ComboFix 10-04-15.05 - fernanda mazzieri 17/04/2010 13.51.36.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1015.357 [GMT 2:00]
Eseguito da: c:\documents and settings\fernanda mazzieri\Documenti\Download\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Creati Da 2010-03-17 al 2010-04-17 )))))))))))))))))))))))))))))))))))
.
2010-04-17 07:31 . 2010-04-17 07:31 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Malwarebytes
2010-04-17 07:30 . 2010-03-29 13:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-17 07:30 . 2010-04-17 07:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-04-17 07:30 . 2010-04-17 07:30 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-04-17 07:30 . 2010-03-29 13:24 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-15 12:00 . 2010-04-15 12:01 125952 ----a-w- c:\documents and settings\All Users\Dati applicazioni\ParetoLogic\UUS2\Temp\Update.exe
2010-04-15 11:58 . 2010-04-15 17:03 24352 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-04-15 11:58 . 2010-04-15 17:03 1804576 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-04-15 09:44 . 2010-04-15 13:31 -------- d-----w- c:\programmi\File comuni\ParetoLogic
2010-04-15 09:44 . 2010-04-15 13:31 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ParetoLogic
2010-04-15 09:43 . 2010-04-15 09:43 -------- d-----w- c:\documents and settings\fernanda mazzieri\Impostazioni locali\Dati applicazioni\Downloaded Installations
2010-04-13 13:07 . 2010-04-13 13:11 117760 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-04-13 13:07 . 2010-04-13 13:07 52224 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-04-13 13:07 . 2010-04-13 13:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2010-04-13 13:06 . 2010-04-13 13:06 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2010-04-13 07:49 . 2010-04-13 07:49 -------- d-----w- c:\windows\system32\wbem\Repository
2010-04-11 05:50 . 2010-04-13 13:06 -------- d-----w- c:\programmi\SUPERAntiSpyware
2010-04-11 05:50 . 2010-04-11 05:50 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\SUPERAntiSpyware.com
2010-04-06 12:54 . 2010-04-06 12:54 -------- d-----w- c:\programmi\File comuni\PCSuite
2010-04-06 12:54 . 2010-04-06 12:54 -------- d-----w- c:\programmi\File comuni\Nokia
2010-04-06 12:53 . 2010-04-06 12:53 -------- d-----w- c:\programmi\DIFX
2010-04-06 12:53 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-04-06 12:53 . 2010-04-06 12:53 -------- d-----w- c:\programmi\PC Connectivity Solution
2010-04-06 12:53 . 2009-02-09 05:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-04-06 12:53 . 2010-04-06 12:54 -------- d-----w- c:\programmi\Nokia
2010-04-06 12:52 . 2009-01-01 10:00 52048144 --s-a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\PC-Suite.exe
2010-04-06 12:52 . 2010-04-06 12:52 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-06 12:52 . 2010-04-06 12:52 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-06 12:52 . 2010-04-06 12:52 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-06 12:50 . 2010-04-06 12:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Installations
2010-04-06 09:12 . 2001-08-30 21:07 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-04-06 09:12 . 2008-04-14 01:13 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-04-06 08:12 . 2010-04-06 08:12 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\FUJIFILM
2010-04-06 08:07 . 2000-03-29 15:11 8096 ------w- c:\windows\system32\drivers\MASPINT.SYS
2010-04-06 08:07 . 1997-02-28 01:00 2486 ------w- c:\windows\system\AS16POST.BIN
2010-04-06 08:07 . 2010-04-06 08:07 -------- d-----w- C:\MWASPI
2010-04-06 08:03 . 2010-04-06 08:03 -------- d-----w- c:\programmi\PIXELA
2010-04-06 08:03 . 2004-02-04 23:29 380928 ----a-w- c:\windows\system32\FE05F3D7.dll
2010-04-06 08:03 . 2003-12-09 17:45 401408 ----a-w- c:\windows\system32\FE05F3D6.dll
2010-04-06 08:03 . 2003-08-26 08:54 401408 ----a-w- c:\windows\system32\FE05EFED.dll
2010-04-06 08:03 . 2003-06-25 15:24 299008 ----a-w- c:\windows\system32\FE05F051.dll
2010-04-06 08:03 . 2003-06-09 22:37 299008 ----a-w- c:\windows\system32\FE05F3D5.dll
2010-04-06 08:03 . 2003-06-02 20:50 299008 ----a-w- c:\windows\system32\FE05DA0D.dll
2010-04-06 08:03 . 2002-04-07 02:26 106496 ----a-w- c:\windows\system32\FPXS2Pro.dll
2010-04-06 08:02 . 2003-09-06 05:57 159744 ----a-w- c:\windows\system32\FFRAFLIB.DLL
2010-04-06 08:02 . 2003-09-03 05:45 274432 ----a-w- c:\windows\system32\FFTIFF16.dll
2010-04-06 08:01 . 2001-11-25 11:11 81924 ------w- c:\windows\system32\drivers\VC4CB104.SYS
2010-04-06 08:01 . 2010-04-06 08:01 -------- d-----w- c:\programmi\REGSHAVE
2010-04-06 08:01 . 2002-06-25 08:06 45056 ------w- c:\windows\system32\FINFCOPY.dll
2010-04-06 08:01 . 2002-02-27 11:27 65536 ------w- c:\windows\system32\FINFCHECK.dll
2010-04-06 08:01 . 2002-02-13 10:00 45056 ------w- c:\windows\system32\FCLKBTN.DLL
2010-04-06 08:01 . 2002-02-05 16:33 69632 ------w- c:\windows\system32\FREGSHEX.DLL
2010-03-24 08:04 . 2010-03-24 18:17 952768 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Adobe\Reader\9.3\ARM\25615\AdobeARM.exe
2010-03-24 08:04 . 2010-03-24 18:17 70584 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Adobe\Reader\9.3\ARM\25615\AdobeExtractFiles.dll
2010-03-24 08:04 . 2010-03-24 18:17 326056 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Adobe\Reader\9.3\ARM\25615\ReaderUpdater.exe
2010-03-24 08:04 . 2010-03-24 18:17 326056 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Adobe\Reader\9.3\ARM\25615\AcrobatUpdater.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-17 11:56 . 2009-02-18 17:05 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Skype
2010-04-17 09:16 . 2009-02-18 17:07 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\skypePM
2010-04-16 11:59 . 2009-02-13 13:37 -------- d-----w- c:\programmi\eMule
2010-04-15 17:03 . 2010-04-15 11:58 3356 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-04-15 17:03 . 2010-04-15 11:58 25244 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-04-15 06:20 . 2004-08-29 15:16 88758 ----a-w- c:\windows\system32\perfc010.dat
2010-04-15 06:20 . 2004-08-29 15:16 500338 ----a-w- c:\windows\system32\perfh010.dat
2010-04-14 19:42 . 2009-03-16 07:35 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\uTorrent
2010-04-13 07:49 . 2010-01-15 08:44 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Disk Cleaner
2010-04-13 07:48 . 2009-04-03 15:27 -------- d-----w- c:\programmi\Google
2010-04-08 13:28 . 2009-06-13 20:35 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\gtk-2.0
2010-04-06 08:03 . 2009-02-12 21:54 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-04-05 12:46 . 2009-03-18 13:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-04-03 13:13 . 2009-02-12 21:53 -------- d-----w- c:\programmi\File comuni\Java
2010-04-03 13:12 . 2009-06-17 06:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-25 06:28 . 2009-12-25 12:01 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Apple Computer
2010-03-22 05:55 . 2009-03-17 10:56 -------- d-----w- c:\programmi\uTorrent
2010-03-20 13:36 . 2009-02-13 08:35 67592 ----a-w- c:\documents and settings\fernanda mazzieri\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-12 06:27 . 2010-03-12 06:27 300616 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-12 06:27 . 2010-03-12 06:27 329312 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-12 06:27 . 2009-02-13 13:26 -------- d-----w- c:\programmi\File comuni\Real
2010-03-12 06:26 . 2010-03-12 06:26 -------- d-----w- c:\programmi\Real
2010-03-12 06:26 . 2010-03-12 06:26 -------- d-----w- c:\programmi\File comuni\xing shared
2010-03-12 06:25 . 2009-02-13 13:26 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-12 06:25 . 2009-02-13 13:26 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-03-10 06:15 . 2004-08-19 22:39 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-06 08:02 . 2010-03-06 08:02 155600 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-02-26 20:24 . 2010-02-26 20:24 -------- d-----w- c:\programmi\CCleaner
2010-02-25 06:16 . 2004-08-19 22:39 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-04 06:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:05 . 2004-08-19 22:34 2193664 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2004-08-19 09:00 2070528 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-15 21:58 . 2010-01-15 11:23 38784 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-13 14:14 . 2010-02-13 14:14 509 ----a-w- c:\documents and settings\fernanda mazzieri\KiweeChatbarCleanup.bat
2010-02-13 14:13 . 2010-02-13 14:13 298 ----a-w- c:\documents and settings\fernanda mazzieri\UnifiedToolbarCleanup.bat
2010-02-12 10:03 . 2010-03-06 07:32 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2004-08-19 22:39 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 06:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-01-25 17:01 . 2010-01-25 15:53 43646 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_BA42303DF6E9A82071196E.exe
2010-01-25 17:01 . 2010-01-25 15:53 29926 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_3C166BAD640EEF09D248BD.exe
2010-01-25 17:01 . 2010-01-25 15:53 43646 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_D707CE1C009F1381803C2C.exe
2010-01-25 17:01 . 2010-01-25 15:53 43646 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_A92E8E99C2D2589BBFDBFF.exe
2010-01-25 17:01 . 2010-01-25 15:53 43646 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_21F3885A18D238E15AAE81.exe
2010-01-25 17:01 . 2010-01-25 15:53 109534 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_6FEFF9B68218417F98F549.exe
2010-01-24 21:30 . 2010-01-24 21:30 503808 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5785977f-n\msvcp71.dll
2010-01-24 21:30 . 2010-01-24 21:30 499712 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5785977f-n\jmc.dll
2010-01-24 21:30 . 2010-01-24 21:30 348160 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5785977f-n\msvcr71.dll
2010-01-24 21:30 . 2010-01-24 21:30 61440 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7deacdc2-n\decora-sse.dll
2010-01-24 21:30 . 2010-01-24 21:30 12800 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7deacdc2-n\decora-d3d.dll
2010-01-21 16:10 . 2010-03-08 18:10 52224 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\components\FFExternalAlert.dll
2010-01-21 16:10 . 2010-03-08 18:10 101376 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\components\RadioWMPCore.dll
2010-01-21 15:20 . 2010-01-21 15:20 15328 ----a-w- c:\windows\system32\drivers\pssnap.sys
2010-01-21 15:20 . 2010-01-21 15:20 32736 ----a-w- c:\windows\system32\drivers\psmounter.sys
2010-01-21 14:30 . 2010-01-21 14:30 61440 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\decora-sse.dll
2010-01-21 14:30 . 2010-01-21 14:30 503808 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\msvcp71.dll
2010-01-21 14:30 . 2010-01-21 14:30 499712 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\jmc.dll
2010-01-21 14:30 . 2010-01-21 14:30 348160 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\msvcr71.dll
2010-01-21 14:30 . 2010-01-21 14:30 12800 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\decora-d3d.dll
2010-01-21 14:30 . 2010-01-21 14:30 114688 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-1a2fc121-n\jogl_cg.dll
2010-01-21 14:30 . 2010-01-21 14:30 315392 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-1a2fc121-n\jogl.dll
2010-01-21 14:30 . 2010-01-21 14:30 20480 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-1a2fc121-n\jogl_awt.dll
2010-01-21 14:30 . 2010-01-21 14:30 20480 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\45\4f710eed-3a55512c-n\gluegen-rt.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-26 08:36 1008896 ----a-w- c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
2009-12-24 13:32 2166296 ----a-w- c:\programmi\Mininova-Vuze\tbMin1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-10-19 15:15 1345336 ----a-w- c:\programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d51d388b-f5dc-471a-a1ce-5e2d671091c0}"= "c:\programmi\Mininova-Vuze\tbMin1.dll" [2009-12-24 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
"{D51D388B-F5DC-471A-A1CE-5E2D671091C0}"= "c:\programmi\Mininova-Vuze\tbMin1.dll" [2009-12-24 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Emule Installer"="c:\programmi\Emule Installer\EmuleInstaller.exe" [2008-11-28 484864]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2009-03-27 24103720]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-08-30 139264]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-29 39408]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-04-01 2010864]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe" [2009-04-29 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MAKTray"="MAKTray.exe" [2004-08-27 287232]
"SetRefresh"="c:\programmi\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-19 2046816]
"VX1000"="c:\windows\vVX1000.exe" [2006-10-13 707376]
"LifeCam"="c:\programmi\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SweetIM"="c:\programmi\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2010-03-12 202256]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"REGSHAVE"="c:\programmi\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
c:\documents and settings\fernanda mazzieri\Menu Avvio\Programmi\Esecuzione automatica\
Widget vodafone.lnk - c:\programmi\Widget vodafone.it\Widget vodafone.it.exe [2010-1-20 95232]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-23 06:44 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgtray.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgui.exe"=
"c:\\Programmi\\Spybot - Search & Destroy\\SpybotSD.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25:TCP"= 25:TCP:File and Printer Sharing
"2785:TCP"= 2785:TCP:ajyh
"8386:TCP"= 8386:TCP:ajyh
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [21/01/2010 17.20.50 15328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/02/2009 0.27.03 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/02/2009 0.27.09 108552]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 11.25.50 12872]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [17/02/2010 11.15.58 66632]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [13/02/2009 0.26.58 297752]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\programmi\Macrium\Reflect\ReflectService.exe [21/01/2010 17.20.24 220128]
R3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [17/02/2010 11.15.58 12872]
S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [29/06/2009 20.19.10 133104]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [16/03/2009 16.09.55 8192]
S2 wisc;WinInet Soap Connector Library;c:\windows\system32\rundll32.exe wisc.dll,ajyh --> c:\windows\system32\rundll32.exe wisc.dll,ajyh [?]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [21/01/2010 17.20.38 32736]
.
Contenuto della cartella 'Scheduled Tasks'
2010-04-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-04-17 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-29 12:04]
2010-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-29 18:19]
2010-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-29 18:19]
2010-04-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2970431553-3055220488-3798296123-1006.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-04-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2970431553-3055220488-3798296123-1006.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-04-17 c:\windows\Tasks\User_Feed_Synchronization-{76FC3D1D-6382-48BE-802E-60E3EA401460}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
2010-04-17 c:\windows\Tasks\User_Feed_Synchronization-{DFA0D97C-874A-4F53-9F03-4C8807B5D6FB}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
mStart Page = hxxp://www.forospyware.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
Trusted Zone: swzone.it\forum
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1978305&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Mininova-Vuze Customized Web Search
FF - prefs.js: browser.startup.homepage -
www.google.itFF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=it-it&FORM=MICI05&q=
FF - component: c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\components\RadioWMPCore.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-17 13:55
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"0140AC1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(652)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2216)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-04-17 13:58:06
ComboFix-quarantined-files.txt 2010-04-17 11:58
ComboFix2.txt 2010-04-17 11:41
ComboFix3.txt 2010-04-17 11:22
Pre-Run: 219.712.999.424 byte disponibili
Post-Run: 219.701.624.832 byte disponibili
- - End Of File - - 0EE3E089FD7D4CBE142DDBAD73CBE095
ecco il risultato
ComboFix 10-04-15.05 - fernanda mazzieri 17/04/2010 13.51.36.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1015.357 [GMT 2:00]
Eseguito da: c:\documents and settings\fernanda mazzieri\Documenti\Download\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Creati Da 2010-03-17 al 2010-04-17 )))))))))))))))))))))))))))))))))))
.
2010-04-17 07:31 . 2010-04-17 07:31 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Malwarebytes
2010-04-17 07:30 . 2010-03-29 13:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-17 07:30 . 2010-04-17 07:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-04-17 07:30 . 2010-04-17 07:30 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-04-17 07:30 . 2010-03-29 13:24 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-15 12:00 . 2010-04-15 12:01 125952 ----a-w- c:\documents and settings\All Users\Dati applicazioni\ParetoLogic\UUS2\Temp\Update.exe
2010-04-15 11:58 . 2010-04-15 17:03 24352 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-04-15 11:58 . 2010-04-15 17:03 1804576 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-04-15 09:44 . 2010-04-15 13:31 -------- d-----w- c:\programmi\File comuni\ParetoLogic
2010-04-15 09:44 . 2010-04-15 13:31 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\ParetoLogic
2010-04-15 09:43 . 2010-04-15 09:43 -------- d-----w- c:\documents and settings\fernanda mazzieri\Impostazioni locali\Dati applicazioni\Downloaded Installations
2010-04-13 13:07 . 2010-04-13 13:11 117760 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-04-13 13:07 . 2010-04-13 13:07 52224 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-04-13 13:07 . 2010-04-13 13:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2010-04-13 13:06 . 2010-04-13 13:06 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2010-04-13 07:49 . 2010-04-13 07:49 -------- d-----w- c:\windows\system32\wbem\Repository
2010-04-11 05:50 . 2010-04-13 13:06 -------- d-----w- c:\programmi\SUPERAntiSpyware
2010-04-11 05:50 . 2010-04-11 05:50 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\SUPERAntiSpyware.com
2010-04-06 12:54 . 2010-04-06 12:54 -------- d-----w- c:\programmi\File comuni\PCSuite
2010-04-06 12:54 . 2010-04-06 12:54 -------- d-----w- c:\programmi\File comuni\Nokia
2010-04-06 12:53 . 2010-04-06 12:53 -------- d-----w- c:\programmi\DIFX
2010-04-06 12:53 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-04-06 12:53 . 2010-04-06 12:53 -------- d-----w- c:\programmi\PC Connectivity Solution
2010-04-06 12:53 . 2009-02-09 05:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-04-06 12:53 . 2010-04-06 12:54 -------- d-----w- c:\programmi\Nokia
2010-04-06 12:52 . 2009-01-01 10:00 52048144 --s-a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\PC-Suite.exe
2010-04-06 12:52 . 2010-04-06 12:52 8192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-06 12:52 . 2010-04-06 12:52 61440 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-06 12:52 . 2010-04-06 12:52 10240 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-06 12:50 . 2010-04-06 12:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Installations
2010-04-06 09:12 . 2001-08-30 21:07 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-04-06 09:12 . 2008-04-14 01:13 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-04-06 08:12 . 2010-04-06 08:12 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\FUJIFILM
2010-04-06 08:07 . 2000-03-29 15:11 8096 ------w- c:\windows\system32\drivers\MASPINT.SYS
2010-04-06 08:07 . 1997-02-28 01:00 2486 ------w- c:\windows\system\AS16POST.BIN
2010-04-06 08:07 . 2010-04-06 08:07 -------- d-----w- C:\MWASPI
2010-04-06 08:03 . 2010-04-06 08:03 -------- d-----w- c:\programmi\PIXELA
2010-04-06 08:03 . 2004-02-04 23:29 380928 ----a-w- c:\windows\system32\FE05F3D7.dll
2010-04-06 08:03 . 2003-12-09 17:45 401408 ----a-w- c:\windows\system32\FE05F3D6.dll
2010-04-06 08:03 . 2003-08-26 08:54 401408 ----a-w- c:\windows\system32\FE05EFED.dll
2010-04-06 08:03 . 2003-06-25 15:24 299008 ----a-w- c:\windows\system32\FE05F051.dll
2010-04-06 08:03 . 2003-06-09 22:37 299008 ----a-w- c:\windows\system32\FE05F3D5.dll
2010-04-06 08:03 . 2003-06-02 20:50 299008 ----a-w- c:\windows\system32\FE05DA0D.dll
2010-04-06 08:03 . 2002-04-07 02:26 106496 ----a-w- c:\windows\system32\FPXS2Pro.dll
2010-04-06 08:02 . 2003-09-06 05:57 159744 ----a-w- c:\windows\system32\FFRAFLIB.DLL
2010-04-06 08:02 . 2003-09-03 05:45 274432 ----a-w- c:\windows\system32\FFTIFF16.dll
2010-04-06 08:01 . 2001-11-25 11:11 81924 ------w- c:\windows\system32\drivers\VC4CB104.SYS
2010-04-06 08:01 . 2010-04-06 08:01 -------- d-----w- c:\programmi\REGSHAVE
2010-04-06 08:01 . 2002-06-25 08:06 45056 ------w- c:\windows\system32\FINFCOPY.dll
2010-04-06 08:01 . 2002-02-27 11:27 65536 ------w- c:\windows\system32\FINFCHECK.dll
2010-04-06 08:01 . 2002-02-13 10:00 45056 ------w- c:\windows\system32\FCLKBTN.DLL
2010-04-06 08:01 . 2002-02-05 16:33 69632 ------w- c:\windows\system32\FREGSHEX.DLL
2010-03-24 08:04 . 2010-03-24 18:17 952768 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Adobe\Reader\9.3\ARM\25615\AdobeARM.exe
2010-03-24 08:04 . 2010-03-24 18:17 70584 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Adobe\Reader\9.3\ARM\25615\AdobeExtractFiles.dll
2010-03-24 08:04 . 2010-03-24 18:17 326056 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Adobe\Reader\9.3\ARM\25615\ReaderUpdater.exe
2010-03-24 08:04 . 2010-03-24 18:17 326056 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Adobe\Reader\9.3\ARM\25615\AcrobatUpdater.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-17 11:56 . 2009-02-18 17:05 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Skype
2010-04-17 09:16 . 2009-02-18 17:07 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\skypePM
2010-04-16 11:59 . 2009-02-13 13:37 -------- d-----w- c:\programmi\eMule
2010-04-15 17:03 . 2010-04-15 11:58 3356 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-04-15 17:03 . 2010-04-15 11:58 25244 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-04-15 06:20 . 2004-08-29 15:16 88758 ----a-w- c:\windows\system32\perfc010.dat
2010-04-15 06:20 . 2004-08-29 15:16 500338 ----a-w- c:\windows\system32\perfh010.dat
2010-04-14 19:42 . 2009-03-16 07:35 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\uTorrent
2010-04-13 07:49 . 2010-01-15 08:44 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Disk Cleaner
2010-04-13 07:48 . 2009-04-03 15:27 -------- d-----w- c:\programmi\Google
2010-04-08 13:28 . 2009-06-13 20:35 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\gtk-2.0
2010-04-06 08:03 . 2009-02-12 21:54 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-04-05 12:46 . 2009-03-18 13:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-04-03 13:13 . 2009-02-12 21:53 -------- d-----w- c:\programmi\File comuni\Java
2010-04-03 13:12 . 2009-06-17 06:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-25 06:28 . 2009-12-25 12:01 -------- d-----w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Apple Computer
2010-03-22 05:55 . 2009-03-17 10:56 -------- d-----w- c:\programmi\uTorrent
2010-03-20 13:36 . 2009-02-13 08:35 67592 ----a-w- c:\documents and settings\fernanda mazzieri\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-12 06:27 . 2010-03-12 06:27 300616 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-12 06:27 . 2010-03-12 06:27 118784 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-12 06:27 . 2010-03-12 06:27 329312 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-12 06:27 . 2009-02-13 13:26 -------- d-----w- c:\programmi\File comuni\Real
2010-03-12 06:26 . 2010-03-12 06:26 -------- d-----w- c:\programmi\Real
2010-03-12 06:26 . 2010-03-12 06:26 -------- d-----w- c:\programmi\File comuni\xing shared
2010-03-12 06:25 . 2009-02-13 13:26 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-12 06:25 . 2009-02-13 13:26 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-03-10 06:15 . 2004-08-19 22:39 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-06 08:02 . 2010-03-06 08:02 155600 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-02-26 20:24 . 2010-02-26 20:24 -------- d-----w- c:\programmi\CCleaner
2010-02-25 06:16 . 2004-08-19 22:39 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-04 06:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:05 . 2004-08-19 22:34 2193664 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2004-08-19 09:00 2070528 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-15 21:58 . 2010-01-15 11:23 38784 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-13 14:14 . 2010-02-13 14:14 509 ----a-w- c:\documents and settings\fernanda mazzieri\KiweeChatbarCleanup.bat
2010-02-13 14:13 . 2010-02-13 14:13 298 ----a-w- c:\documents and settings\fernanda mazzieri\UnifiedToolbarCleanup.bat
2010-02-12 10:03 . 2010-03-06 07:32 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2004-08-19 22:39 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 06:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-01-25 17:01 . 2010-01-25 15:53 43646 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_BA42303DF6E9A82071196E.exe
2010-01-25 17:01 . 2010-01-25 15:53 29926 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_3C166BAD640EEF09D248BD.exe
2010-01-25 17:01 . 2010-01-25 15:53 43646 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_D707CE1C009F1381803C2C.exe
2010-01-25 17:01 . 2010-01-25 15:53 43646 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_A92E8E99C2D2589BBFDBFF.exe
2010-01-25 17:01 . 2010-01-25 15:53 43646 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_21F3885A18D238E15AAE81.exe
2010-01-25 17:01 . 2010-01-25 15:53 109534 ----a-r- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Microsoft\Installer\{1DD377D6-FE55-40FA-B1C2-42DCB2E540A0}\_6FEFF9B68218417F98F549.exe
2010-01-24 21:30 . 2010-01-24 21:30 503808 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5785977f-n\msvcp71.dll
2010-01-24 21:30 . 2010-01-24 21:30 499712 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5785977f-n\jmc.dll
2010-01-24 21:30 . 2010-01-24 21:30 348160 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5785977f-n\msvcr71.dll
2010-01-24 21:30 . 2010-01-24 21:30 61440 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7deacdc2-n\decora-sse.dll
2010-01-24 21:30 . 2010-01-24 21:30 12800 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7deacdc2-n\decora-d3d.dll
2010-01-21 16:10 . 2010-03-08 18:10 52224 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\components\FFExternalAlert.dll
2010-01-21 16:10 . 2010-03-08 18:10 101376 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\components\RadioWMPCore.dll
2010-01-21 15:20 . 2010-01-21 15:20 15328 ----a-w- c:\windows\system32\drivers\pssnap.sys
2010-01-21 15:20 . 2010-01-21 15:20 32736 ----a-w- c:\windows\system32\drivers\psmounter.sys
2010-01-21 14:30 . 2010-01-21 14:30 61440 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\decora-sse.dll
2010-01-21 14:30 . 2010-01-21 14:30 503808 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\msvcp71.dll
2010-01-21 14:30 . 2010-01-21 14:30 499712 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\jmc.dll
2010-01-21 14:30 . 2010-01-21 14:30 348160 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\msvcr71.dll
2010-01-21 14:30 . 2010-01-21 14:30 12800 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-37e51d6c-n\decora-d3d.dll
2010-01-21 14:30 . 2010-01-21 14:30 114688 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-1a2fc121-n\jogl_cg.dll
2010-01-21 14:30 . 2010-01-21 14:30 315392 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-1a2fc121-n\jogl.dll
2010-01-21 14:30 . 2010-01-21 14:30 20480 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-1a2fc121-n\jogl_awt.dll
2010-01-21 14:30 . 2010-01-21 14:30 20480 ----a-w- c:\documents and settings\fernanda mazzieri\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\45\4f710eed-3a55512c-n\gluegen-rt.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-26 08:36 1008896 ----a-w- c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
2009-12-24 13:32 2166296 ----a-w- c:\programmi\Mininova-Vuze\tbMin1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-10-19 15:15 1345336 ----a-w- c:\programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d51d388b-f5dc-471a-a1ce-5e2d671091c0}"= "c:\programmi\Mininova-Vuze\tbMin1.dll" [2009-12-24 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
"{D51D388B-F5DC-471A-A1CE-5E2D671091C0}"= "c:\programmi\Mininova-Vuze\tbMin1.dll" [2009-12-24 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programmi\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Emule Installer"="c:\programmi\Emule Installer\EmuleInstaller.exe" [2008-11-28 484864]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2009-03-27 24103720]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-08-30 139264]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-29 39408]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-04-01 2010864]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe" [2009-04-29 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MAKTray"="MAKTray.exe" [2004-08-27 287232]
"SetRefresh"="c:\programmi\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-19 2046816]
"VX1000"="c:\windows\vVX1000.exe" [2006-10-13 707376]
"LifeCam"="c:\programmi\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SweetIM"="c:\programmi\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2010-03-12 202256]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"REGSHAVE"="c:\programmi\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
c:\documents and settings\fernanda mazzieri\Menu Avvio\Programmi\Esecuzione automatica\
Widget vodafone.lnk - c:\programmi\Widget vodafone.it\Widget vodafone.it.exe [2010-1-20 95232]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-23 06:44 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgtray.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgui.exe"=
"c:\\Programmi\\Spybot - Search & Destroy\\SpybotSD.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25:TCP"= 25:TCP:File and Printer Sharing
"2785:TCP"= 2785:TCP:ajyh
"8386:TCP"= 8386:TCP:ajyh
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [21/01/2010 17.20.50 15328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/02/2009 0.27.03 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/02/2009 0.27.09 108552]
R1 SASDIFSV;SASDIFSV;c:\programmi\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 11.25.50 12872]
R1 SASKUTIL;SASKUTIL;c:\programmi\SUPERAntiSpyware\SASKUTIL.SYS [17/02/2010 11.15.58 66632]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [13/02/2009 0.26.58 297752]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\programmi\Macrium\Reflect\ReflectService.exe [21/01/2010 17.20.24 220128]
R3 SASENUM;SASENUM;c:\programmi\SUPERAntiSpyware\SASENUM.SYS [17/02/2010 11.15.58 12872]
S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [29/06/2009 20.19.10 133104]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [16/03/2009 16.09.55 8192]
S2 wisc;WinInet Soap Connector Library;c:\windows\system32\rundll32.exe wisc.dll,ajyh --> c:\windows\system32\rundll32.exe wisc.dll,ajyh [?]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [21/01/2010 17.20.38 32736]
.
Contenuto della cartella 'Scheduled Tasks'
2010-04-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-04-17 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-29 12:04]
2010-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-29 18:19]
2010-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-06-29 18:19]
2010-04-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2970431553-3055220488-3798296123-1006.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-04-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2970431553-3055220488-3798296123-1006.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-04-17 c:\windows\Tasks\User_Feed_Synchronization-{76FC3D1D-6382-48BE-802E-60E3EA401460}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
2010-04-17 c:\windows\Tasks\User_Feed_Synchronization-{DFA0D97C-874A-4F53-9F03-4C8807B5D6FB}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
mStart Page = hxxp://www.forospyware.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
Trusted Zone: swzone.it\forum
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1978305&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Mininova-Vuze Customized Web Search
FF - prefs.js: browser.startup.homepage -
www.google.itFF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=it-it&FORM=MICI05&q=
FF - component: c:\documents and settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\fernanda mazzieri\Dati applicazioni\Mozilla\Firefox\Profiles\6jxeyzdk.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\components\RadioWMPCore.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-17 13:55
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"0140AC1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(652)
c:\programmi\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2216)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2010-04-17 13:58:06
ComboFix-quarantined-files.txt 2010-04-17 11:58
ComboFix2.txt 2010-04-17 11:41
ComboFix3.txt 2010-04-17 11:22
Pre-Run: 219.712.999.424 byte disponibili
Post-Run: 219.701.624.832 byte disponibili
- - End Of File - - 0EE3E089FD7D4CBE142DDBAD73CBE095