ComboFix 10-02-17.01 - Administrator 20/02/2010 12.50.38.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2047.1577 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Administrator\Desktop\CFScript.txt
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-01-20 al 2010-02-20 )))))))))))))))))))))))))))))))))))
.
2010-02-19 20:41 . 2010-02-19 20:42 -------- dc-h--w- c:\windows\ie8
2010-02-19 16:14 . 2010-02-19 16:14 -------- d-----w- c:\programmi\ESET
2010-02-18 18:24 . 2010-02-18 18:44 -------- d-----w- C:\AVGTemp
2010-02-18 13:42 . 2010-02-18 13:42 -------- d-----w- C:\ERDNT
2010-02-18 10:22 . 2007-02-13 15:17 69632 ----a-w- c:\windows\system32\MCCDevice.dll
2010-02-17 10:15 . 2010-02-17 10:16 -------- d-----w- c:\programmi\Motive
2010-02-16 09:15 . 2010-02-16 09:15 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Motive
2010-02-03 17:36 . 2010-02-17 10:17 -------- d-----w- c:\windows\Motive
2010-02-03 17:36 . 2010-02-17 10:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Motive
2010-02-03 17:36 . 2010-02-03 17:36 -------- d-----w- c:\programmi\File comuni\Motive
2010-02-03 17:36 . 2010-02-03 17:36 -------- d-----w- c:\programmi\Common Files
2010-02-03 17:35 . 2010-02-17 10:17 -------- d-----w- c:\programmi\Alice ti aiuta
2010-02-03 17:35 . 2002-10-17 19:44 46352 ----a-w- c:\windows\setdebug.exe
2010-02-03 17:35 . 2002-10-17 19:44 171280 ----a-w- c:\windows\system32\jit.dll
2010-02-03 17:35 . 2002-10-17 19:44 139536 ----a-w- c:\windows\system32\javaee.dll
2010-02-03 17:35 . 2002-10-17 18:08 6550 ----a-w- c:\windows\jautoexp.dat
2010-02-03 17:35 . 2002-10-17 18:07 313856 ----a-w- c:\windows\system32\dx3j.dll
2010-02-03 17:32 . 2010-02-03 17:47 -------- d-----w- c:\programmi\Telecom Italia
2010-02-02 20:10 . 2005-08-25 16:48 27136 ----a-w- c:\windows\system32\GsiDi32.dll
2010-02-01 18:37 . 2010-02-19 21:02 52224 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-29 22:10 . 2010-01-29 22:10 -------- d-----w- c:\programmi\File comuni\DirectX
2010-01-29 21:52 . 2010-01-29 22:09 -------- d-----w- c:\programmi\Microsoft Games for Windows - LIVE
2010-01-29 21:26 . 2010-01-30 14:42 -------- d-----w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Rockstar Games
2010-01-29 21:25 . 2010-01-31 09:17 -------- d-----w- c:\programmi\Rockstar Games
2010-01-27 19:31 . 2010-01-27 19:31 -------- d-----w- c:\programmi\EA GAMES
2010-01-26 21:45 . 2010-01-26 21:45 -------- d-----w- C:\found.000
2010-01-25 14:44 . 2010-01-25 14:44 -------- d-sh--w- c:\windows\ftpcache
2010-01-22 16:33 . 2010-02-18 11:58 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\KeePass
2010-01-22 16:30 . 2010-01-22 16:30 -------- d-----w- c:\programmi\KeePass Password Safe 2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-20 11:37 . 2009-10-18 12:52 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\uTorrent
2010-02-19 21:02 . 2009-07-24 16:06 117760 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-19 21:02 . 2009-07-24 15:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-02-19 20:18 . 2009-10-14 17:05 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Skype
2010-02-19 19:58 . 2009-08-18 17:25 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\vlc
2010-02-19 17:56 . 2009-07-24 13:47 -------- d-----w- c:\programmi\Mozilla Thunderbird
2010-02-19 15:52 . 2009-10-14 17:06 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\skypePM
2010-02-18 20:11 . 2009-11-04 15:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-02-18 14:19 . 2009-07-24 16:05 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-02-18 14:16 . 2009-07-24 16:07 5115824 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-02-18 13:06 . 2009-11-04 16:26 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Spider Player
2010-02-17 18:34 . 2009-10-18 12:54 -------- d-----w- c:\programmi\uTorrent
2010-02-16 09:11 . 2009-10-14 21:10 1006848 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-02-12 22:10 . 2009-07-24 09:43 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-02-12 17:34 . 2009-12-05 18:29 -------- d-----w- c:\programmi\Free Video Converter
2010-02-11 20:02 . 2009-07-24 16:04 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2010-02-10 13:57 . 2006-03-02 12:00 80382 ----a-w- c:\windows\system32\perfc010.dat
2010-02-10 13:57 . 2006-03-02 12:00 482022 ----a-w- c:\windows\system32\perfh010.dat
2010-02-08 14:52 . 2009-08-03 17:09 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\dvdcss
2010-02-06 20:30 . 2009-07-24 13:51 -------- d-----w- c:\programmi\Google
2010-02-03 17:47 . 2009-07-24 07:49 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-02-03 17:35 . 2010-02-03 17:35 2232 ----a-w- c:\windows\java\Packages\Data\175R5ZFJ.DAT
2010-02-03 17:35 . 2010-02-03 17:35 155995 ----a-w- c:\windows\java\Packages\XJT3L3XR.ZIP
2010-02-03 17:35 . 2010-02-03 17:35 2678 ----a-w- c:\windows\java\Packages\Data\P3D7FFJL.DAT
2010-02-03 17:35 . 2010-02-03 17:35 2678 ----a-w- c:\windows\java\Packages\Data\3F1VBXJ1.DAT
2010-02-03 17:34 . 2010-02-03 17:34 2678 ----a-w- c:\windows\java\Packages\Data\ES86D357.DAT
2010-02-03 17:34 . 2010-02-03 17:34 2678 ----a-w- c:\windows\java\Packages\Data\UE9BH3BB.DAT
2010-02-03 17:34 . 2010-02-03 17:34 2678 ----a-w- c:\windows\java\Packages\Data\5NZJTF97.DAT
2010-01-30 15:48 . 2009-10-15 14:12 -------- d-----w- c:\programmi\eMule
2010-01-27 17:06 . 2010-01-09 17:41 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Bioshock
2010-01-25 14:33 . 2009-07-24 13:45 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\ESTsoft
2010-01-22 15:53 . 2009-07-24 13:46 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Estsoft
2010-01-21 18:28 . 2009-11-28 19:39 -------- d-----w- c:\programmi\Microsoft Silverlight
2010-01-17 09:27 . 2009-07-25 17:45 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\U3
2010-01-15 15:04 . 2009-07-31 14:40 -------- d-----w- c:\programmi\File comuni\Adobe
2010-01-14 17:42 . 2010-01-14 17:42 -------- d-----w- c:\windows\system32\config\systemprofile\Dati applicazioni\Application Updater
2010-01-14 10:12 . 2009-10-04 13:05 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-09 17:16 . 2010-01-09 17:16 -------- d-----w- c:\programmi\7-Zip
2010-01-07 15:07 . 2009-07-24 16:05 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-07-24 16:05 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 13:21 . 2010-01-06 13:21 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\GARMIN
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-25 20:36 . 2009-12-25 20:36 -------- d-----w- c:\programmi\Mp3 Knife
2009-12-24 23:14 . 2009-12-08 13:53 -------- d-----w- c:\programmi\3 Internet
2009-12-18 16:37 . 2009-07-24 08:29 71216 ----a-w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-12-18 16:30 . 2009-12-18 16:30 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-12-18 16:30 . 2009-12-18 16:30 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-12-18 16:30 . 2009-12-18 16:30 129784 ------w- c:\windows\system32\pxafs.dll
2009-12-18 16:30 . 2009-12-18 16:30 116472 ------w- c:\windows\system32\pxcpyi64.exe
2009-12-18 16:30 . 2009-12-18 16:30 43528 ------w- c:\windows\system32\drivers\PxHelp20.sys
2009-12-18 16:30 . 2009-12-18 16:30 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-12-14 07:08 . 2006-03-02 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 18:22 . 2006-03-02 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:12 . 2006-03-02 12:00 1296896 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:12 . 2004-08-19 15:39 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2001-08-30 23:08 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2006-03-02 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2006-03-02 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2006-03-02 12:00 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-19 15:39 48128 ----a-w- c:\windows\system32\iyuv_32.dll
.
(((((((((((((((((((((((((((((
SnapShot@2010-02-18_20.26.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-20 11:48 . 2010-02-20 11:48 16384 c:\windows\Temp\Perflib_Perfdata_6d0.dat
- 2009-03-08 03:31 . 2009-12-21 19:06 55296 c:\windows\system32\msfeedsbs.dll
+ 2009-03-08 03:31 . 2009-03-08 03:31 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-03-02 12:00 . 2009-03-08 03:33 25600 c:\windows\system32\jsproxy.dll
- 2006-03-02 12:00 . 2009-12-21 19:06 25600 c:\windows\system32\jsproxy.dll
- 2009-03-08 03:33 . 2009-12-21 19:06 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-03-08 03:33 . 2009-03-08 03:33 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 37888 c:\windows\ie8\url.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 37888 c:\windows\ie8\url.dll
+ 2010-02-19 20:41 . 2009-03-08 19:34 58448 c:\windows\ie8\spuninst\iecustom.dll
- 2010-02-17 15:00 . 2009-03-08 19:34 58448 c:\windows\ie8\spuninst\iecustom.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 39424 c:\windows\ie8\pngfilt.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 39424 c:\windows\ie8\pngfilt.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 97280 c:\windows\ie8\occache.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 97280 c:\windows\ie8\occache.dll
+ 2010-02-19 20:41 . 2008-04-13 16:49 57344 c:\windows\ie8\mshtmler.dll
- 2010-02-17 14:59 . 2008-04-13 16:49 57344 c:\windows\ie8\mshtmler.dll
- 2010-02-17 14:59 . 2008-04-13 17:14 29184 c:\windows\ie8\mshta.exe
+ 2010-02-19 20:41 . 2008-04-13 17:14 29184 c:\windows\ie8\mshta.exe
+ 2010-02-19 20:41 . 2008-04-13 17:13 22016 c:\windows\ie8\licmgr10.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 22016 c:\windows\ie8\licmgr10.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 15872 c:\windows\ie8\jsproxy.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 15872 c:\windows\ie8\jsproxy.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 96768 c:\windows\ie8\inseng.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 96768 c:\windows\ie8\inseng.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 35840 c:\windows\ie8\imgutil.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 35840 c:\windows\ie8\imgutil.dll
- 2010-02-17 14:59 . 2008-04-13 17:14 93184 c:\windows\ie8\iexplore.exe
+ 2010-02-19 20:41 . 2008-04-13 17:14 93184 c:\windows\ie8\iexplore.exe
+ 2010-02-19 20:41 . 2008-04-13 17:13 63488 c:\windows\ie8\iesetup.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 63488 c:\windows\ie8\iesetup.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 49152 c:\windows\ie8\iernonce.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 49152 c:\windows\ie8\iernonce.dll
- 2010-02-17 14:59 . 2009-04-29 04:33 81920 c:\windows\ie8\ieencode.dll
+ 2010-02-19 20:41 . 2009-04-29 04:33 81920 c:\windows\ie8\ieencode.dll
+ 2010-02-19 20:41 . 2008-04-13 17:14 34304 c:\windows\ie8\ie4uinit.exe
- 2010-02-17 14:59 . 2008-04-13 17:14 34304 c:\windows\ie8\ie4uinit.exe
- 2010-02-17 14:59 . 2008-04-13 17:13 38912 c:\windows\ie8\hmmapi.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 38912 c:\windows\ie8\hmmapi.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 35328 c:\windows\ie8\corpol.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 35328 c:\windows\ie8\corpol.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 61440 c:\windows\ie8\admparse.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 61440 c:\windows\ie8\admparse.dll
+ 2006-03-02 12:00 . 2009-03-08 03:34 914944 c:\windows\system32\wininet.dll
+ 2006-03-02 12:00 . 2009-03-08 03:34 109568 c:\windows\system32\occache.dll
+ 2009-03-08 03:32 . 2009-03-08 03:32 594432 c:\windows\system32\msfeeds.dll
- 2009-03-08 03:32 . 2009-12-21 19:06 594432 c:\windows\system32\msfeeds.dll
- 2006-03-02 12:00 . 2009-06-22 06:45 726528 c:\windows\system32\jscript.dll
+ 2006-03-02 12:00 . 2009-03-08 03:33 726528 c:\windows\system32\jscript.dll
+ 2006-03-02 12:00 . 2009-03-08 03:31 183808 c:\windows\system32\iepeers.dll
+ 2006-03-02 12:00 . 2009-03-08 13:09 391536 c:\windows\system32\iedkcs32.dll
- 2006-03-02 12:00 . 2009-12-21 13:20 173056 c:\windows\system32\ie4uinit.exe
+ 2006-03-02 12:00 . 2009-03-08 03:32 173056 c:\windows\system32\ie4uinit.exe
+ 2009-03-08 03:34 . 2009-03-08 03:34 914944 c:\windows\system32\dllcache\wininet.dll
+ 2009-03-08 03:34 . 2009-03-08 03:34 109568 c:\windows\system32\dllcache\occache.dll
+ 2008-05-09 10:53 . 2009-03-08 03:33 726528 c:\windows\system32\dllcache\jscript.dll
- 2008-05-09 10:53 . 2009-06-22 06:45 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-03-08 03:31 . 2009-03-08 03:31 183808 c:\windows\system32\dllcache\iepeers.dll
+ 2009-03-08 13:09 . 2009-03-08 13:09 391536 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 03:32 . 2009-03-08 03:32 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2009-03-08 03:32 . 2009-12-21 13:20 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2010-02-17 14:59 . 2008-04-13 17:13 668672 c:\windows\ie8\wininet.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 668672 c:\windows\ie8\wininet.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 280576 c:\windows\ie8\webcheck.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 280576 c:\windows\ie8\webcheck.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 851968 c:\windows\ie8\vgx.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 851968 c:\windows\ie8\vgx.dll
- 2010-02-17 14:59 . 2008-05-09 10:53 430080 c:\windows\ie8\vbscript.dll
+ 2010-02-19 20:41 . 2008-05-09 10:53 430080 c:\windows\ie8\vbscript.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 620544 c:\windows\ie8\urlmon.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 620544 c:\windows\ie8\urlmon.dll
+ 2010-02-19 20:41 . 2009-01-07 17:21 401952 c:\windows\ie8\spuninst\updspapi.dll
- 2010-02-17 15:00 . 2009-01-07 17:21 401952 c:\windows\ie8\spuninst\updspapi.dll
- 2010-02-17 15:00 . 2009-01-07 17:21 234016 c:\windows\ie8\spuninst\spuninst.exe
+ 2010-02-19 20:41 . 2009-01-07 17:21 234016 c:\windows\ie8\spuninst\spuninst.exe
+ 2010-02-19 20:41 . 2008-04-13 17:13 532480 c:\windows\ie8\mstime.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 532480 c:\windows\ie8\mstime.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 146432 c:\windows\ie8\msrating.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 146432 c:\windows\ie8\msrating.dll
+ 2010-02-19 20:41 . 2006-03-02 12:00 146432 c:\windows\ie8\msls31.dll
- 2010-02-17 14:59 . 2006-03-02 12:00 146432 c:\windows\ie8\msls31.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 449024 c:\windows\ie8\mshtmled.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 449024 c:\windows\ie8\mshtmled.dll
+ 2010-02-19 20:41 . 2008-05-09 10:53 512000 c:\windows\ie8\jscript.dll
- 2010-02-17 14:59 . 2008-05-09 10:53 512000 c:\windows\ie8\jscript.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 251904 c:\windows\ie8\iepeers.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 251904 c:\windows\ie8\iepeers.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 323584 c:\windows\ie8\iedkcs32.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 323584 c:\windows\ie8\iedkcs32.dll
+ 2010-02-19 20:41 . 2006-03-02 12:00 237568 c:\windows\ie8\ieakui.dll
- 2010-02-17 14:59 . 2006-03-02 12:00 237568 c:\windows\ie8\ieakui.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 221184 c:\windows\ie8\ieaksie.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 221184 c:\windows\ie8\ieaksie.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 143360 c:\windows\ie8\ieakeng.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 143360 c:\windows\ie8\ieakeng.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 205312 c:\windows\ie8\dxtrans.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 205312 c:\windows\ie8\dxtrans.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 357888 c:\windows\ie8\dxtmsft.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 357888 c:\windows\ie8\dxtmsft.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 101888 c:\windows\ie8\advpack.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 101888 c:\windows\ie8\advpack.dll
+ 2006-03-02 12:00 . 2009-03-08 03:34 1206784 c:\windows\system32\urlmon.dll
+ 2006-03-02 12:00 . 2009-03-08 03:41 5937152 c:\windows\system32\mshtml.dll
+ 2009-03-08 03:32 . 2009-03-08 03:32 1985024 c:\windows\system32\iertutil.dll
+ 2009-03-08 03:34 . 2009-03-08 03:34 1206784 c:\windows\system32\dllcache\urlmon.dll
+ 2009-03-08 03:41 . 2009-03-08 03:41 5937152 c:\windows\system32\dllcache\mshtml.dll
- 2010-02-17 14:59 . 2008-04-13 17:13 3066880 c:\windows\ie8\mshtml.dll
+ 2010-02-19 20:41 . 2008-04-13 17:13 3066880 c:\windows\ie8\mshtml.dll
+ 2009-03-08 03:39 . 2009-03-08 03:39 11063808 c:\windows\system32\ieframe.dll
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\programmi\uTorrent\uTorrent.exe" [2010-02-17 319280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\programmi\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-21 61440]
"Motive SmartBridge"="c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"COMODO Internet Security"="c:\programmi\COMODO\COMODO Internet Security\cfp.exe" [2009-07-24 1796856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 09:05 356352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Alice ti aiuta.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Alice ti aiuta.lnk
backup=c:\windows\pss\Alice ti aiuta.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-09-10 23:43 67488 ----a-w- c:\programmi\Adobe\Photoshop Elements 6.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2009-04-24 03:05 203416 ----a-w- c:\programmi\Alcohol Soft\Alcohol 52\AxCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-01-15 14:14 147456 ----a-w- c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-13 17:14 110592 ----a-w- c:\windows\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LELA]
2008-08-06 10:16 159744 ----a-w- c:\programmi\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmctxth]
2008-05-16 04:11 648504 ----a-w- c:\programmi\File comuni\Pure Networks Shared\Platform\nmctxth.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 14:07 2260480 --sha-r- c:\programmi\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-11-13 15:32 149280 ----a-w- c:\programmi\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-08-11 16:41 39408 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-02-17 15:09 319280 ----a-w- c:\programmi\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"cmdAgent"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Programmi\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Programmi\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Programmi\\KONAMI\\Pro Evolution Soccer 2010\\pes2010.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [24/07/2009 14.49.38 99216]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [24/07/2009 14.49.38 31504]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [17/02/2009 10.43.28 8944]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [17/02/2009 10.43.28 55024]
R2 WinDefend;Windows Defender;c:\programmi\Windows Defender\MsMpEng.exe [03/11/2006 18.19.58 13592]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [09/11/2009 16.06.32 721904]
S2 gupdate1ca1aa48ebc7b9a;Servizio di Google Update (gupdate1ca1aa48ebc7b9a);c:\programmi\Google\Update\GoogleUpdate.exe [11/08/2009 17.55.27 133104]
S2 LinksysUpdater;Linksys Updater;c:\programmi\Linksys\Linksys Updater\bin\LinksysUpdater.exe [26/06/2008 13.52.42 204800]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [03/02/2010 18.47.55 8192]
S3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [17/02/2009 10.43.30 7408]
.
Contenuto della cartella 'Scheduled Tasks'
2010-02-20 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-11 16:41]
2010-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-08-11 16:54]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-08-11 16:54]
2010-02-20 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2010-02-20 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\nqv3kvfr.default\
FF - prefs.js: browser.startup.homepage -
www.google.itFF - component: c:\programmi\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\programmi\Common Files\Motive\npMotive.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{B922D405-6D13-4A2B-AE89-08A030DA4402} - (no file)
BHO-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
Notify-avgrsstarter - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-20 12:56
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1409082233-287218729-725345543-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:98,fc,1a,e4,f5,77,20,50,ee,3e,d0,9a,b7,2f,61,13,a3,2b,f2,b8,c7,17,b2,
2e,84,3f,f3,d0,ad,dd,05,08,61,0c,bb,3f,34,03,5f,06,d9,ff,1c,30,78,10,c4,b8,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-1409082233-287218729-725345543-500\Software\SecuROM\License information*]
"datasecu"=hex:3a,a5,79,0d,cc,13,81,f0,d2,27,8c,b3,8d,98,59,f4,d2,d5,89,3f,06,
4d,ae,ee,af,66,8f,f8,9e,bf,b1,17,42,72,6f,fc,f3,ab,1e,d9,72,95,55,af,b4,76,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(572)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Ora fine scansione: 2010-02-20 12:58:37
ComboFix-quarantined-files.txt 2010-02-20 11:58
ComboFix2.txt 2010-02-18 20:28
Pre-Run: 110.872.158.208 byte disponibili
Post-Run: 110.824.443.904 byte disponibili
- - End Of File - - A7403671AE0687E8B21E908A0DE908B6