ComboFix 10-03-11.06 - Vista 12/03/2010 17.51.03.4.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.39.1040.18.3002.1752 [GMT 1:00]
Eseguito da: c:\users\vista\documents\downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Creati Da 2010-02-12 al 2010-03-12 )))))))))))))))))))))))))))))))))))
.
2010-03-12 16:58 . 2010-03-12 16:58 -------- d-----w- c:\users\Vista\AppData\Local\temp
2010-03-12 16:58 . 2010-03-12 16:58 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-03-12 16:58 . 2010-03-12 16:58 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-03-12 10:02 . 2010-03-02 14:23 84912 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100311.036\NAVENG.SYS
2010-03-12 10:02 . 2010-03-02 14:23 1324720 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100311.036\NAVEX15.SYS
2010-03-12 10:02 . 2009-08-29 09:00 177520 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100311.036\NAVENG32.DLL
2010-03-12 10:02 . 2009-08-29 09:00 1647984 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100311.036\NAVEX32A.DLL
2010-03-12 10:02 . 2010-03-02 14:23 2747440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100311.036\CCERASER.DLL
2010-03-12 10:02 . 2010-03-02 14:23 259440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100311.036\ECMSVR32.DLL
2010-03-12 10:02 . 2009-08-29 09:00 371248 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100311.036\EECTRL.SYS
2010-03-12 10:02 . 2009-08-29 09:00 102448 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100311.036\ERASER.SYS
2010-03-11 16:51 . 2010-03-11 16:51 -------- d-----w- c:\users\Vista\AppData\Roaming\Malwarebytes
2010-03-11 16:50 . 2010-03-12 16:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-11 16:50 . 2010-03-11 16:50 -------- d-----w- c:\programdata\Malwarebytes
2010-03-11 14:19 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100310.001\IDSvix86.sys
2010-03-11 14:19 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100310.001\IDSXpx86.sys
2010-03-11 14:19 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100310.001\Scxpx86.dll
2010-03-11 14:19 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100310.001\IDSxpx86.dll
2010-03-11 14:19 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100310.001\IDSviA64.sys
2010-03-10 16:32 . 2010-03-10 19:06 -------- d-----w- c:\users\Vista\AppData\Local\CrashDumps
2010-03-08 19:39 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100305.002\Scxpx86.dll
2010-03-08 19:39 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100305.002\IDSXpx86.sys
2010-03-08 19:39 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100305.002\IDSvix86.sys
2010-03-08 19:39 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100305.002\IDSxpx86.dll
2010-03-08 19:39 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100305.002\IDSviA64.sys
2010-03-04 17:27 . 2010-03-04 17:27 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-04 16:58 . 2010-03-04 16:58 -------- d-----w- c:\users\Vista\AppData\Local\Apple_Inc
2010-03-04 16:24 . 2010-03-04 16:24 -------- d-----w- c:\users\Public\CyberLink
2010-03-02 18:56 . 2010-03-02 18:56 -------- d-----w- c:\program files\Trend Micro
2010-03-02 14:21 . 2009-12-03 06:09 44080 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2010-03-02 14:07 . 2010-03-02 14:06 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-03-02 14:06 . 2010-03-02 14:07 -------- d-----w- c:\program files\Symantec
2010-03-02 14:06 . 2009-08-30 00:16 164216 ----a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\IPSFFPlgn\components\IPSFFPl.dll
2010-03-02 14:06 . 2009-08-26 22:13 900464 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\OCS\hsplayer.dll
2010-03-02 14:06 . 2009-09-01 09:02 893296 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\CLT\cltLMSx.dll
2010-03-02 14:06 . 2010-03-02 17:24 -------- d-----w- c:\windows\system32\drivers\NAV
2010-03-02 14:06 . 2010-03-02 14:06 -------- d-----w- c:\program files\Norton AntiVirus
2010-03-02 14:05 . 2010-03-02 14:05 -------- d-----w- c:\program files\NortonInstaller
2010-02-24 15:24 . 2010-02-24 15:24 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Apple Computer
2010-02-24 14:20 . 2010-01-23 09:26 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-24 14:20 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 14:20 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll
2010-02-24 14:20 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 14:19 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 14:19 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 14:19 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 14:19 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-02-24 14:19 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 14:19 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-02-24 14:19 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-02-24 14:19 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-02-24 14:19 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-02-22 20:23 . 2010-02-24 15:24 -------- d--h--w- c:\users\Vista\AppData\Roaming\sys
2010-02-21 20:39 . 2010-02-21 20:39 -------- d-----w- c:\users\Vista\AppData\Roaming\java
2010-02-21 20:39 . 2010-02-21 20:39 45056 ---ha-w- c:\users\Vista\AppData\Roaming\java\msnmsgs.exe
2010-02-21 20:39 . 2010-02-21 20:40 45056 ----a-w- c:\users\Vista\AppData\Roaming\msnmsgs.exe
2010-02-19 23:47 . 2010-02-19 23:47 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-11 17:45 . 2010-02-11 17:45 676912 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100211.001\BHDrvx64.sys
2010-02-11 17:45 . 2010-02-11 17:45 611216 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100211.001\bbRGen.dll
2010-02-11 17:45 . 2010-02-11 17:45 536112 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100211.001\BHDrvx86.sys
2010-02-11 17:45 . 2010-02-11 17:45 201616 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100211.001\BHRules.dll
2010-02-11 17:45 . 2010-02-11 17:45 1406352 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100211.001\BHEngine.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-12 16:47 . 2009-05-16 16:12 -------- d-----w- c:\users\Vista\AppData\Roaming\uTorrent
2010-03-12 16:42 . 2008-08-01 06:27 -------- d-----w- c:\programdata\WildTangent
2010-03-11 18:13 . 2009-03-22 08:25 -------- d-----w- c:\programdata\Lx_cats
2010-03-11 15:13 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-03-10 19:53 . 2008-08-01 15:35 665702 ----a-w- c:\windows\system32\perfh010.dat
2010-03-10 19:53 . 2008-08-01 15:35 121302 ----a-w- c:\windows\system32\perfc010.dat
2010-03-10 19:05 . 2009-03-23 11:45 -------- d-----w- c:\program files\Sparta - La Battaglia delle Termopili
2010-03-06 18:04 . 2009-05-28 12:18 122 ----a-w- c:\users\Vista\AppData\Roaming\wklnhst.dat
2010-03-04 17:24 . 2009-02-25 13:16 -------- d-----w- c:\program files\Common Files\ACD Systems
2010-03-04 17:17 . 2008-08-01 07:17 -------- d-----w- c:\program files\Common Files\Java
2010-03-04 17:15 . 2008-08-01 07:17 -------- d-----w- c:\program files\Java
2010-03-04 17:08 . 2008-08-01 06:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-04 17:05 . 2008-08-01 06:59 -------- d-----w- c:\program files\CyberLink
2010-03-04 16:24 . 2009-03-23 11:09 -------- d-----w- c:\users\Vista\AppData\Roaming\CyberLink
2010-03-04 06:43 . 2008-08-01 07:08 588472 ----a-w- c:\windows\system32\ezsvc7x.dll
2010-03-02 15:51 . 2009-03-08 15:16 5972 ----a-w- c:\users\Vista\AppData\Local\d3d9caps.dat
2010-03-02 14:21 . 2008-08-01 06:01 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-03-02 14:06 . 2010-03-02 14:07 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-03-02 14:06 . 2010-03-02 14:07 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-03-02 14:06 . 2009-05-29 18:21 -------- d-----w- c:\programdata\Norton
2010-03-02 14:05 . 2009-05-29 18:20 -------- d-----w- c:\programdata\NortonInstaller
2010-02-24 15:24 . 2009-02-25 11:14 102816 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 14:50 . 2009-02-25 11:22 102816 ----a-w- c:\users\Vista\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-22 12:28 . 2010-03-06 11:23 1282824 ----a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-02-09 20:58 . 2009-08-20 19:11 -------- d-----w- c:\program files\uTorrent
2010-02-08 21:00 . 2010-02-08 21:00 -------- d-----w- c:\program files\Windows Portable Devices
2010-02-08 21:00 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-02-08 21:00 . 2010-02-08 21:00 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-02-08 21:00 . 2010-02-08 21:00 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-02-08 20:39 . 2010-02-08 20:39 -------- d-----w- c:\program files\Bonjour
2010-02-08 20:33 . 2008-08-01 06:55 -------- d-----w- c:\programdata\Microsoft Help
2010-02-08 19:34 . 2010-02-08 19:34 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-02-08 19:33 . 2010-02-08 19:33 -------- d-----w- c:\program files\Microsoft.NET
2010-02-08 19:33 . 2010-02-08 19:33 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-02-08 19:31 . 2010-02-08 19:31 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-02-08 19:22 . 2008-08-01 06:42 -------- d-----w- c:\program files\Microsoft Works
2010-02-08 18:29 . 2009-03-19 18:15 -------- d-----w- c:\program files\Google
2010-02-07 16:46 . 2010-02-07 16:46 123788 ---ha-w- c:\windows\system32\mlfcache.dat
2010-02-07 16:46 . 2009-06-16 10:14 -------- d-----w- c:\users\Vista\AppData\Roaming\Apple Computer
2010-02-07 16:11 . 2010-02-07 16:10 -------- d-----w- c:\program files\iTunes
2010-02-07 16:10 . 2010-02-07 16:10 -------- d-----w- c:\program files\iPod
2010-02-07 16:10 . 2009-06-16 10:11 -------- d-----w- c:\program files\Common Files\Apple
2010-02-07 16:06 . 2010-02-07 16:06 -------- d-----w- c:\program files\QuickTime
2010-02-07 16:02 . 2010-02-07 16:02 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-04 15:51 . 2010-03-06 11:23 49152 ----a-w- c:\windows\Help\OEM\scripts\Interop.TaskScheduler.dll
2010-01-29 18:48 . 2010-01-29 18:48 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2010-01-24 20:22 . 2008-08-01 06:01 -------- d-----w- c:\programdata\Symantec
2010-01-22 14:13 . 2009-03-05 17:21 -------- d-----w- c:\programdata\Messenger Plus!
2010-01-22 13:49 . 2009-03-05 16:55 -------- d-----w- c:\program files\Messenger Plus! Live
2010-01-20 14:26 . 2010-01-20 14:26 -------- d-----w- c:\program files\MSECache
2010-01-18 16:36 . 2010-01-18 16:34 -------- d-----w- c:\program files\Opera
2010-01-06 15:38 . 2010-02-24 14:19 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-24 14:19 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-06 15:38 . 2010-02-24 14:19 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-24 14:19 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 10:53 . 2009-08-28 07:09 89 ----a-w- c:\users\Vista\AppData\Local\lredjwn.bat
2010-01-02 06:38 . 2010-01-22 06:44 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 06:44 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 06:44 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 06:44 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-17 16:14 . 2009-09-20 09:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2008-08-01 15:38 . 2008-08-01 15:38 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-03 20:12 556432 ----a-w- c:\progra~1\MICROS~3\Office14\URLREDIR.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-02-09 319280]
"Google Update"="c:\users\Vista\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-09-12 133104]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-17 145944]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-11 468264]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-05-12 202032]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"lxdimon.exe"="c:\program files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-05-07 435120]
"lxdiamon"="c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-03-05 20480]
"FaxCenterServer"="c:\program files\\Lexmark Fax Solutions\fm3032.exe" [2007-05-07 312240]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2009-09-26 83312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):c7,69,91,4b,5f,52,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1384446576-1961234908-3673197661-1000]
"EnableNotificationsRef"=dword:00000001
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-09-26 4639136]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1105000.07F\SYMDS.SYS [2009-08-30 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1105000.07F\SYMEFA.SYS [2009-11-26 172592]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100211.001\BHDrvx86.sys [2010-02-11 536112]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1105000.07F\ccHPx86.sys [2009-12-09 501888]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100310.001\IDSvix86.sys [2009-10-28 343088]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1105000.07F\Ironx86.SYS [2009-11-26 116272]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NAV\1105000.07F\SYMTDIV.SYS [2009-11-22 340016]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe [2007-04-26 517040]
S2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdiserv.exe [2007-04-26 99248]
S2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe [2009-12-09 126392]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-25 361808]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-08-29 102448]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-04 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 13:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
[HKEY_CURRENT_USER\software\microsoft\active setup\installed components\{1D1BADC6-EAC7-0CCD-03A7-EDF22BE6FCD8}]
c:\users\Vista\AppData\Roaming\sys\winfinder.exe [BU]
.
Contenuto della cartella 'Scheduled Tasks'
2010-03-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1384446576-1961234908-3673197661-1000Core.job
- c:\users\Vista\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-12 16:04]
2010-03-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1384446576-1961234908-3673197661-1000UA.job
- c:\users\Vista\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-12 16:04]
2010-03-08 c:\windows\Tasks\HPCeeScheduleForVista.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-08-01 13:14]
2010-03-12 c:\windows\Tasks\User_Feed_Synchronization-{F233B6AA-D954-4DF7-9560-114012602893}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://it.ask.com?o=15161&l=dis
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-12 17:58
Windows 6.0.6002 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\17.5.0.127\diMaster.dll\" /prefetch:1"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2010-03-12 18:01:55
ComboFix-quarantined-files.txt 2010-03-12 17:01
ComboFix2.txt 2010-03-02 20:24
Pre-Run: 112.064.503.808 byte disponibili
Post-Run: 112.036.626.432 byte disponibili
- - End Of File - - ED8BC8EFF9CBE055380BC07CE3D432CB