0.49c-Installer.exe
2009-06-09 09:57 . 2009-06-09 09:57 10053112 ----a-w- c:\programmi\picasa3-setup.exe
2009-05-02 05:28 . 2009-05-02 05:28 1053744 ----a-w- c:\programmi\revosetup.exe
2008-12-14 19:13 . 2008-12-14 19:13 372520 ----a-w- c:\programmi\ymjsetup_24.exe
2008-12-07 18:27 . 2008-12-07 18:27 14958253 ----a-w- c:\programmi\Windows_Sidebar__Real_one_Pack_by_joshoon.zip
2008-10-13 00:00 . 2008-10-12 23:55 183 ----a-w- c:\programmi\presence_sip_pandreoni_alice_it.xml
2008-10-12 23:52 . 2008-10-12 23:52 183 ----a-w- c:\programmi\presence_sip_pandreono_alice_it.xml
2008-10-07 20:12 . 2008-10-07 20:11 1011844 ----a-w- c:\programmi\SetupPoigpsGo.zip
2008-10-05 21:41 . 2008-10-05 21:41 7730856 ----a-w- c:\programmi\GoogleEarth.exe
2004-08-10 21:09 . 2009-08-23 13:46 126976 ----a-w- c:\programmi\epic_eula.dll
2004-03-01 05:43 . 2009-08-23 13:46 625 ----a-w- c:\programmi\Setup.exe.manifest
2003-04-20 18:39 . 2009-08-23 13:46 245408 ----a-w- c:\programmi\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}"= "c:\programmi\PHPNukeIT\tbPHP1.dll" [2009-07-12 2215960]
[HKEY_CLASSES_ROOT\clsid\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05647034-1833-4EF0-AD7E-D6603C152BFe}]
2009-10-11 20:51 116736 ----a-w- c:\windows\system32\fontext32.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
2009-07-12 09:38 2215960 ----a-w- c:\programmi\PHPNukeIT\tbPHP1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}"= "c:\programmi\PHPNukeIT\tbPHP1.dll" [2009-07-12 2215960]
[HKEY_CLASSES_ROOT\clsid\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{2C965F3F-8EFD-4BFC-A2C5-1672845FDBBF}"= "c:\programmi\PHPNukeIT\tbPHP1.dll" [2009-07-12 2215960]
[HKEY_CLASSES_ROOT\clsid\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-14 1695232]
"TomTomHOME.exe"="c:\programmi\TomTom HOME 2\TomTomHOMERunner.exe" [2009-08-07 247144]
"TaskTray"="c:\programmi\Creative\SBAudigy\TaskBar\CTLTray.exe" [2001-06-29 163840]
"TaskBar"="c:\programmi\Creative\SBAudigy\TaskBar\CTLTask.exe" [2002-05-08 122880]
"Sidebar"="c:\programmi\Windows Sidebar\sidebar.exe" [2007-07-28 1230848]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-16 68856]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2009-07-16 25604904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"CTStartup"="c:\programmi\Creative\Splash Screen\CTEaxSpl.EXE" [2001-12-19 28672]
"Jet Detection"="c:\programmi\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"StormCodec_Helper"="c:\programmi\Ringz Studio\Storm Codec\StormSet.exe" [2006-11-26 97357]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2008-12-11 2652056]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"HP Software Update"="c:\programmi\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2002-12-17 49152]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-26 172032]
"DeviceDiscovery"="c:\programmi\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2002-12-02 40960]
"Disc Detector"="c:\programmi\Creative\ShareDLL\CtNotify.exe" [2001-12-25 191488]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Google Quick Search Box"="c:\programmi\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-08 68592]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2007-06-22 569344]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"WINDVDPatch"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2002-07-02 24576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2004-12-24 483328]
Microsoft Office.lnk - c:\programmi\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fc170e3e660]
2009-08-23 19:53 119296 ----a-w- c:\windows\system32\expsrv32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [14/04/2009 13.16.34 159600]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [14/04/2009 13.16.40 73840]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmi\TomTom HOME 2\TomTomHOMEService.exe [07/08/2009 16.31.40 92008]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [14/04/2009 13.16.20 95640]
S2 gupdate1c98afdb2c2012c;Google Update Service (gupdate1c98afdb2c2012c);c:\programmi\Google\Update\GoogleUpdate.exe [09/02/2009 23.30.56 133104]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [28/09/2008 10.38.09 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
"c:\programmi\Windows Sidebar\sidebar.exe" /RegServer
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-11 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2009-08-30 14:09]
2009-10-12 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-28 06:09]
2009-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-09 21:30]
2009-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-09 21:30]
2009-07-12 c:\windows\Tasks\User_Feed_Synchronization-{7B6974CF-900C-467F-9F8B-3243D7DE8C97}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-AliceRE_McciTrayApp - c:\progra~1\ALICET~1\vendors\AliceRE\content\template\DRIVEN~1\syncer\MCCITR~1.EXE
Notify-avgrsstarter - avgrsstx.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-12 03:27
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = c:\programmi\Creative\Splash Screen\CTEaxSpl.EXE /run???????h??????s?????\?w? ?w???????w???w4???????.??w4???????4???TA?s4????????&??????\??? ??? ???\???\???????????5?:~e?:~\???\????????9`??????C@?\???\??????s????\??????s\????&??A??s?&???C@?x???`|?w\?????@
Disc Detector = c:\programmi\Creative\ShareDLL\CtNotify.exe?? ??X???????????????????E?@?Disc Detector?A????? ?A?p ????B?e!@???@???@?? C?????E?@?????????@?B???A????? ?A?? ????B???@?????P?????@?? ??????~?:~??????????@???????????????????B?????? ??????????????????????????r?B
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1844237615-2052111302-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\System32\expsrv32.dll
- - - - - - - > 'explorer.exe'(3468)
c:\windows\system32\WININET.dll
c:\programmi\Google\Quick Search Box\bin\1.2.1150.158\qsb.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\System32\expsrv32.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\CTSVCCDA.EXE
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\PC Tools Firewall Plus\FWService.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\Creative\ShareDLL\MEDIADET.EXE
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
c:\programmi\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Ora fine scansione: 2009-10-12 3.30.41 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-10-12 01:30
Pre-Run: 81.158.500.352 byte disponibili
Post-Run: 81.267.724.288 byte disponibili
282 --- E O F --- 2009-09-09 06:01