ComboFix 09-11-16.03 - Utente 19/11/2009 23.09.14..2 - FAT32x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1023.721 [GMT 1:00]
Eseguito da: c:\documents and settings\Utente\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {00000002-0002-0000-6C25-9E7C08000A00}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Utente\Dati applicazioni\Desktopicon
c:\documents and settings\Utente\Dati applicazioni\Desktopicon\eBay.ico
c:\documents and settings\Utente\Dati applicazioni\Desktopicon\uninst.exe
c:\documents and settings\Utente\Dati applicazioni\inst.exe
c:\documents and settings\Utente\Documenti\ZbThumbnail.info
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\awuso.dat
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\awuso_nav.dat
c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\awuso_navps.dat
.
((((((((((((((((((((((((( Files Creati Da 2009-10-19 al 2009-11-19 )))))))))))))))))))))))))))))))))))
.
2009-11-17 05:03 . 2009-11-17 05:07 5908024 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Resources.dll
2009-11-17 05:03 . 2009-11-17 05:03 327000 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-17 05:03 . 2009-11-17 05:03 87496 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-17 04:58 . 2009-11-17 05:00 0 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-11-17 04:57 . 2009-11-17 04:58 641632 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-17 04:54 . 2009-11-17 04:55 816272 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-11-17 04:51 . 2009-11-17 04:54 822904 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-11-17 04:49 . 2009-11-17 04:51 1638640 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-11-17 04:48 . 2009-11-17 04:49 788880 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-11-17 04:47 . 2009-11-17 04:48 1184912 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-11-17 03:57 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-11-17 03:54 . 2009-10-03 08:15 2924848 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-11-17 03:54 . 2009-11-17 03:54 -------- dc-h--w- c:\documents and settings\All Users\Dati applicazioni\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-17 03:52 . 2009-11-17 03:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2009-11-17 03:52 . 2009-11-17 03:52 -------- d-----w- c:\programmi\Lavasoft
2009-11-16 23:01 . 2009-11-16 23:01 -------- d-----w- c:\programmi\Globus
2009-11-16 22:36 . 2009-11-16 22:36 8240064 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Azureus\tmp\AZU24902.tmp\Vuze_4.3.0.0_win32.exe
2009-11-16 21:34 . 2009-11-16 21:34 -------- d-----w- c:\documents and settings\Utente\Nuova cartella (3)
2009-11-16 05:05 . 2009-11-16 05:05 -------- d-----w- c:\programmi\JPEGCompress
2009-11-12 05:50 . 2009-09-03 09:17 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-11-12 05:36 . 2009-11-12 05:37 93360 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-11-12 05:35 . 2009-11-12 05:36 862040 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-11-12 05:35 . 2009-11-12 05:35 554280 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\sbap.dll
2009-11-12 05:35 . 2009-11-12 05:35 15880 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-11-12 05:34 . 2009-11-12 05:34 206944 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-11-12 05:33 . 2009-11-12 05:34 390288 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-11-12 05:33 . 2009-11-12 05:33 537576 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-11-12 05:32 . 2009-11-12 05:33 212480 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-11-12 05:32 . 2009-11-12 05:32 283944 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-11-12 05:31 . 2009-11-12 05:31 370744 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-11-12 05:31 . 2009-11-12 05:31 163728 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-11-12 05:31 . 2009-11-12 05:31 194104 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-11-12 05:30 . 2009-11-12 05:31 1223976 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-11-12 05:29 . 2009-11-12 05:29 242984 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-11-08 22:41 . 2009-10-30 13:38 528764 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aescript.dll
2009-11-08 22:41 . 2009-09-15 15:58 106867 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aevdf.dll
2009-11-08 22:41 . 2009-09-03 15:24 127346 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aescn.dll
2009-11-08 22:41 . 2009-11-05 14:21 422261 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aepack.dll
2009-11-08 22:41 . 2009-11-05 14:21 2093431 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aeheur.dll
2009-11-08 22:41 . 2009-11-05 14:21 364916 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aegen.dll
2009-11-08 22:41 . 2009-10-02 22:15 479604 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aerdl.dll
2009-11-08 22:41 . 2009-09-03 15:24 237940 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aehelp.dll
2009-11-08 22:41 . 2009-06-17 14:32 196987 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aeoffice.dll
2009-11-08 22:41 . 2009-11-05 14:21 184694 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aecore.dll
2009-11-08 22:41 . 2009-10-02 22:15 393587 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\FAILSAVE\aeemu.dll
2009-11-08 22:41 . 2008-10-15 10:49 53618 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Avira\AntiVir Desktop\CONFIG\AVWIN.INIaebb.dll
2009-11-08 03:22 . 2009-11-08 03:22 -------- d-----w- c:\documents and settings\Utente\Nuova cartella (2)
2009-11-01 13:04 . 2009-11-01 13:07 -------- d-----w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\AskToolbar
2009-10-31 13:46 . 2009-10-31 13:47 -------- d-----w- c:\programmi\Ask.com
2009-10-31 13:46 . 2009-10-31 16:56 -------- d-----w- c:\programmi\File comuni\DVDVideoSoft
2009-10-31 13:46 . 2009-10-31 14:40 -------- d-----w- c:\programmi\DVDVideoSoft
2009-10-31 11:32 . 2009-10-31 11:32 -------- d-----w- c:\documents and settings\Utente\esame 2lia
2009-10-31 07:40 . 2009-10-31 07:40 -------- d-----w- C:\Disc1 (DVD-Video
2009-10-29 22:43 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-29 22:43 . 2009-02-13 11:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-29 22:43 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-29 22:43 . 2009-10-29 22:43 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-16 22:49 . 2009-10-01 16:44 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Azureus
2009-11-16 21:26 . 2008-10-22 15:00 1 ----a-w- c:\documents and settings\Utente\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-12 05:52 . 2009-04-13 00:16 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2009-11-10 02:52 . 2009-02-09 23:19 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-11-09 14:23 . 2009-02-08 23:44 -------- d-----w- c:\programmi\Mozilla Thunderbird
2009-11-09 01:08 . 2009-02-27 22:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DriverCure
2009-11-02 22:25 . 2009-03-27 23:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NCH Swift Sound
2009-11-02 22:25 . 2009-03-27 23:12 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\NCH Swift Sound
2009-11-02 22:23 . 2009-03-28 13:46 -------- d-----w- c:\programmi\NCH Swift Sound
2009-11-02 18:12 . 2008-12-25 16:10 335 ----a-w- c:\windows\nsreg.dat
2009-11-02 14:16 . 2009-04-12 19:43 -------- d-----w- c:\programmi\vanBasco's Karaoke Player
2009-10-31 17:13 . 2009-03-28 00:35 -------- d-----w- c:\programmi\AVS4YOU
2009-10-31 13:22 . 2009-03-28 00:35 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\AVS4YOU
2009-10-29 23:50 . 2008-11-19 22:31 -------- d-----w- c:\programmi\eMule
2009-10-29 21:25 . 2008-10-21 17:18 18624 ----a-w- c:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-10-29 21:15 . 2009-09-04 13:46 -------- d-----w- c:\programmi\Fighters
2009-10-29 20:59 . 2009-10-28 20:34 4526 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-10-29 20:59 . 2001-08-31 17:00 80186 ----a-w- c:\windows\system32\perfc010.dat
2009-10-29 20:59 . 2001-08-31 17:00 480640 ----a-w- c:\windows\system32\perfh010.dat
2009-10-29 16:09 . 2009-10-23 21:45 -------- d-----w- c:\programmi\Easy Graphic Converter
2009-10-29 16:09 . 2009-10-25 18:55 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Thunderbird(2)
2009-10-29 16:09 . 2009-10-25 17:57 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Real(2)
2009-10-29 16:09 . 2008-12-07 22:58 -------- d-----w- c:\programmi\Google
2009-10-29 16:08 . 2009-10-29 16:08 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-10-29 16:08 . 2008-11-25 23:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-10-29 16:08 . 2009-10-29 16:08 -------- d-----w- c:\programmi\Garmin
2009-10-29 16:08 . 2009-10-29 16:08 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\GARMIN
2009-10-29 16:08 . 2009-10-29 16:08 -------- d-----w- c:\programmi\Garmin GPS Plugin
2009-10-29 05:59 . 2008-11-24 18:27 18273 ----a-w- c:\windows\E220AutoRunLog.tmp
2009-10-28 21:37 . 2009-10-28 21:37 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\vlc(2)
2009-10-28 21:20 . 2009-01-19 00:51 -------- d-----w- c:\programmi\Windows Media Connect 2
2009-10-28 20:31 . 2009-10-28 20:31 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Uniblue(2)
2009-10-27 10:05 . 2009-10-27 10:05 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\OpenOffice(2).org
2009-10-25 18:55 . 2009-10-25 18:55 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Talkback(2)
2009-10-21 20:50 . 2009-10-01 16:43 -------- d-----w- c:\programmi\Vuze
2009-10-12 22:30 . 2008-11-09 22:24 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\ZoomBrowser EX
2009-10-12 21:50 . 2008-11-09 22:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ZoomBrowser
2009-10-10 22:09 . 2009-10-10 22:09 -------- d-----w- c:\programmi\MSBuild
2009-10-10 22:09 . 2009-10-10 22:09 -------- d-----w- c:\programmi\Reference Assemblies
2009-10-10 16:24 . 2009-10-10 16:24 -------- d-----w- c:\programmi\File comuni\ParetoLogic
2009-10-10 16:24 . 2009-10-10 16:24 -------- d-----w- c:\programmi\ParetoLogic
2009-10-10 14:14 . 2009-10-10 14:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Drivers HeadQuarters
2009-10-07 21:49 . 2009-09-04 10:11 -------- d-----w- c:\programmi\iTunes
2009-10-07 21:49 . 2009-09-04 10:09 -------- d-----w- c:\programmi\File comuni\Apple
2009-10-07 21:41 . 2008-10-22 14:23 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-10-07 21:41 . 2009-10-07 21:41 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\InstallShield
2009-10-05 06:29 . 2009-10-05 06:29 -------- d-----w- c:\programmi\Packard Bell
2009-10-02 23:47 . 2009-10-02 23:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2009-10-02 22:34 . 2009-09-30 21:21 -------- d-----w- c:\programmi\Registry Winner
2009-10-01 18:34 . 2009-10-01 18:34 -------- d-----w- c:\programmi\Uniblue
2009-10-01 18:11 . 2009-10-01 18:11 -------- d-----w- c:\programmi\SmartPCTools
2009-10-01 16:44 . 2009-10-01 16:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Azureus
2009-09-30 19:28 . 2009-09-30 19:28 -------- d-----w- c:\documents and settings\Utente\Dati applicazioni\Uniblue
2009-09-29 16:25 . 2009-09-29 16:25 435720 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Real\Update\setup3.08\setup.exe
2009-09-11 14:17 . 2008-04-13 17:13 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 13:54 . 2009-02-09 23:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 13:53 . 2009-02-09 23:19 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2008-04-13 17:13 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-31 08:18 . 2009-10-20 16:19 52224 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\1ir2zbah.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\FFExternalAlert.dll
2009-08-31 08:18 . 2009-10-20 16:19 114688 ----a-w- c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\1ir2zbah.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\npmozax.dll
2009-08-29 07:26 . 2008-10-09 14:28 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:26 . 2008-10-09 14:27 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:26 . 2008-10-09 14:27 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2008-04-13 17:13 247326 ----a-w- c:\windows\system32\strmdll.dll
.
------- Sigcheck -------
[-] 2008-10-09 . 3316C8A8EC07A9D4C0BE10310809A9E5 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmi\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Lingoes"="c:\programmi\Lingoes\Translator2\Lingoes.exe" [2009-07-01 2187264]
"Registry Repair Wizard Scheduler"="c:\programmi\SmartPCTools\Registry Repair Wizard\RCHelper.exe" [2009-07-25 1540352]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456]
"WMPNSCFG"="c:\programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"EPSON Stylus C46 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE" [2004-01-13 99840]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2008-12-25 185872]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-05-26 413696]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes Anti-Malware (reboot)"="c:\programmi\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BlueSoleil.lnk - c:\programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe [2005-11-3 656384]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Utente^Menu Avvio^Programmi^Esecuzione automatica^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Utente\Menu Avvio\Programmi\Esecuzione automatica\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programmi\\mIRC\\mirc.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17/11/2009 4.57.08 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 12.17.32 1169232]
S2 gupdate1c9c9edbcb77d86;Google Update Service (gupdate1c9c9edbcb77d86);c:\programmi\Google\Update\GoogleUpdate.exe [01/05/2009 0.45.25 133104]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contenuto della cartella 'Scheduled Tasks'
2009-11-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programmi\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:06]
2009-11-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-11-09 c:\windows\Tasks\DriverCure.job
- c:\programmi\ParetoLogic\DriverCure\DriverCure.exe [2009-08-07 19:36]
2009-11-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-04-30 23:45]
2009-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-04-30 23:45]
2009-11-09 c:\windows\Tasks\ParetoLogic Registration.job
- c:\programmi\File comuni\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]
2009-11-09 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\programmi\File comuni\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
2009-11-17 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\programmi\Ask.com\UpdateTask.exe [2009-06-16 16:22]
2009-11-12 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-09-04 20:18]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: Open With JPEGCompress - c:\programmi\JPEGCompress\owjc.dll/CONTEXT_HANDLE.HTM
FF - ProfilePath - c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\1ir2zbah.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=DVSV5&o=15012&locale=it_IT&q=
FF - component: c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\1ir2zbah.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\1ir2zbah.default\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}\components\FFExternalAlert.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\programmi\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\programmi\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{DD02A4EB-4AFD-4D60-99D8-E67F964CA813} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-WgaLogon - (no file)
AddRemove-eBay Icon - c:\documents and settings\Utente\Dati applicazioni\Desktopicon\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-19 23:17
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-220523388-299502267-1177238915-1003\Software\MZ*#*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-220523388-299502267-1177238915-1003\Software\MZ*#*\ITA_Settings\BCGCommandManager]
"CommandsWithoutImages"=hex:00,00
"MenuUserImages"=hex:00,00
[HKEY_USERS\S-1-5-21-220523388-299502267-1177238915-1003\Software\MZ*#*\ITA_Settings\BCGControlBarVersion]
"Major"=dword:00000008
"Minor"=dword:0000003c
[HKEY_USERS\S-1-5-21-220523388-299502267-1177238915-1003\Software\MZ*#*\ITA_Settings\BCGToolbarParameters]
"Tooltips"=dword:00000001
"ShortcutKeys"=dword:00000001
"LargeIcons"=dword:00000001
"MenuAnimation"=dword:00000000
"RecentlyUsedMenus"=dword:00000001
"MenuShadows"=dword:00000001
"ShowAllMenusAfterDelay"=dword:00000001
"Look2000"=dword:00000001
"CommandsUsage"=hex:47,00,00,00,00,00
.
Ora fine scansione: 2009-11-19 23:20
ComboFix-quarantined-files.txt 2009-11-19 22:20
Pre-Run: 49.022.631.936 byte disponibili
Post-Run: 49.455.378.432 byte disponibili
- - End Of File - - 7263EABE1EAC2AA484160278710E6C98