Ecco il log ,di combofix.Inoltre gentilmente potresti dirmi se è tutto a posto ,e se devo fare qualche altra cosa ,il problema e che avg ê sul desktop ma non funziona,anche se risulta tutto attivo..infine io della McAfee non ho mai installato nulla ,quindi non capisco come mai ci sono questi resti. grazie.
ComboFix 10-06-10.06 - globalservice 11/06/2010 18.20.46.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.39.1040.18.3066.1880 [GMT 2:00]
Eseguito da: c:\users\globalservice\Desktop\ComboFix.exe
Opzioni usate :: c:\users\globalservice\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 0 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Alcohol Soft
c:\program files\Alcohol Soft\Alcohol 120\ACID.exe
c:\program files\Alcohol Soft\Alcohol 120\Alcohol.exe
c:\program files\Alcohol Soft\Alcohol 120\alcohol.log
c:\program files\Alcohol Soft\Alcohol 120\Alcohol_.exe
c:\program files\Alcohol Soft\Alcohol 120\Alcoholx.dll
c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe
c:\program files\Alcohol Soft\Alcohol 120\AxDTA.exe
c:\program files\Alcohol Soft\Alcohol 120\AXShlEx.dll
c:\program files\Alcohol Soft\Alcohol 120\AxShlExHlper.exe
c:\program files\Alcohol Soft\Alcohol 120\AxSWdCPL.exe
c:\program files\Alcohol Soft\Alcohol 120\AxType.ini
c:\program files\Alcohol Soft\Alcohol 120\DevSupp.dll
c:\program files\Alcohol Soft\Alcohol 120\Help\ax_enu.chm
c:\program files\Alcohol Soft\Alcohol 120\imgengine.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_AR.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_BUL.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_CAT.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_Chs.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_Cht.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_CZ.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_DA.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_ES.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_FI.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_FR.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_GE.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_GR.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_HR.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_HU.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_IT.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_JPN.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_KR.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_MK.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_NL.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_NO.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_PL.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_PT.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_PT_BR.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_RU.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_SK.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_SLV.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_SR.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_SV.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_TR.dll
c:\program files\Alcohol Soft\Alcohol 120\Langs\AX_UA.dll
c:\program files\Alcohol Soft\Alcohol 120\pfctoc.dll
c:\program files\Alcohol Soft\Alcohol 120\pidalc.dll
c:\program files\Alcohol Soft\Alcohol 120\Plugins\AxSWind.dll
c:\program files\Alcohol Soft\Alcohol 120\Plugins\AxtraWd.dll
c:\program files\Alcohol Soft\Alcohol 120\Plugins\DPM.dll
c:\program files\Alcohol Soft\Alcohol 120\Plugins\DPMChart.dll
c:\program files\Alcohol Soft\Alcohol 120\Plugins\Helper\AxSrvUACHlper.exe
c:\program files\Alcohol Soft\Alcohol 120\Plugins\Helper\AxSwindHlp.dll
c:\program files\Alcohol Soft\Alcohol 120\Plugins\Helper\UACHlper.exe
c:\program files\Alcohol Soft\Alcohol 120\Plugins\NapalmBurn.dll
c:\program files\Alcohol Soft\Alcohol 120\star_syn_client.dll
c:\program files\Alcohol Soft\Alcohol 120\StarWind\config.xsd
c:\program files\Alcohol Soft\Alcohol 120\StarWind\license.txt
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindLite.cfg
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Alcohol Soft\Alcohol 120\uninst.exe
c:\program files\Alwil Software
c:\program files\Alwil Software\Avast5\Setup\setup.ini
c:\program files\Kaspersky Lab
c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\kis9cf.reg
c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\lic.ppl
c:\programdata\Alwil Software
c:\programdata\Kaspersky Lab Setup Files
c:\programdata\Kaspersky Lab
c:\programdata\Kaspersky Lab\AVP9\AVZData\bt.avz
c:\programdata\Kaspersky Lab\AVP9\AVZData\scu.avz
c:\programdata\Kaspersky Lab\AVP9\AVZData\tsw.avz
c:\programdata\Kaspersky Lab\AVP9\Encryption\containers.db
c:\programdata\Kaspersky Lab\AVP9\Temp\2EB2.tmp
c:\programdata\Kaspersky Lab\AVP9\Temp\3087.tmp
c:\programdata\Kaspersky Lab\AVP9\Temp\categories.db
c:\programdata\Kaspersky Lab\AVP9\Temp\E0EF.tmp
c:\programdata\Lavasoft
c:\programdata\Lavasoft\License\adaware.da2
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_StarWindServiceAE
-------\Service_StarWindServiceAE
((((((((((((((((((((((((( Files Creati Da 2010-05-11 al 2010-06-11 )))))))))))))))))))))))))))))))))))
.
2010-06-11 16:31 . 2010-06-11 16:35 -------- d-----w- c:\users\globalservice\AppData\Local\temp
2010-06-11 16:31 . 2010-06-11 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-06-11 16:31 . 2010-06-11 16:31 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-06-11 16:31 . 2010-06-11 16:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-11 16:15 . 2010-06-11 16:17 -------- d-----w- C:\32788R22FWJFW
2010-06-10 19:17 . 2010-06-10 19:17 -------- d-----w- c:\programdata\Comodo Downloader
2010-06-10 18:54 . 2010-06-10 18:54 -------- d-----w- c:\users\globalservice\AppData\Roaming\AVG9
2010-06-10 18:17 . 2010-04-05 16:07 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-10 18:17 . 2010-05-26 16:16 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-10 18:17 . 2010-05-26 14:25 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-10 18:17 . 2010-05-04 18:42 833024 ----a-w- c:\windows\system32\wininet.dll
2010-06-07 19:27 . 2010-06-07 19:27 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Zattoo
2010-06-07 18:07 . 2010-06-07 18:07 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\TuneUp Software
2010-06-07 17:28 . 2010-06-07 17:28 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes
2010-06-07 08:38 . 2010-06-08 11:41 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
2010-06-05 14:44 . 2010-06-05 15:27 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Adobe
2010-06-04 20:04 . 2010-06-04 20:04 -------- d-----w- C:\$AVG
2010-06-04 19:57 . 2010-06-04 19:57 -------- d-----w- c:\users\globalservice\AppData\Roaming\Symantec
2010-06-04 19:57 . 2010-06-04 19:57 -------- d-----w- c:\users\globalservice\AppData\Local\Symantec_Corporation
2010-06-04 19:56 . 2010-06-04 19:56 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-04 19:33 . 2010-06-04 19:33 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2010-06-04 19:28 . 2010-06-04 19:28 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Symantec
2010-06-04 19:28 . 2010-06-04 19:28 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Symantec_Corporation
2010-06-03 22:00 . 2010-06-03 22:00 -------- d-----w- c:\program files\Symantec
2010-06-03 21:59 . 2009-10-01 20:03 131000 ----a-w- c:\windows\system32\drivers\WimFltr.sys
2010-06-03 21:52 . 2010-06-03 21:52 -------- d-----w- C:\5b344792d01785a6a881690f
2010-06-03 21:51 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-03 21:51 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-06-03 21:51 . 2010-06-04 21:11 -------- d-----w- c:\program files\Norton Ghost
2010-06-03 21:51 . 2010-06-04 21:11 -------- d-----w- c:\programdata\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3}
2010-06-03 21:39 . 2010-06-11 11:16 -------- d-----w- c:\windows\system32\drivers\Avg
2010-06-03 21:39 . 2010-06-07 17:28 -------- d-----w- c:\programdata\AVG Security Toolbar
2010-06-03 21:39 . 2010-06-04 19:56 25096 ----a-w- c:\windows\system32\drivers\AVGIDSvx.sys
2010-06-03 21:39 . 2010-06-04 19:54 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-06-03 21:39 . 2010-06-04 19:56 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-03 21:39 . 2010-06-04 19:54 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-03 21:39 . 2010-06-04 19:56 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-06-03 21:38 . 2010-06-04 19:54 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2010-06-03 21:38 . 2010-06-03 21:38 -------- d-----w- c:\programdata\avg9
2010-06-03 21:38 . 2010-06-03 21:38 -------- d-----w- c:\program files\AVG
2010-06-03 09:36 . 2010-06-03 09:36 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\PowerCinema
2010-05-29 19:31 . 2010-05-29 19:31 552 ----a-w- c:\users\globalservice\AppData\Local\d3d8caps.dat
2010-05-28 15:48 . 2010-05-28 16:21 -------- d-----w- c:\program files\NVIDIA Corporation
2010-05-28 15:33 . 2010-05-28 15:33 -------- d-----w- C:\NVIDIA
2010-05-19 17:37 . 2010-05-18 18:36 262144 ----a-w- c:\program files\Uninstall Ask Toolbar.dll
2010-05-18 18:36 . 2010-05-18 18:36 249592 ----a-w- c:\windows\system32\cssdll32.dll
2010-05-18 18:31 . 2010-05-19 07:47 -------- d-----w- c:\users\globalservice\AppData\Roaming\Comodo
2010-05-18 18:08 . 2010-05-18 18:08 -------- d-----w- c:\programdata\Prevx
2010-05-14 13:47 . 2010-05-14 13:47 -------- d-----w- c:\users\globalservice\AppData\Roaming\dvdcss
2010-05-14 09:23 . 2010-05-14 09:23 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-05-13 22:43 . 2010-05-14 09:31 -------- d-----w- c:\users\globalservice\AppData\Roaming\Vso
2010-05-13 21:56 . 2010-01-29 16:21 738304 ----a-w- c:\windows\system32\inetcomm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-11 16:35 . 2010-06-03 20:04 78493 ----a-w- c:\programdata\nvModes.dat
2010-06-11 15:56 . 2008-12-20 08:46 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-10 21:40 . 2008-11-17 18:08 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-06-10 18:47 . 2008-05-08 06:57 662862 ----a-w- c:\windows\system32\perfh010.dat
2010-06-10 18:47 . 2008-05-08 06:57 120326 ----a-w- c:\windows\system32\perfc010.dat
2010-06-09 16:21 . 2010-04-16 18:52 -------- d-----w- c:\program files\SpywareBlaster
2010-06-06 17:17 . 2008-05-07 21:13 -------- d-----w- c:\program files\Acer GameZone
2010-06-04 21:12 . 2008-11-12 19:26 -------- d-----w- c:\programdata\Symantec
2010-06-04 20:24 . 2010-06-04 20:24 3581208 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2010-06-04 19:57 . 2010-06-04 19:57 356616 ----a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-06-04 19:57 . 2010-06-04 19:57 74760 ----a-w- c:\programdata\avg9\update\backup\UniversalDD.sys
2010-06-04 19:57 . 2010-06-04 19:57 30216 ----a-w- c:\programdata\avg9\update\backup\AVGIDSFilter.sys
2010-06-04 19:57 . 2010-06-04 19:57 28424 ----a-w- c:\programdata\avg9\update\backup\avgmfx86.sys
2010-06-04 19:57 . 2010-06-04 19:57 27800 ----a-w- c:\programdata\avg9\update\backup\AVGIDSShim.sys
2010-06-04 19:57 . 2010-06-04 19:57 25608 ----a-w- c:\programdata\avg9\update\backup\AVGIDSvx.sys
2010-06-04 19:57 . 2010-06-04 19:57 122376 ----a-w- c:\programdata\avg9\update\backup\AVGIDSDriver.sys
2010-06-04 19:57 . 2010-06-04 19:57 333192 ----a-w- c:\programdata\avg9\update\backup\avgldx86.sys
2010-06-04 19:57 . 2010-06-04 19:57 29464 ----a-w- c:\programdata\avg9\update\backup\avgfwd6a.sys
2010-06-04 19:57 . 2010-06-04 19:57 23832 ----a-w- c:\programdata\avg9\update\backup\avgfwd6x.sys
2010-06-04 19:57 . 2010-06-04 19:57 161672 ----a-w- c:\programdata\avg9\update\backup\avgrkx86.sys
2010-06-03 21:39 . 2010-06-04 19:52 875288 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
2010-06-03 21:39 . 2010-06-04 19:52 1656088 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-06-03 21:39 . 2010-06-04 19:52 798488 ----a-w- c:\programdata\avg9\update\backup\avginet.dll
2010-06-03 21:39 . 2010-06-04 19:52 610072 ----a-w- c:\programdata\avg9\update\backup\avgiproxy.exe
2010-06-03 20:05 . 2008-10-29 21:16 -------- d-----w- c:\programdata\NVIDIA
2010-06-03 19:57 . 2010-03-13 09:14 -------- d-----w- c:\users\globalservice\AppData\Roaming\vlc
2010-06-03 19:57 . 2010-03-09 20:02 -------- d-----w- c:\program files\Zattoo4
2010-06-03 19:46 . 2006-11-02 13:02 9268 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\d3d9caps.dat
2010-06-03 09:36 . 2008-10-29 21:10 105920 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-30 15:28 . 2010-03-28 21:54 -------- d-----w- c:\users\globalservice\AppData\Roaming\Nitro PDF
2010-05-29 21:34 . 2010-03-04 18:49 -------- d-----w- c:\programdata\Lx_cats
2010-05-29 19:32 . 2008-11-03 21:42 1356 ----a-w- c:\users\globalservice\AppData\Local\d3d9caps.dat
2010-05-25 21:28 . 2009-02-28 13:18 1 ----a-w- c:\users\globalservice\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-24 18:47 . 2008-10-29 21:21 -------- d-----w- c:\program files\Launch Manager
2010-05-16 20:46 . 2010-05-16 20:46 12 ----a-w- c:\windows\system32\DROPPEDFILEOKgfx3.tmp
2010-05-14 22:05 . 2009-12-01 18:55 -------- d-----w- c:\users\globalservice\AppData\Roaming\muvee Technologies
2010-05-14 09:31 . 2010-05-13 22:43 81920 ----a-w- c:\users\globalservice\AppData\Roaming\ezpinst.exe
2010-05-14 09:31 . 2010-05-13 22:43 81920 ----a-w- c:\users\globalservice\AppData\Roaming\ezpinst.exe
2010-05-14 09:31 . 2010-05-13 22:43 47360 ----a-w- c:\users\globalservice\AppData\Roaming\pcouffin.sys
2010-05-14 09:31 . 2010-05-13 22:43 47360 ----a-w- c:\users\globalservice\AppData\Roaming\pcouffin.sys
2010-05-14 09:21 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-13 23:46 . 2010-03-12 20:09 -------- d-----w- c:\program files\Super Internet TV
2010-05-04 18:37 . 2010-06-10 18:16 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 16:53 . 2010-06-10 18:16 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 13:53 . 2010-06-10 18:16 2036224 ----a-w- c:\windows\system32\win32k.sys
2010-05-01 10:40 . 2009-09-20 09:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-04-29 20:32 . 2009-09-12 17:08 -------- d-----w- c:\users\globalservice\AppData\Roaming\GetRightToGo
2010-04-23 13:55 . 2010-06-10 18:16 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-16 16:10 . 2010-06-10 18:16 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-03-28 21:39 . 2008-11-11 09:19 432 ----a-w- c:\users\globalservice\AppData\Roaming\wklnhst.dat
2010-03-26 22:31 . 2010-03-26 22:31 7168 ----a-w- c:\windows\system32\drivers\utm4njy1.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-10-29 12:43 . 2008-10-29 12:42 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 08:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 22:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2008-12-09 495616]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-22 1037608]
"RtHDVCpl"="RtHDVCpl.exe" [2008-08-07 6265376]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-07-25 809480]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-03-07 544768]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-04-30 397312]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-04-10 147456]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-03 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-03 92704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"USBToolTip"=c:\progra~1\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"WarReg_PopUp"=c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
"PrinTray"=c:\windows\system32\spool\DRIVERS\W32X86\3\printray.exe
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"Lexmark 6500 Series Fax Server"="c:\program files\Lexmark 6500 Series\fm3032.exe" /s
"lxdfamon"="c:\program files\Lexmark 6500 Series\lxdfamon.exe"
"lxdfmon.exe"="c:\program files\Lexmark 6500 Series\lxdfmon.exe"
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1815193764-2899108687-2117010896-1000]
"EnableNotificationsRef"=dword:00000001
R2 gupdate1c9b9fffb8cd680;Google Update Service (gupdate1c9b9fffb8cd680);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-10 133104]
R2 lxdfCATSCustConnectService;lxdfCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdfserv.exe [2007-05-29 99248]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [x]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
R3 cmusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2051;c:\windows\system32\DRIVERS\cmusbser.sys [2008-09-01 103552]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-12 84240]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [x]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-03-19 136704]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-03-19 8320]
R3 utm4njy1;AVZ Kernel Driver;c:\windows\system32\Drivers\utm4njy1.sys [2010-03-26 7168]
R4 lxdf_device;lxdf_device;c:\windows\system32\lxdfcoms.exe [2007-05-29 598960]
R4 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-05-14 691696]
S0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\System32\Drivers\AVGIDSvx.sys [2010-06-04 25096]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-06-04 52872]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-06-04 24856]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-06-04 216200]
S1 AvgTdiX;AVG Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-06-04 242896]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-04-18 61424]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-06-04 916760]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-04 308064]
S2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-06-04 2331544]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
S2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [2009-04-02 135168]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
S2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [2009-09-15 188736]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
S2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2008-01-10 233472]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-02-11 172328]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-02-25 1047880]
S3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-06-04 122376]
S3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-06-04 30216]
S3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-06-04 27144]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-04-03 43552]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenuto della cartella 'Scheduled Tasks'
2010-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-10 17:15]
2010-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-10 17:15]
2010-06-11 c:\windows\Tasks\User_Feed_Synchronization-{2916B595-576A-4ACD-9704-CC8F49211E42}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = local
FF - ProfilePath - c:\users\globalservice\AppData\Roaming\Mozilla\Firefox\Profiles\z9gna6mg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - mipony-plugin Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2465030&SearchSource=13
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-11 18:35
Windows 6.0.6001 Service Pack 1 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'Explorer.exe'(1304)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\System32\SysHook.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\Launch Manager\LManager.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\ASTSRV.EXE
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Power Translator 11\LogoMedia TranslateDotNet Server.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Ora fine scansione: 2010-06-11 18:45:19 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-06-11 16:45
ComboFix2.txt 2010-06-08 22:29
Pre-Run: 18.712.268.800 byte disponibili
Post-Run: 18.162.614.272 byte disponibili
- - End Of File - - 373863E68418CD4F4F9E167612FD07AD