Ciao. Fatto tutto come indicato. Unica curiosità... è normale che dopo la scansione con combo mi sia apparsa sul desktop una nuova icona di internet explorer?
Ciao.
posto il log di combo :
ComboFix 09-10-11.03 - Administrator 12/10/2009 21.46.15.2.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3327.2796 [GMT 2:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1356 [VPS 091011-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Outpost Firewall *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
.
((((((((((((((((((((((((( Files Creati Da 2009-09-12 al 2009-10-12 )))))))))))))))))))))))))))))))))))
.
2009-10-12 18:40 . 2009-09-15 10:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-12 18:40 . 2009-09-15 10:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-12 18:40 . 2009-09-15 10:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-12 18:40 . 2009-09-15 10:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-12 18:40 . 2009-09-15 10:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-12 18:40 . 2009-09-15 10:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-12 18:40 . 2009-09-15 10:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-12 18:40 . 2009-09-15 10:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-11 23:04 . 2009-10-12 18:02 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-10-11 21:51 . 2009-10-11 21:51 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2009-10-11 21:51 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-11 21:51 . 2009-10-11 21:51 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-10-11 21:51 . 2009-10-11 21:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-10-11 21:51 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-11 18:15 . 2009-10-11 18:15 -------- d-----w- c:\programmi\Trend Micro
2009-10-11 14:56 . 2009-10-11 14:56 -------- d-----w- c:\windows\system32\xircom
2009-10-11 14:56 . 2009-10-11 14:56 -------- d-----w- c:\windows\system32\wbem\snmp
2009-10-11 14:56 . 2009-10-11 14:56 -------- d-----w- c:\programmi\microsoft frontpage
2009-10-11 14:25 . 2008-10-21 12:10 319488 ----a-w- c:\windows\system32\dirtysock.dll
2009-10-11 11:45 . 2009-10-11 11:45 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Uniblue
2009-10-10 00:07 . 2009-10-10 00:05 6070272 --sh--r- C:\FIFA10-CDrun.exe
2009-10-10 00:07 . 2009-10-10 00:07 -------- d-sh--r- c:\programmi\FIFA 10
2009-10-08 21:11 . 2009-10-08 21:13 -------- d--h--w- c:\windows\$hf_mig$
2009-10-08 21:08 . 2009-06-29 16:12 459264 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-10-08 21:08 . 2009-06-29 16:12 268288 ------w- c:\windows\system32\dllcache\iertutil.dll
2009-10-08 21:08 . 2009-06-29 16:12 52224 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-08 21:08 . 2009-06-29 11:25 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-10-08 21:08 . 2009-06-29 08:33 2452872 ------w- c:\windows\system32\dllcache\ieapfltr.dat
2009-10-08 21:08 . 2009-07-19 13:20 6070784 ------w- c:\windows\system32\dllcache\ieframe.dll
2009-10-08 21:08 . 2009-06-29 16:12 63488 ------w- c:\windows\system32\dllcache\icardie.dll
2009-10-08 21:08 . 2009-06-29 16:12 380928 ------w- c:\windows\system32\dllcache\ieapfltr.dll
2009-10-08 20:07 . 2009-10-08 20:07 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-10-08 19:58 . 2009-10-08 19:58 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-10-08 19:55 . 2009-06-29 16:12 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-02 23:29 . 2009-10-02 23:29 74752 ----a-w- c:\windows\ST6UNST.EXE
2009-10-02 23:29 . 2009-10-02 23:29 290816 ------w- c:\windows\Setup1.exe
2009-10-02 21:39 . 2009-10-02 21:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Babylon
2009-10-02 21:39 . 2009-10-02 21:39 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Babylon
2009-10-02 19:42 . 2009-04-06 09:37 704384 ----a-w- c:\windows\system32\drivers\SandBox.sys
2009-10-02 19:42 . 2009-02-10 14:15 257432 ----a-w- c:\windows\system32\drivers\afwcore.sys
2009-10-02 19:41 . 2009-02-18 15:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys
2009-10-02 19:41 . 2009-10-02 19:41 -------- d-----w- c:\programmi\Agnitum
2009-10-02 19:33 . 2009-10-02 19:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Agnitum
2009-09-30 19:55 . 2009-10-02 19:23 -------- d-----w- c:\programmi\Sunbelt Software
2009-09-30 19:47 . 2009-10-12 19:46 -------- d-----w- c:\programmi\PeerGuardian2
2009-09-25 21:55 . 2005-12-28 14:44 162816 ----a-w- c:\windows\system32\fmod.dll
2009-09-25 21:55 . 2001-04-27 13:11 24576 ----a-w- c:\windows\system32\smartsubclass.dll
2009-09-25 21:55 . 2005-11-11 16:42 40208 ----a-w- c:\windows\system32\dsetup.dll
2009-09-25 21:54 . 2009-09-25 22:34 -------- d-----w- c:\programmi\Atmosphere Lite
2009-09-19 10:35 . 2009-09-19 10:35 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-19 10:17 . 2009-04-02 14:43 520 ----a-w- c:\windows\system32\drivers\SamSfPa.dat
2009-09-19 10:13 . 2009-09-19 10:14 -------- d--h--w- c:\windows\msdownld.tmp
2009-09-19 08:51 . 2009-09-19 08:51 -------- d-----w- c:\programmi\IObit
2009-09-19 08:43 . 2009-09-19 12:11 -------- d-----w- c:\programmi\Fs2Utils
2009-09-19 08:39 . 2009-10-10 23:31 -------- d-----w- c:\programmi\fishsim2
2009-09-18 18:19 . 2009-09-18 18:19 -------- d-----w- c:\programmi\NVIDIA Corporation
2009-09-18 18:19 . 2009-09-18 18:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NVIDIA Corporation
2009-09-18 18:19 . 2009-08-16 22:57 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-09-18 18:18 . 2009-08-11 10:35 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-09-17 19:19 . 2009-09-17 19:19 -------- d-----w- c:\programmi\KONAMI
2009-09-14 19:18 . 2009-09-24 18:24 -------- d-----w- c:\programmi\TrueFish
2009-09-13 20:05 . 2009-09-13 20:05 -------- d-----w- c:\programmi\Finson Live Update
2009-09-13 20:05 . 2000-11-09 16:31 79360 ----a-w- c:\windows\system32\FinsonLU.dll
2009-09-13 20:04 . 2009-09-14 20:24 -------- d-----w- c:\programmi\Coiffeur 3
2009-09-12 22:28 . 2009-09-12 22:28 -------- d-----w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google
2009-09-12 22:28 . 2009-09-12 22:28 -------- d-----w- c:\programmi\Google
2009-09-12 22:20 . 2009-09-12 22:20 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-12 18:15 . 2001-08-31 16:00 84156 ----a-w- c:\windows\system32\perfc010.dat
2009-10-12 18:15 . 2001-08-31 16:00 489410 ----a-w- c:\windows\system32\perfh010.dat
2009-10-11 21:42 . 2008-09-25 20:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-10-11 21:38 . 2009-04-19 15:27 -------- d-----w- c:\programmi\QuickTime
2009-10-11 18:25 . 2005-04-08 02:16 25632 ---ha-w- c:\documents and settings\Administrator\Dati applicazioni\logs.dat
2009-10-10 17:35 . 2008-09-25 20:33 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-10-10 17:35 . 2008-09-25 21:06 -------- d-----w- c:\programmi\SpywareBlaster
2009-09-30 19:25 . 2008-11-27 20:36 -------- d-----w- c:\programmi\File comuni\PC Tools
2009-09-30 19:25 . 2008-11-27 20:36 -------- d-----w- c:\programmi\PC Tools Firewall Plus
2009-09-27 15:12 . 2008-09-25 15:23 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-09-19 10:34 . 2008-09-25 15:48 -------- d-----w- c:\programmi\Realtek
2009-09-19 09:17 . 2009-01-08 21:18 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-18 20:35 . 2009-06-01 19:56 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\SoundSpectrum
2009-09-18 20:35 . 2009-06-01 19:55 -------- d-----w- c:\programmi\SoundSpectrum
2009-09-18 18:20 . 2008-11-15 20:45 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-09-18 18:19 . 2008-11-15 20:45 -------- d-----w- c:\programmi\AGEIA Technologies
2009-09-12 18:51 . 2008-09-25 15:23 -------- d-----w- c:\programmi\Windows Media Connect 2
2009-09-12 18:35 . 2008-11-09 15:53 -------- d-----w- c:\programmi\Rockstar Games
2009-09-12 18:34 . 2008-09-25 15:48 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-09-12 18:29 . 2009-09-12 18:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NCH Software
2009-09-12 18:26 . 2009-09-12 18:26 -------- d-----w- c:\programmi\NCH Software
2009-09-12 18:26 . 2009-09-12 18:26 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\NCH Software
2009-09-12 18:09 . 2009-09-12 18:01 -------- d-----w- c:\programmi\File comuni\AVSMedia
2009-09-12 18:02 . 2009-09-12 18:02 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\AVS4YOU
2009-09-12 18:02 . 2009-09-12 18:02 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\AVS4YOU
2009-09-12 18:02 . 2008-09-25 12:41 67104 ----a-w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-12 15:37 . 2009-09-12 15:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Bug Shooting
2009-09-12 15:14 . 2009-09-12 15:14 -------- d-----w- c:\programmi\Bug Shooting
2009-09-12 10:50 . 2008-09-25 20:59 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2009-09-03 20:18 . 2009-09-03 20:18 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\CyberLink
2009-08-17 01:03 . 2009-08-17 01:03 3674112 ----a-w- c:\windows\system32\nvwssr.dll
2009-08-17 01:02 . 2009-08-17 01:02 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-08-16 22:57 . 2009-08-16 22:57 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-08-16 22:57 . 2009-08-16 22:57 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-08-16 22:57 . 2009-08-16 22:57 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-08-16 22:57 . 2009-08-16 22:57 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-08-16 22:57 . 2009-08-16 22:57 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-08-16 22:57 . 2009-08-16 22:57 155648 ----a-w- c:\windows\system32\nvcodins.dll
2009-08-16 22:57 . 2009-08-16 22:57 155648 ----a-w- c:\windows\system32\nvcod.dll
2009-08-16 22:57 . 2009-08-16 22:57 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-08-16 22:57 . 2007-09-16 17:07 7729568 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-08-16 22:57 . 2007-09-16 17:07 5845760 ----a-w- c:\windows\system32\nv4_disp.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"LogitechSoftwareUpdate"="c:\programmi\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"VeohPlugin"="c:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-05-19 3561720]
"PeerGuardian"="c:\programmi\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\programmi\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\programmi\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"ClamWin"="c:\programmi\ClamWin\bin\ClamTray.exe" [2008-09-05 86016]
"AdobeCS4ServiceManager"="c:\programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"nwiz"="c:\programmi\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-01-30 16116224]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-06-29 124928]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - c:\programmi\Alice ti aiuta\bin\matcli.exe [2008-9-25 212992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FAH-02"=2 (0x2)
"MDM"=2 (0x2)
"FAH-01"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Programmi\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Programmi\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Programmi\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Programmi\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Programmi\\File comuni\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Programmi\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Programmi\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Programmi\\Lphant\\eLePhantClient.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12/10/2009 20.40.34 114768]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [02/10/2009 21.42.56 704384]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [02/10/2009 21.41.25 1195008]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/10/2009 20.40.36 20560]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [02/10/2009 21.41.27 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [02/10/2009 21.42.51 257432]
S4 FAH-01;Folding Service #01;c:\folding@home\Folding@Home #02\FAH-Console.exe [30/06/2008 21.38.32 253952]
S4 FAH-02;Folding Service #02;c:\folding@home\Folding@Home #02\FAH-Console.exe [30/06/2008 21.38.32 253952]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - ASWUPDSV
*NewlyCreated* - AVAST!_MAIL_SCANNER
*NewlyCreated* - AVAST!_WEB_SCANNER
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.virgilio.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-12 21:50
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-823518204-1229272821-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ba,31,b7,59,dd,94,a4,43,8e,76,63,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ba,31,b7,59,dd,94,a4,43,8e,76,63,\
[HKEY_USERS\S-1-5-21-823518204-1229272821-1801674531-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:94,42,70,4a,32,64,05,ca,bb,56,ff,c1,d3,ac,08,cc,fc,57,04,f9,db,95,61,
3a,5d,42,4c,a5,be,18,96,05,3a,a6,53,16,6b,7e,bb,9b,42,75,2c,b5,b1,f7,45,68,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-823518204-1229272821-1801674531-500\Software\SecuROM\License information*]
"datasecu"=hex:50,e4,9f,1c,9c,32,26,5f,11,4c,75,b0,9d,b0,b0,24,20,e6,79,5c,42,
38,25,bb,99,b6,ec,3b,84,53,b9,d3,a5,54,a0,2d,5f,68,72,ab,98,3d,87,d8,73,7c,\
"rkeysecu"=hex:00,ad,6d,49,0f,a1,6f,eb,72,da,dd,90,f1,4e,e8,7a
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(496)
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Ora fine scansione: 2009-10-12 21.52.03
ComboFix-quarantined-files.txt 2009-10-12 19:52
Pre-Run: 238.255.812.608 byte disponibili
Post-Run: 238.227.251.200 byte disponibili
251