oleeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
habemus combofix heheheh, no no sul serio parlando in modalità provvisoria combofix ha fatto il suo sporco lavoro,ma ho dovuto rifare due volte la scansione per avere il report log, ma ora log alla mano eccovi i risultato della scansione:
ComboFix 10-03-29.04 - Utente 02/04/2010 2.55.35.8.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3071.2700 [GMT 2:00]
Eseguito da: h:\documents and settings\Utente\Desktop\eddyno.exe
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {00000002-0002-0000-6C25-9E7C08000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
H:\setup.exe
h:\windows\system32\d3d10core.dll
h:\windows\system32\kernel32new.dll
h:\windows\system32\msvcrtnew.dll
h:\windows\system32\vbzlib1.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Creati Da 2010-03-02 al 2010-04-02 )))))))))))))))))))))))))))))))))))
.
2010-04-01 23:35 . 2010-04-01 23:35 -------- d-----w- h:\documents and settings\Administrator
2010-04-01 18:42 . 2010-04-01 18:42 -------- d-----w- h:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\PackageAware
2010-04-01 10:32 . 2009-08-06 17:23 274288 ----a-w- h:\windows\system32\mucltui.dll
2010-04-01 05:50 . 2010-04-01 05:50 -------- d-----w- h:\programmi\Trend Micro
2010-04-01 03:54 . 2010-04-01 03:54 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Malwarebytes
2010-04-01 03:54 . 2010-03-29 13:24 38224 ----a-w- h:\windows\system32\drivers\mbamswissarmy.sys
2010-04-01 03:54 . 2010-04-01 03:54 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-04-01 03:54 . 2010-04-01 03:54 -------- d-----w- h:\programmi\Malwarebytes' Anti-Malware
2010-04-01 03:54 . 2010-03-29 13:24 20824 ----a-w- h:\windows\system32\drivers\mbam.sys
2010-03-31 02:13 . 2010-03-31 02:13 -------- d-----w- h:\windows\Sun
2010-03-31 02:12 . 2010-03-31 02:12 503808 ----a-w- h:\documents and settings\Utente\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6dc0c142-n\msvcp71.dll
2010-03-31 02:12 . 2010-03-31 02:12 499712 ----a-w- h:\documents and settings\Utente\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6dc0c142-n\jmc.dll
2010-03-31 02:12 . 2010-03-31 02:12 348160 ----a-w- h:\documents and settings\Utente\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6dc0c142-n\msvcr71.dll
2010-03-31 02:12 . 2010-03-31 02:12 61440 ----a-w- h:\documents and settings\Utente\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-11aa3693-n\decora-sse.dll
2010-03-31 02:12 . 2010-03-31 02:12 12800 ----a-w- h:\documents and settings\Utente\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-11aa3693-n\decora-d3d.dll
2010-03-28 20:27 . 2010-03-28 20:29 -------- d-----w- h:\programmi\File comuni\DVDVideoSoft
2010-03-28 20:27 . 2010-03-28 20:27 -------- d-----w- h:\programmi\DVDVideoSoft
2010-03-26 04:06 . 2010-03-26 04:06 -------- d-----w- h:\programmi\DsNET Corp
2010-03-25 16:31 . 2010-03-25 16:31 -------- d-----w- h:\windows\system32\Adobe
2010-03-23 02:32 . 2010-03-23 02:43 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\dvdcss
2010-03-23 02:26 . 2010-03-23 02:26 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Media Player Classic
2010-03-20 21:19 . 2010-03-20 21:19 -------- d-----w- h:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Atari
2010-03-20 21:09 . 2010-03-20 21:09 -------- d-----w- h:\programmi\Atari
2010-03-15 19:13 . 2010-03-15 19:13 159080 ----a-w- h:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-03-15 03:45 . 2010-03-15 03:45 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\gnupg
2010-03-14 14:29 . 2010-03-14 14:42 -------- d-----w- h:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\Rockstar Games
2010-03-14 14:21 . 2010-03-14 14:21 -------- d--h--r- h:\documents and settings\Utente\Dati applicazioni\SecuROM
2010-03-14 14:16 . 2010-03-14 14:16 -------- d-----w- h:\windows\system32\xlive
2010-03-14 14:16 . 2010-03-14 14:37 -------- d-----w- h:\programmi\Microsoft Games for Windows - LIVE
2010-03-10 22:15 . 2010-03-10 22:15 -------- d-----w- h:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Adobe
2010-03-08 23:22 . 2010-03-08 23:22 -------- d-----w- h:\programmi\Badaboom
2010-03-08 21:31 . 2010-03-08 21:31 -------- d-----w- h:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\CAPCOM
2010-03-07 16:52 . 2010-03-29 01:18 -------- d-----w- H:\X-Plane 9
2010-03-07 16:04 . 2010-03-07 16:04 -------- d-----w- h:\programmi\ESET
2010-03-07 16:04 . 2010-03-07 16:04 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\ESET
2010-03-07 14:19 . 2010-03-07 14:19 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2010-03-07 14:01 . 2010-04-01 16:15 443912 ----a-w- h:\documents and settings\Utente\Dati applicazioni\Real\Update\setup3.10\setup.exe
2010-03-07 11:39 . 2010-03-07 11:40 -------- d-----w- h:\programmi\Essentials Codec Pack
2010-03-07 11:31 . 2006-10-18 01:53 147456 ----a-w- h:\windows\system32\RtlCPAPI.dll
2010-03-07 11:30 . 2010-03-07 11:30 -------- d-----w- h:\programmi\Realtek AC97
2010-03-07 10:31 . 2010-03-07 10:31 -------- d-----w- h:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-02 00:58 . 2001-08-31 12:00 585164 ----a-w- h:\windows\system32\perfh010.dat
2010-04-02 00:58 . 2001-08-31 12:00 113510 ----a-w- h:\windows\system32\perfc010.dat
2010-04-01 23:54 . 2010-02-06 02:17 -------- d---a-w- h:\documents and settings\All Users\Dati applicazioni\TEMP
2010-04-01 23:25 . 2010-02-27 15:10 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Free Download Manager
2010-04-01 22:56 . 2010-02-02 14:58 -------- d--h--w- h:\programmi\InstallShield Installation Information
2010-04-01 22:34 . 2010-02-01 16:31 69224 ----a-w- h:\documents and settings\Utente\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-04-01 17:32 . 2010-02-11 05:38 -------- d-----w- h:\programmi\DAEMON Tools Toolbar
2010-04-01 16:19 . 2010-02-02 10:56 -------- d-----w- h:\programmi\Windows Media Connect 2
2010-04-01 15:46 . 2010-02-16 07:09 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\avg9
2010-04-01 14:23 . 2010-02-02 15:02 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-04-01 13:49 . 2010-02-06 02:26 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Alwil Software
2010-04-01 13:40 . 2010-02-05 21:07 -------- d-----w- h:\programmi\PC Connectivity Solution
2010-04-01 13:21 . 2010-02-06 01:41 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\BitTorrent
2010-03-31 23:42 . 2010-02-21 23:05 -------- d-----w- h:\programmi\Windows Live Safety Center
2010-03-31 23:09 . 2010-02-05 23:02 -------- d-----w- h:\programmi\Messenger_Plus_Live
2010-03-31 23:09 . 2010-02-05 23:02 -------- d-----w- h:\programmi\Messenger Plus! Live
2010-03-31 20:58 . 2010-02-02 18:53 -------- d-----w- h:\programmi\File comuni\Wise Installation Wizard
2010-03-31 02:41 . 2010-02-07 13:36 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\vlc
2010-03-31 02:13 . 2010-02-05 21:30 -------- d-----w- h:\programmi\File comuni\Java
2010-03-31 02:12 . 2010-02-05 21:30 -------- d-----w- h:\programmi\Java
2010-03-16 06:51 . 2010-02-02 18:53 61440 ----a-w- h:\windows\system32\OpenCL.dll
2010-03-16 06:51 . 2010-02-02 18:53 11640832 ----a-w- h:\windows\system32\nvcompiler.dll
2010-03-16 06:51 . 2010-02-01 18:39 6432128 ----a-w- h:\windows\system32\nv4_disp.dll
2010-03-16 06:51 . 2010-02-01 18:38 10232352 ----a-w- h:\windows\system32\drivers\nv4_mini.sys
2010-03-16 06:51 . 2009-10-05 10:10 4075520 ----a-w- h:\windows\system32\nvcuda.dll
2010-03-16 06:51 . 2009-10-05 10:10 2646632 ----a-w- h:\windows\system32\nvcuvenc.dll
2010-03-16 06:51 . 2009-10-05 10:10 2183470 ----a-w- h:\windows\system32\nvdata.bin
2010-03-16 06:51 . 2009-10-05 10:10 215656 ----a-w- h:\windows\system32\nvcodins.dll
2010-03-16 06:51 . 2009-10-05 10:10 215656 ----a-w- h:\windows\system32\nvcod.dll
2010-03-16 06:51 . 2009-10-05 10:10 2030184 ----a-w- h:\windows\system32\nvcuvid.dll
2010-03-16 06:51 . 2009-10-05 10:10 14757888 ----a-w- h:\windows\system32\nvoglnt.dll
2010-03-16 06:51 . 2009-10-05 10:10 1097728 ----a-w- h:\windows\system32\nvapi.dll
2010-03-12 09:26 . 2010-02-02 17:53 600680 ----a-w- h:\windows\system32\NVUNINST.EXE
2010-03-09 02:28 . 2010-03-01 19:26 411368 ----a-w- h:\windows\system32\deploytk.dll
2010-03-08 23:55 . 2010-02-05 23:48 -------- d-----w- h:\programmi\EXPERTool
2010-03-08 21:30 . 2010-02-08 01:31 107888 ----a-w- h:\windows\system32\CmdLineExt.dll
2010-03-07 11:52 . 2010-02-02 18:53 -------- d-----w- h:\programmi\NVIDIA Corporation
2010-03-07 11:49 . 2010-02-27 15:10 -------- d-----w- h:\programmi\Free Download Manager
2010-03-07 11:39 . 2010-02-11 00:13 -------- d-----w- h:\programmi\Codec
2010-03-07 11:38 . 2010-02-07 16:30 26457 ----a-w- h:\windows\system32\unins000.dat
2010-03-07 11:38 . 2010-02-07 16:30 716153 ----a-w- h:\windows\system32\unins000.exe
2010-03-07 11:37 . 2010-02-08 19:12 41694 ----a-w- h:\programmi\File comuni\unins000.dat
2010-03-07 11:36 . 2010-02-08 19:12 730138 ----a-w- h:\programmi\File comuni\unins000.exe
2010-03-03 03:44 . 2010-02-15 10:42 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\flightgear.org
2010-03-01 19:26 . 2010-03-01 19:26 152576 ----a-w- h:\documents and settings\Utente\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2010-03-01 19:25 . 2010-03-01 19:25 79488 ----a-w- h:\documents and settings\Utente\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-28 11:12 . 2010-02-27 15:10 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Software Informer
2010-02-27 15:10 . 2010-02-27 15:10 -------- d-----w- h:\programmi\Software Informer
2010-02-27 15:10 . 2010-02-27 15:10 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\FreeDownloadManager.ORG
2010-02-18 06:32 . 2010-02-18 06:32 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\fltk.org
2010-02-17 02:06 . 2010-02-06 01:41 -------- d-----w- h:\programmi\BitTorrent
2010-02-16 06:39 . 2010-02-11 02:57 1396544 ----a-w- h:\windows\FSX_Screensaver.scr
2010-02-15 01:17 . 2010-02-11 02:57 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\DivX
2010-02-13 04:07 . 2010-02-11 00:10 -------- d-----w- h:\programmi\DivX
2010-02-13 04:07 . 2010-02-11 00:10 -------- d-----w- h:\programmi\File comuni\DivX Shared
2010-02-12 06:53 . 2010-02-12 06:53 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Activision
2010-02-12 06:53 . 2010-02-12 06:53 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Activision
2010-02-11 23:35 . 2010-02-05 21:07 -------- d-----w- h:\programmi\Samsung
2010-02-11 20:07 . 2010-02-11 20:07 -------- d-----w- h:\programmi\File comuni\SWF Studio
2010-02-11 05:52 . 2010-02-11 05:43 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\DAEMON Tools Lite
2010-02-11 05:43 . 2010-02-11 05:43 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\DAEMON Tools Lite
2010-02-11 05:38 . 2010-02-11 05:38 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\DAEMON Tools
2010-02-11 05:37 . 2010-02-11 05:13 691696 ----a-w- h:\windows\system32\drivers\sptd.sys
2010-02-11 05:29 . 2010-02-11 05:29 -------- d-----w- h:\programmi\Alcohol Soft
2010-02-11 04:23 . 2010-02-11 04:23 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Registry Mechanic
2010-02-11 04:01 . 2010-02-08 01:31 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Bioshock
2010-02-11 04:01 . 2010-02-11 03:47 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Norton
2010-02-11 04:01 . 2010-02-11 03:51 -------- d-----w- h:\programmi\File comuni\Symantec Shared
2010-02-11 03:47 . 2010-02-11 03:47 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Symantec
2010-02-11 03:47 . 2010-02-11 03:47 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\NortonInstaller
2010-02-11 02:57 . 2010-02-11 02:57 -------- d-----w- h:\programmi\FSX_Screensaver
2010-02-11 00:14 . 2010-02-11 00:14 -------- d-----w- h:\programmi\Xvid
2010-02-08 03:13 . 2010-02-02 11:04 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Ahead
2010-02-08 03:12 . 2010-02-08 03:12 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Apple Computer
2010-02-07 19:36 . 2010-02-02 17:25 -------- d-----w- h:\programmi\Realtek
2010-02-07 17:06 . 2010-02-02 17:25 -------- d-----w- h:\programmi\File comuni\InstallShield
2010-02-07 14:34 . 2010-02-07 14:34 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\CyberLink
2010-02-07 13:55 . 2010-02-07 13:55 -------- d-----w- h:\programmi\File comuni\Real
2010-02-07 13:55 . 2010-02-07 13:55 -------- d-----w- h:\programmi\File comuni\xing shared
2010-02-07 13:55 . 2010-02-02 14:57 499712 ----a-w- h:\windows\system32\msvcp71.dll
2010-02-07 13:55 . 2010-02-07 13:55 -------- d-----w- h:\programmi\Real
2010-02-07 13:54 . 2010-02-06 02:16 -------- d-----w- h:\programmi\Google
2010-02-07 13:50 . 2010-02-07 13:50 -------- d-----w- h:\programmi\QuickTime
2010-02-07 13:50 . 2010-02-07 13:50 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Apple Computer
2010-02-07 13:50 . 2010-02-07 13:50 -------- d-----w- h:\programmi\File comuni\Apple
2010-02-07 13:50 . 2010-02-07 13:50 -------- d-----w- h:\programmi\Apple Software Update
2010-02-07 13:50 . 2010-02-07 13:50 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Apple
2010-02-07 13:48 . 2010-02-07 13:40 -------- d-----w- h:\programmi\Winamp
2010-02-07 13:47 . 2010-02-07 13:40 -------- d-----w- h:\documents and settings\Utente\Dati applicazioni\Winamp
2010-02-07 13:41 . 2010-02-07 13:41 -------- d-----w- h:\programmi\Winamp Toolbar
2010-02-07 13:41 . 2010-02-07 13:41 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Winamp Toolbar
2010-02-07 13:39 . 2010-02-07 13:37 -------- d-----w- h:\programmi\The KMPlayer
2010-02-07 13:35 . 2010-02-07 13:35 -------- d-----w- h:\programmi\VideoLAN
2010-02-07 13:10 . 2010-02-07 13:10 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\PC Drivers HeadQuarters
2010-02-07 13:09 . 2010-02-07 13:09 -------- d-----w- h:\programmi\PC Drivers HeadQuarters
2010-02-07 12:57 . 2010-02-07 12:57 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\UAB
2010-02-07 12:57 . 2010-02-07 12:57 -------- d-----w- h:\documents and settings\All Users\Dati applicazioni\Driver Whiz
2010-02-07 12:56 . 2010-02-07 12:56 -------- d-----w- h:\programmi\Driver Whiz
2010-02-07 12:55 . 2010-02-02 10:40 -------- d-----w- h:\programmi\File comuni\Adobe
2010-02-06 17:41 . 2010-02-02 15:17 56816 ----a-w- h:\windows\system32\drivers\avgntflt.sys
.
(((((((((((((((((((((((((((((
SnapShot@2010-04-01_23.45.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-08-31 12:00 . 2010-04-02 00:58 89426 h:\windows\system32\perfc009.dat
+ 2001-08-31 12:00 . 2010-04-02 00:58 508220 h:\windows\system32\perfh009.dat
+ 2010-02-05 21:12 . 2010-04-02 00:52 204316 h:\windows\system32\inetsrv\MetaBase.bin
- 2010-02-05 21:12 . 2010-04-01 23:45 204316 h:\windows\system32\inetsrv\MetaBase.bin
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "h:\programmi\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
"{9b339f6e-ddcd-401b-8764-230adbd01761}"= "h:\programmi\Messenger_Plus_Live\tbMess.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CLASSES_ROOT\clsid\{9b339f6e-ddcd-401b-8764-230adbd01761}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9b339f6e-ddcd-401b-8764-230adbd01761}]
2009-12-31 09:53 2349080 ----a-w- h:\programmi\Messenger_Plus_Live\tbMess.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9b339f6e-ddcd-401b-8764-230adbd01761}"= "h:\programmi\Messenger_Plus_Live\tbMess.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{9b339f6e-ddcd-401b-8764-230adbd01761}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9B339F6E-DDCD-401B-8764-230ADBD01761}"= "h:\programmi\Messenger_Plus_Live\tbMess.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{9b339f6e-ddcd-401b-8764-230adbd01761}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="h:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [BU]
"msnmsgr"="h:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"AutoStartNPSAgent"="h:\programmi\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-04-02 102400]
"AliceMessenger"="h:\programmi\Alice Messenger\alicemessenger.exe" [2009-02-05 3657728]
"GAINWARD"="h:\programmi\EXPERTool\TBPanel.exe" [2009-10-05 2174976]
"swg"="h:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-02-06 39408]
"RegistryMechanic"="h:\programmi\Registry Mechanic\RegMech.exe" [2009-11-25 3176408]
"fsm"="" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="h:\programmi\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 71216]
"LanguageShortcut"="h:\programmi\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"GrooveMonitor"="h:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NVRaidService"="h:\windows\system32\nvraidservice.exe" [2007-09-11 187936]
"XboxStat"="h:\programmi\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]
"NPSStartup"="" [BU]
"MsmqIntCert"="mqrt.dll" [2008-04-13 177152]
"PDF Complete"="h:\programmi\PDF Complete\pdfsty.exe" [2008-05-12 318488]
"SunJavaUpdateSched"="h:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SynTPEnh"="h:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1040384]
"Motive SmartBridge"="h:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe" [2006-04-21 438359]
"AliceRE_McciTrayApp"="c:\progra~1\ALICET~1\vendors\AliceRE\content\template\driven~1\syncer\McciTrayApp.exe" [BU]
"Adobe Reader Speed Launcher"="h:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="h:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="h:\programmi\QuickTime\qttask.exe" [2009-11-10 417792]
"TkBellExe"="h:\programmi\File comuni\Real\Update_OB\realsched.exe" [2010-02-07 198160]
"RTHDCPL"="RTHDCPL.EXE" [2010-01-19 18790432]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"AlcWzrd"="ALCWZRD.EXE" [2010-01-19 2815520]
"nwiz"="nwiz.exe" [BU]
"NvCplDaemon"="h:\windows\system32\NvCpl.dll" [2010-03-16 13670504]
"NvMediaCenter"="h:\windows\system32\NvMcTray.dll" [2010-03-16 110696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="h:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
h:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Alice ti aiuta.lnk - h:\programmi\Alice ti aiuta\bin\matcli.exe [2010-2-6 217088]
NETGEAR WG111v3 Smart Wizard.lnk - h:\programmi\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 2326528]
WDDMStatus.lnk - h:\programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-10-14 2049344]
WDSmartWare.lnk - h:\programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-10-14 9085760]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "h:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"h:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"h:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"h:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"h:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"h:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"h:\\Programmi\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"h:\\Programmi\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"h:\\WINDOWS\\system32\\mqsvc.exe"=
"h:\\Programmi\\BitTorrent\\bittorrent.exe"=
"h:\\WINDOWS\\system32\\dxdiag.exe"=
"h:\\WINDOWS\\system32\\dpnsvr.exe"=
"h:\\WINDOWS\\system32\\dpvsetup.exe"=
"h:\\Programmi\\Free Download Manager\\fdm.exe"=
"h:\\X-Plane 9\\X-Plane.exe"=
"h:\\Programmi\\Atari\\AITD\\Alone.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Gruppi peer-to-peer Windows
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;h:\windows\system32\drivers\nvoclock.sys [15/09/2009 14.59.28 38248]
S0 sptd;sptd;h:\windows\system32\drivers\sptd.sys [11/02/2010 7.13.53 691696]
S2 EAPPkt;Realtek EAPPkt Protocol;h:\windows\system32\drivers\EAPPkt.sys [09/10/2007 14.13.00 38144]
S2 FsUsbExService;FsUsbExService;h:\windows\system32\FsUsbExService.Exe [05/02/2010 23.07.43 233472]
S2 gupdate;Servizio di Google Update (gupdate);h:\programmi\Google\Update\GoogleUpdate.exe [06/02/2010 4.17.03 135664]
S2 Network WanMiniport First Position;Network WanMiniport First Position;h:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [06/02/2010 0.01.08 8192]
S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;h:\programmi\File comuni\PC Tools\sMonitor\StartManSvc.exe [06/02/2010 4.17.08 632792]
S2 pdfcDispatcher;PDF Document Manager;h:\programmi\PDF Complete\pdfsvc.exe [05/02/2010 23.29.40 576024]
S2 WDDMService;WD SmartWare Drive Manager;h:\programmi\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [14/10/2009 15.31.02 98304]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;h:\programmi\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 10.58.08 20480]
S3 Ambfilt;Ambfilt;h:\windows\system32\drivers\Ambfilt.sys [07/02/2010 21.33.39 1691480]
S3 FsUsbExDisk;FsUsbExDisk;h:\windows\system32\FsUsbExDisk.Sys [05/02/2010 23.07.43 36608]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;h:\windows\system32\drivers\nvhda32.sys [02/05/2008 23.46.00 58600]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;h:\windows\system32\drivers\wg111v3.sys [28/12/2007 16.02.12 287232]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);h:\windows\system32\drivers\ss_bbus.sys [05/02/2010 23.07.47 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);h:\windows\system32\drivers\ss_bmdfl.sys [05/02/2010 23.07.47 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;h:\windows\system32\drivers\ss_bmdm.sys [05/02/2010 23.07.47 121856]
S3 WDC_SAM;WD SCSI Pass Thru driver;h:\windows\system32\drivers\wdcsam.sys [05/02/2010 23.48.18 11520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contenuto della cartella 'Scheduled Tasks'
2010-03-31 h:\windows\Tasks\AppleSoftwareUpdate.job
- h:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-04-01 h:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- h:\programmi\Google\Update\GoogleUpdate.exe [2010-02-06 02:17]
2010-04-01 h:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- h:\programmi\Google\Update\GoogleUpdate.exe [2010-02-06 02:17]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&sporta in Microsoft Excel - h:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - h:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Scarica con Free Download Manager - file://h:\programmi\Free Download Manager\dllink.htm
IE: Scarica i video con Free Download Manager - file://h:\programmi\Free Download Manager\dlfvideo.htm
IE: Scarica selezionati con Free Download Manager - file://h:\programmi\Free Download Manager\dlselected.htm
IE: Scarica tutto con Free Download Manager - file://h:\programmi\Free Download Manager\dlall.htm
Trusted Zone: adobe.com\www
DPF: Microsoft XML Parser for Java - file:///H:/WINDOWS/Java/classes/xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SharedTaskScheduler-{F46BE738-CAC5-44DE-B094-C59942198F9C} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-02 02:59
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="h:\programmi\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\h:\programmi\CyberLink\PowerDVD\000.fcl"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1454471165-179605362-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1454471165-179605362-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:1e,0f,9e,76,bd,9e,d1,4c,b0,0c,d7,41,4f,f8,73,6f,23,c6,0e,e4,67,
7e,af,f0,60,a5,52,94,a1,5f,7a,26,1a,50,02,16,b7,5f,ed,e9,a4,ce,c6,f0,91,51,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(2008)
h:\windows\system32\WININET.dll
.
Ora fine scansione: 2010-04-02 03:00:58
ComboFix-quarantined-files.txt 2010-04-02 01:00
Pre-Run: 401.196.261.376 byte disponibili
Post-Run: 401.216.020.480 byte disponibili
- - End Of File - - 0CB63B208999A09426387AA7A87CA77F
bene ecco tutto, ora attendo vostre istruzioni sul procedere ^.-"
e grazie grazie e ancora grazie per il vostro aiuto,siete impagabili!