forse è questo ?????
ComboFix 10-02-01.02 - Dardani Mauro 01/02/2010 21.15.05.9.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.2038.1622 [GMT 1:00]
Eseguito da: C:\Documents and Settings\Dardani Mauro\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-01-01 al 2010-02-01 )))))))))))))))))))))))))))))))))))
.
2010-01-24 08:30:31 . 2010-01-24 08:30:31 -------- d-----w- C:\Programmi\MarkAnyContentSAFER
2010-01-22 16:23:04 . 2010-01-24 08:26:20 89280248 ----a-w- C:\Documents and Settings\Dardani Mauro\Dati applicazioni\Samsung\New PC Studio\LiveUpdate\Setup_For_Full_Update_IH2_7.exe
2010-01-13 14:21:54 . 2010-01-16 15:05:24 -------- d-----w- C:\Media
2010-01-13 14:20:54 . 2010-01-13 14:21:28 -------- d-----w- C:\Programmi\TVLC
2010-01-10 13:34:05 . 2010-02-01 20:14:40 -------- d-----w- C:\WINDOWS\system32\CatRoot2
2010-01-09 14:09:33 . 2010-01-31 11:53:56 -------- d-----w- C:\Documents and Settings\Dardani Mauro\Dati applicazioni\vlc
2010-01-07 19:27:01 . 2010-01-07 19:27:01 86088 ----a-w- C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-01-07 18:40:00 . 2010-01-07 18:40:00 -------- d-----w- C:\Documents and Settings\Dardani Mauro\Impostazioni locali\Dati applicazioni\IsolatedStorage
2010-01-05 19:21:12 . 2010-01-05 19:21:12 -------- d-----w- C:\Documents and Settings\Dardani Mauro\Dati applicazioni\VSRevoGroup
2010-01-04 19:24:08 . 2010-01-04 19:24:08 -------- d-----w- C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 20:05:59 . 2009-02-16 16:27:17 -------- d-----w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2010-02-01 16:39:24 . 2009-03-17 13:17:01 -------- d-----w- C:\Documents and Settings\All Users\Dati applicazioni\Google Updater
2010-01-24 08:32:34 . 2005-09-21 14:39:26 -------- d--h--w- C:\Programmi\InstallShield Installation Information
2010-01-24 08:28:00 . 2007-10-25 15:26:10 5632 ----a-w- C:\WINDOWS\system32\drivers\StarOpen.sys
2010-01-22 13:10:19 . 2009-11-27 13:53:09 -------- d-----w- C:\Programmi\Microsoft Silverlight
2010-01-16 11:14:44 . 2009-06-04 19:25:57 -------- d-----w- C:\Programmi\IObit
2010-01-10 13:33:24 . 2010-01-10 13:33:01 76875 ----a-w- C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
2010-01-09 14:14:21 . 2008-11-12 21:22:26 -------- d-----w- C:\Programmi\Malwarebytes' Anti-Malware
2010-01-09 14:14:00 . 2010-01-02 15:42:02 5115824 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-07 15:07:14 . 2009-12-06 22:37:07 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07:04 . 2009-12-06 22:36:56 19160 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2010-01-06 10:49:27 . 2009-08-09 09:20:42 -------- d-----w- C:\Programmi\Foxit Software
2010-01-04 19:24:44 . 2007-04-23 10:37:31 -------- d-----w- C:\Programmi\QuickTime
2010-01-03 19:40:23 . 2005-09-21 09:01:18 524614 ----a-w- C:\WINDOWS\system32\perfh010.dat
2010-01-03 19:40:23 . 2005-09-21 09:01:18 100576 ----a-w- C:\WINDOWS\system32\perfc010.dat
2010-01-02 14:36:29 . 2009-12-31 15:35:29 -------- d-----w- C:\Programmi\Paint.NET
2009-12-22 18:45:29 . 2009-09-28 18:53:25 -------- d-----w- C:\Documents and Settings\Dardani Mauro\Dati applicazioni\SUPERAntiSpyware.com
2009-12-22 18:45:19 . 2008-04-21 17:09:50 -------- d-----w- C:\Programmi\File comuni\Wise Installation Wizard
2009-12-22 17:41:11 . 2008-01-10 20:03:33 -------- d-----w- C:\Programmi\Google
2009-12-21 19:06:28 . 2005-09-21 09:01:12 916480 ----a-w- C:\WINDOWS\system32\wininet.dll
2009-12-21 15:06:20 . 2009-12-21 15:06:20 -------- d-----w- C:\Programmi\Secunia
2009-12-18 17:45:58 . 2009-12-18 17:45:58 -------- d-----w- C:\Documents and Settings\Dardani Mauro\Dati applicazioni\Blitware
2009-12-18 17:45:55 . 2009-12-18 17:45:55 -------- d-----w- C:\Programmi\Driver Robot
2009-12-16 17:02:06 . 2009-11-13 15:51:30 -------- d-----w- C:\Programmi\Kaspersky Lab
2009-12-14 15:35:55 . 2009-12-14 15:35:21 1840 ----a-w- C:\WINDOWS\pchealth\helpctr\PackageStore(2)\SkuStore.bin
2009-12-14 15:35:50 . 2009-12-14 15:35:32 76875 ----a-w- C:\WINDOWS\pchealth\helpctr\OfflineCache(2)\index.dat
2009-12-13 16:48:36 . 2009-12-13 16:48:11 -------- d-----w- C:\Programmi\Online TV Player 4
2009-12-13 15:42:58 . 2009-12-13 15:42:58 -------- d-----w- C:\Documents and Settings\All Users\Dati applicazioni\TVU Networks
2009-12-13 15:42:58 . 2009-12-13 15:39:44 -------- d-----w- C:\Programmi\TVUPlayer
2009-12-13 15:38:19 . 2008-03-16 10:07:01 -------- d-----w- C:\Programmi\VideoLAN
2009-12-03 16:59:51 . 2009-12-03 16:59:51 80400 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2009-12-03 16:59:47 . 2009-12-03 16:59:47 80400 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2009-12-01 21:03:36 . 2009-12-01 19:52:36 78848 ----a-w- C:\Documents and Settings\Dardani Mauro\Dati applicazioni\Samsung\New PC Studio\LiveUpdate\Setup_For_Full_Update_IH2_6_4.exe
2009-11-21 15:54:26 . 2005-09-21 09:00:43 471552 ----a-w- C:\WINDOWS\AppPatch\aclayers.dll
2009-11-21 15:49:28 . 2009-11-21 15:49:28 117760 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\Sandbox\KLSB1\Device\HarddiskVolume1\Documents and Settings\Dardani Mauro\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-17 17:54:11 . 2009-11-17 17:54:11 397328 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\oeas.dll
2009-11-17 17:54:11 . 2009-11-17 17:54:11 17936 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\kloehk.dll
2009-11-17 17:54:11 . 2009-11-17 17:54:11 109072 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mzvkbd3.dll
2009-11-17 17:54:10 . 2009-11-17 17:54:10 315408 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\sys\i386\5.1\klif.sys
2009-11-15 09:48:43 . 2009-11-15 09:48:43 152576 ----a-w- C:\Documents and Settings\Dardani Mauro\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-15 09:48:31 . 2009-11-15 09:48:31 79488 ----a-w- C:\Documents and Settings\Dardani Mauro\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-13 16:03:26 . 2009-11-13 16:03:26 932368 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2009-11-13 16:03:26 . 2009-11-13 16:03:26 678416 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2009-11-13 16:03:26 . 2009-11-13 16:03:26 604688 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2009-11-13 16:03:26 . 2009-11-13 16:03:26 1096208 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2009-11-13 16:03:26 . 2009-11-13 16:03:25 522768 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2009-11-13 15:52:35 . 2009-11-13 15:52:35 95259 ----a-w- C:\WINDOWS\system32\drivers\klick.dat
2009-11-13 15:52:35 . 2009-11-13 15:52:35 108059 ----a-w- C:\WINDOWS\system32\drivers\klin.dat
2009-11-11 09:44:44 . 2009-11-21 15:49:30 158960 ----a-w- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab\Sandbox\KLSB1\Device\HarddiskVolume1\Documents and Settings\Dardani Mauro\Impostazioni locali\Temp\SSUPDATE.EXE
2009-09-20 10:51:52 . 2009-02-16 16:27:18 2512416 --sha-w- C:\WINDOWS\system32\drivers\fidbox.dat
2009-09-20 10:51:52 . 2009-02-16 16:27:18 589856 --sha-w- C:\WINDOWS\system32\drivers\fidbox2.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-11 21:44:21 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-20 19:39:28 340456]
"SunJavaUpdateSched"="C:\Programmi\Java\jre6\bin\jusched.exe" [2009-10-11 03:17:36 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 02:14:03 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytoosl"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 12:11:14 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-12-22 08:10:04 88358 ----a-w- C:\WINDOWS\agrsmmsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
2010-01-24 08:28:11 102400 ----a-w- C:\Programmi\Samsung\Samsung New PC Studio\NPSAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 02:14:03 15360 ------w- C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
2009-11-01 09:22:46 122880 ----a-w- C:\Programmi\Google\Quick Search Box\GoogleQuickSearchBox.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-07-19 18:06:12 77824 ----a-w- C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-07-19 18:10:06 114688 ----a-w- C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08:18 417792 ----a-w- C:\Programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2005-05-12 11:33:00 118784 ----a-w- C:\Programmi\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-11 21:44:21 39408 ----a-w- C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\Toshiba\\ConfigFree\\CFXFER.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
"C:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"C:\\Programmi\\SopCast\\SopCast.exe"=
"C:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\Italian\\setup.exe"=
"C:\\Programmi\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"C:\\Programmi\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"C:\\Programmi\\TVUPlayer\\TVUPlayer.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [14/10/2009 21.18.34 36880]
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\drivers\Msikbd2k.sys [28/06/2006 14.57.38 6656]
R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [30/06/2009 20.58.24 233472]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [30/06/2009 20.58.24 36608]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\drivers\klim5.sys [14/09/2009 14.42.46 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\WINDOWS\system32\drivers\klmouflt.sys [02/10/2009 19.39.44 19472]
S2 gupdate1c9a702bf95dc54;Servizio di Google Update (gupdate1c9a702bf95dc54);C:\Programmi\Google\Update\GoogleUpdate.exe [17/03/2009 14.17.39 133104]
S2 nhksrv;Netropa NHK Server;C:\Programmi\Netropa\Multimedia Keyboard\nhksrv.exe [28/06/2006 14.57.38 28672]
S3 PSI;PSI;C:\WINDOWS\system32\drivers\psi_mf.sys [17/06/2009 13.20.34 12648]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);C:\WINDOWS\system32\drivers\ss_bbus.sys [30/06/2009 20.59.18 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);C:\WINDOWS\system32\drivers\ss_bmdfl.sys [30/06/2009 20.59.18 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;C:\WINDOWS\system32\drivers\ss_bmdm.sys [30/06/2009 20.59.19 121856]
.
Contenuto della cartella 'Scheduled Tasks'
2009-12-31 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34:12 . 2008-07-30 10:34:12]
2010-02-01 C:\WINDOWS\Tasks\Google Software Updater.job
- C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-17 16:28:14 . 2009-03-27 17:09:39]
2010-02-01 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Programmi\Google\Update\GoogleUpdate.exe [2009-03-17 13:17:39 . 2009-03-17 13:17:33]
2010-02-01 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Programmi\Google\Update\GoogleUpdate.exe [2009-03-17 13:17:39 . 2009-03-17 13:17:33]
2010-01-14 C:\WINDOWS\Tasks\NeroLiveEpgUpdate-YOUR-6BFCBDC390_Dardani-Mauro.job
- C:\Programmi\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 12:51:06 . 2008-09-18 12:51:06]
2010-01-31 C:\WINDOWS\Tasks\SmartDefrag.job
- C:\Programmi\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-01-16 11:14:45 . 2010-01-06 14:30:46]
2010-02-01 C:\WINDOWS\Tasks\User_Feed_Synchronization-{AD3C2CFE-914B-47FE-AB80-EB24155C68E8}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 10:58:32 . 2009-03-08 03:31:54]
2010-02-01 C:\WINDOWS\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job
- C:\Programmi\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20:38 . 2007-10-19 10:20:38]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mStart Page = about:blank
uSearchURL,(Default) = hxxp://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
IE: &MSN Search - C:\Programmi\MSN Toolbar Suite\TB\02.05.0000.1082\it-it\msntb.dll/search.htm
IE: &Windows Live Search - C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: Aggiungi ad Anti-Banner - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
IE: E&sporta in Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
HKLM-Run-NPSStartup - (no file)