ComboFix 09-12-11.01 - Giuseppe 11/12/2009 20.59.18.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3071.2397 [GMT 1:00]
Eseguito da: c:\documents and settings\Giuseppe\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Menu Avvio\Windows Live Messenger .lnk
c:\documents and settings\Giuseppe\Dati applicazioni\Desktopicon
c:\documents and settings\Giuseppe\Dati applicazioni\Desktopicon\config.ini
c:\documents and settings\Giuseppe\Dati applicazioni\Desktopicon\eBay.ico
c:\documents and settings\Giuseppe\Dati applicazioni\Desktopicon\uninst.exe
c:\windows\patchw32.dll
c:\windows\pw32a.dll
c:\windows\regedit.com
c:\windows\system32\taskmgr.com
c:\windows\system32\twain_32.dll
.
((((((((((((((((((((((((( Files Creati Da 2009-11-11 al 2009-12-11 )))))))))))))))))))))))))))))))))))
.
2009-12-11 17:59 . 2009-12-11 17:59 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-11 15:46 . 2009-12-11 15:46 -------- d-----w- c:\programmi\Trend Micro
2009-12-10 14:12 . 2009-12-10 13:32 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-12-10 13:32 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-12-10 13:29 . 2009-12-11 18:09 -------- dc-h--w- c:\documents and settings\All Users\Dati applicazioni\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-12-10 10:28 . 2009-12-10 13:29 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft
2009-12-09 20:20 . 2009-11-21 15:54 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2009-12-09 11:17 . 2009-12-09 11:17 -------- d-----w- c:\programmi\Moo0
2009-12-08 12:57 . 2009-12-08 12:57 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ATI
2009-12-08 12:47 . 2009-09-29 20:15 593920 ------w- c:\windows\system32\ati2sgag.exe
2009-11-25 01:58 . 2009-07-31 04:32 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2009-11-22 03:27 . 2009-11-22 03:29 -------- d-----w- c:\programmi\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-11 20:17 . 2008-10-04 14:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-12-11 16:18 . 2006-03-16 07:44 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\Skype
2009-12-11 09:25 . 2009-11-04 02:21 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\vlc
2009-12-11 07:34 . 2007-11-11 06:35 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\foobar2000
2009-12-11 02:44 . 2007-11-01 12:30 -------- d-----w- c:\programmi\TavoliVerdi
2009-12-10 14:41 . 2007-11-16 02:54 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\skypePM
2009-12-10 13:32 . 2009-12-10 13:32 862040 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-10 13:32 . 2009-12-10 13:32 206944 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-10 13:32 . 2009-12-10 13:32 15880 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-12-10 13:32 . 2009-12-10 13:32 537576 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-10 13:32 . 2009-12-10 13:32 390288 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-10 13:32 . 2009-12-10 13:32 370744 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-10 13:32 . 2009-12-10 13:32 194104 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-10 13:32 . 2009-12-10 13:32 163728 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-12-10 13:32 . 2009-12-10 13:32 5908024 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-10 13:32 . 2009-12-10 13:32 327000 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-12-10 13:31 . 2009-12-10 13:31 87496 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-12-10 13:31 . 2009-12-10 13:31 933120 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-10 13:31 . 2009-12-10 13:31 641632 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-12-10 13:31 . 2009-12-10 13:31 816272 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-10 13:31 . 2009-12-10 13:31 822904 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-10 13:31 . 2009-12-10 13:31 1638640 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-10 13:31 . 2009-12-10 13:31 788880 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-10 13:31 . 2009-12-10 13:31 1184912 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-10 11:11 . 2001-08-31 11:00 537958 ----a-w- c:\windows\system32\perfh010.dat
2009-12-10 11:11 . 2001-08-31 11:00 105138 ----a-w- c:\windows\system32\perfc010.dat
2009-12-08 12:53 . 2005-09-15 12:23 -------- d-----w- c:\programmi\ATI Technologies
2009-12-06 14:09 . 2007-04-06 07:17 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\dvdcss
2009-12-05 07:20 . 2009-03-06 20:06 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-12-05 07:19 . 2009-03-30 18:12 4844296 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-03 15:14 . 2009-03-06 20:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 15:13 . 2009-03-06 20:06 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-03 13:03 . 2009-12-03 13:03 80400 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2009-12-03 13:03 . 2009-12-03 13:03 80400 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2009-11-30 08:46 . 2008-12-18 00:40 -------- d-----w- c:\programmi\USB Safely Remove
2009-11-27 16:53 . 2006-02-23 06:19 -------- d-----w- c:\programmi\Winamp
2009-11-27 11:53 . 2008-05-13 19:14 -------- d-----w- c:\programmi\Microsoft Baseline Security Analyzer 2
2009-11-22 07:49 . 2008-11-17 07:41 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-11-22 01:53 . 2008-05-14 02:59 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-11-21 15:54 . 2004-08-19 14:39 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-18 06:29 . 2008-05-29 10:36 -------- d-----w- c:\programmi\AVI ReComp
2009-11-18 05:19 . 2006-07-31 08:22 -------- d-----w- c:\programmi\a-squared Free
2009-11-17 02:08 . 2005-09-15 12:13 -------- d-----w- c:\programmi\File comuni\Adobe
2009-11-16 17:25 . 2009-11-16 17:25 109072 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mzvkbd3.dll
2009-11-16 17:23 . 2009-11-16 17:23 315408 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\sys\i386\5.1\klif.sys
2009-11-04 11:24 . 2006-03-17 02:09 -------- d-----w- c:\programmi\Unlocker
2009-11-04 00:51 . 2009-10-13 16:29 -------- d-----w- c:\programmi\Java
2009-11-04 00:49 . 2009-11-04 00:49 152576 ----a-w- c:\documents and settings\Giuseppe\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-01 11:22 . 2008-03-04 03:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2009-10-29 07:40 . 2004-08-19 14:39 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-26 10:04 . 2009-04-01 02:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Symantec
2009-10-23 14:17 . 2009-10-23 14:17 64072 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2010 9.0.0.736\Italian\setup.exe
2009-10-21 05:38 . 2004-08-19 14:39 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-19 14:39 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 19:34 . 2009-10-20 19:34 219664 ----a-w- c:\windows\system32\klogon.dll
2009-10-20 16:20 . 2004-08-03 22:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-16 00:36 . 2007-12-08 00:40 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Innovative Solutions
2009-10-15 06:17 . 2009-10-15 06:17 -------- d-----w- c:\programmi\Microsoft Office Outlook Connector
2009-10-15 06:16 . 2007-11-08 02:05 -------- d-----w- c:\programmi\Windows Live
2009-10-14 20:18 . 2008-01-29 16:29 36880 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-10-14 13:43 . 2008-10-04 14:33 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-14 13:43 . 2008-10-04 14:33 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-13 18:51 . 2009-10-13 18:41 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-10-13 18:48 . 2009-10-13 18:48 109072 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd3.dll
2009-10-13 18:48 . 2009-10-13 18:48 59920 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd.dll
2009-10-13 18:48 . 2009-10-13 18:48 264720 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\klwtbbho.dll
2009-10-13 18:36 . 2008-10-04 14:32 7504928 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-13 18:36 . 2008-10-04 14:32 7320 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-13 18:36 . 2008-10-04 14:32 61808 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-13 18:36 . 2008-10-04 14:32 1212448 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-13 18:31 . 2008-02-15 19:33 -------- d-----w- c:\programmi\Kaspersky Lab
2009-10-13 16:36 . 2009-10-13 16:36 -------- d-----w- c:\programmi\File comuni\Skype
2009-10-13 16:36 . 2006-03-16 07:44 -------- d-----r- c:\programmi\Skype
2009-10-13 16:35 . 2006-03-16 07:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2009-10-13 16:29 . 2009-10-13 16:29 0 ----a-w- c:\windows\system32\REN3A.tmp
2009-10-13 16:29 . 2009-10-13 16:29 0 ----a-w- c:\windows\system32\REN39.tmp
2009-10-13 16:29 . 2009-10-13 16:29 0 ----a-w- c:\windows\system32\REN38.tmp
2009-10-13 16:04 . 2008-12-10 20:25 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NOS
2009-10-13 15:46 . 2009-10-13 15:46 1925024 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NOS\Adobe_Downloads\install_flash_player.exe
2009-10-13 15:27 . 2008-12-18 00:40 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\USBSafelyRemove
2009-10-13 15:10 . 2009-01-17 03:54 -------- d-----w- c:\programmi\Windows Desktop Search
2009-10-13 10:33 . 2004-08-19 14:39 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-19 14:39 150016 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-19 14:39 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 03:17 . 2008-11-02 06:13 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-03 08:15 . 2009-12-10 13:29 2924848 -c--a-w- c:\documents and settings\All Users\Dati applicazioni\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-10-02 18:39 . 2009-05-16 18:59 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2009-09-30 04:18 . 2005-08-04 03:10 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2009-09-30 02:20 . 2009-09-30 02:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-09-30 02:19 . 2005-08-04 03:10 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2009-09-30 02:10 . 2009-09-30 02:10 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2009-09-30 02:10 . 2009-09-30 02:10 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2009-09-30 02:10 . 2009-09-30 02:10 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2009-09-30 02:10 . 2009-09-30 02:10 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-09-30 02:10 . 2009-09-30 02:10 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2009-09-30 02:08 . 2009-09-30 02:08 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2009-09-30 02:08 . 2009-09-30 02:08 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2009-09-30 02:07 . 2009-09-30 02:07 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2009-09-30 02:07 . 2009-09-30 02:07 11845632 ----a-w- c:\windows\system32\atioglxx.dll
2009-09-30 02:00 . 2005-08-04 02:54 3818272 ----a-w- c:\windows\system32\ati3duag.dll
2006-10-28 06:20 . 2006-10-28 05:57 56 --sh--r- c:\windows\system32\31FA32EECD.sys
2005-10-11 03:47 . 2005-10-11 03:47 56 --sh--r- c:\windows\system32\540F5200CC.sys
2008-10-24 02:27 . 2008-10-24 02:27 23 --sha-w- c:\windows\system32\bacdccb7_d.dll
2008-02-12 20:10 . 2008-02-12 20:10 23 --sha-w- c:\windows\system32\fdcddf_g.dll
2006-10-28 18:03 . 2006-10-28 05:58 5018 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-28 68856]
"USB Safely Remove"="c:\programmi\USB Safely Remove\USBSafelyRemove.exe" [2009-11-27 1269528]
"Advanced Uninstaller PRO Installation Monitor"="c:\programmi\Innovative Solutions\Advanced Uninstaller PRO - Version 9\monitor.exe" [2008-10-31 1153936]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"<NO NAME>"="c:\progra~1\Mozilla Firefox\firefox.exe" [2009-11-06 908248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"zBrowser Launcher"="c:\programmi\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 20992]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2002-08-29 155648]
"RemoteControl"="c:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"CloneCDTray"="c:\programmi\SlySoft\CloneCD\CloneCDTray.exe" [2002-08-29 57344]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-01-19 221184]
"LogitechVideoRepair"="c:\programmi\Logitech\Video\ISStart.exe" [2005-01-19 458752]
"LogitechVideoTray"="c:\programmi\Logitech\Video\LogiTray.exe" [2005-01-19 217088]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-18 14820864]
"MemoREX"="c:\programmi\MemoRex\MemoRexStart.exe" [2002-08-29 332288]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Adobe Acrobat Speed Launcher"="c:\programmi\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-10-03 38768]
"Acrobat Assistant 8.0"="c:\programmi\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-10-02 640376]
"avp"="c:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-10-20 340456]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\f:\0autocheck autochk *\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Giuseppe^Menu Avvio^Programmi^Esecuzione automatica^desktop.ini]
path=c:\documents and settings\Giuseppe\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini
backup=c:\windows\pss\desktop.iniStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\APC\\PowerChute Business Edition\\agent\\pbeagent.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\Italian\\setup.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Italian\\setup.exe"=
"c:\\Programmi\\eMule0.49c\\emule.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 17.29.38 36880]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10/12/2009 14.32.56 64288]
R0 tdrpman147;Acronis Try&Decide and Restore Points filter (build 147);c:\windows\system32\drivers\tdrpm147.sys [06/12/2008 17.08.24 971584]
R2 a2free;a-squared Free Service;c:\programmi\a-squared Free\a2service.exe [12/06/2007 15.45.20 1858144]
R2 APCPBEAgent;APC PBE Agent;c:\progra~1\APC\POWERC~1\agent\pbeagent.exe [11/12/2008 12.51.59 34048]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\programmi\USB Safely Remove\USBSRService.exe [18/12/2008 1.40.10 261456]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14.42.46 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/05/2009 19.59.44 19472]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [24/03/2009 12.03.08 7808]
S4 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;"c:\programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe" --> c:\programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe [?]
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: Aggiungi a PDF esistente - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Aggiungi destinazione link a PDF esistente - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converti destinazione link in Adobe PDF - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converti in Adobe PDF - c:\programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Crawler Search
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Translate this web page with Babylon
IE: Translate with Babylon
TCP: {F8064CBE-3CAA-4D22-8722-8DC42D0785CF} = 85.37.17.39,85.38.28.71
DPF: {60E33102-59F1-44DA-BA3D-494BB9A80514} - hxxp://www.inps.it/Servizi/ParlaConNoi/VoipFiles/IPhona.cab
DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} - hxxp://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {EFD3EA56-234D-4240-90EA-CC9FA3AF5A01} - hxxp://aiuto.alice.it/ata/static/installers/WebflowActiveXInstaller_4-1-4.cab
FF - ProfilePath - c:\documents and settings\Giuseppe\Dati applicazioni\Mozilla\Firefox\Profiles\5g8uwzs9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.startup.homepage - hxxp://it.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:it:official
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\programmi\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npagent.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
ShellIconOverlayIdentifiers-{5A7647C4-5FB7-4DD6-BC8D-8B647CB7FBB7} - (no file)
HKCU-Run-updateMgr - c:\programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-DriverMax_RESTART - (no file)
HKLM-Run-Anti-Trojan-Watch - (no file)
AddRemove-eBay Icon - c:\documents and settings\Giuseppe\Dati applicazioni\Desktopicon\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-11 21:20
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1547161642-1390067357-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{AD5A1DE6-3F85-08CE-B7C9-C8C8EB0B0C8B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"naibieeggcmdikdkkmdiepiogncp"=hex:6a,61,65,68,6d,64,6e,6b,65,6c,63,6c,6c,65,
61,6e,68,6e,6f,63,00,fa
"macpgcahekfbimeaflaeighjnd"=hex:69,61,64,68,6d,6d,64,66,6b,6f,69,64,61,69,6a,
70,6c,68,00,00
"naebaoobaiobgcoldkjhiobhciff"=hex:62,61,6f,67,00,8f
"abebaphjkjgbnfkcnhpnnmolpjpdmdapai"=hex:61,61,00,00
"mafbmfkamolfmceimbichofgad"=hex:61,61,00,00
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="33B2004865E08CA8D0144217DFCB979398FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E6678EDD5E5BE2F6E667A2D97226D213B555BA7FD869164D67941254F44A2643D69DBD4BAA3ED5250B64FACBE16B738B1BE3E72AF98D3CD88D8F31EA5C0E0286ABD90E3A866E4EB0F06F137D5AD1E0A6C683D3F0C30E731592ABD058ADC8D63C0CC839B9C53155B575FEFAAE923EEECA0B43A342D583655AD77792DE420F8BD24F0F74CD7F6376B3BACF1A437EF470A77599148221BAC5A9F8BE27042757D93CB973863C7C4690AD54436EE3469E07F2089FF85A49681E8885F6D6921FFDCE6E0AE24E123D7CD52CCC5D897C4448AB64B814B63827A1CA810036FD191FC04DE56E6CB91CF38ECEB91F498FBC8865293972584A4DC6617DA05F380BE8D0440AA00DC44FEF856B5467BDD03C1956C920B19272BE8DE985BA780F5A809791908F21FA4325E28EDF16478E66D9C9262F83136B0CB8B204D0D99EEDA0F680F28E3BED47E3E7115DA396F2E79F4B4BA2B39C26C273ECB93FE988AD4E3219C13A11BF91EFC6D85A724C2C8499B3065D2C5705B6D19BA7E4F55A49C1F8D9A63DE149A01BE9B04BDF8658831CE301128354812E96C718C438B9116D7D2705711996CDBA9D9C07290B04A719DCF9888E8665795A98C62438FCCEE02186884863BFB91C39AE64D8EC8487FCC0EE07ED2B73D86DA317E39E08BFAE805F06405AF4DE61131F699153A7BD658321FEA6F9AD19DE70736DA9084ED28488F829659437E7D675416CE74C7C69A3C535BBEB9BEF0CDA740B7D9685B9CB317913A20378CC92976BCAD91FB9A57DFCB44B57D9E1DEA46455FDAB1CE28B024AB3262817A66C58D47FB85A64B9ED35DFA4870CE982FAFEC7D034DF208D9A14177F00721667E277F4A1DD96D58BB611ED4E5E1409D55AFB8387E8867C16516314853F40E6250EF111255E3D891273D37E4E9C2F995927BDCA7D2B1300B32E137356DBD1646F628DF641B40206D5AC839C246022EE2D1DAE069E61F56CC0438D18629B6EDC7766D5A6922E1BC7037FEC85341B32D3180D79D0B6402B78B936809A819C5F93153497D7166E433FE81A9DAC47962D82805E8E7BF7D42E4DC1C2DCC7ECCFF0BFC37E6573B068B7D0FB42E9398AEA62AF74882207F67FFE889DB557A04378750DA20516952BE73E525350E8040D8725FC261B2DAC2E74233C39F169598732431A722142912E8A9A122CB0759C44304D0667346AD7F93923EF9F6D4F5B9F67B3F81D3D48ECCAC199CFE5E2AEC588FA35D5B48ADAA81C2B8B1C04338BC156592432AA594CDE74D208BE837B777515D13E6EA76843F0B9F96D2FBDE0635D599DF6404C8833D701D7B887AD2276568BF4CB448329AA39DCA9DB0C44A85EB2BB1D9111"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2884)
c:\windows\system32\WININET.dll
c:\programmi\Logitech\MouseWare\System\LgWndHk.dll
c:\programmi\Logitech\iTouch\iTchHk.dll
c:\programmi\File comuni\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\webcheck.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Diskeeper Corporation\Diskeeper\DkService.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\File comuni\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
c:\programmi\Logitech\MouseWare\system\em_exec.exe
c:\windows\RTHDCPL.EXE
c:\programmi\Logitech\Video\FxSvr2.exe
c:\programmi\MemoRex\MemoRex.exe
c:\programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\SearchProtocolHost.exe
c:\programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Ora fine scansione: 2009-12-11 21:36:17 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-12-11 20:35
Pre-Run: 40.193.130.496 byte disponibili
Post-Run: 39.953.018.880 byte disponibili
- - End Of File - - 56477ABF001986CBA61899DA66E1D295