ciao r16, ecco il log
ComboFix 10-06-26.03 - Administrator 27/06/2010 22:50:44.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.39.1040.18.2038.1185 [GMT 2:00]
Eseguito da: c:\users\Administrator\Desktop\ComboFix.exe
Opzioni usate :: c:\users\Administrator\Desktop\CFScript.txt
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((( Files Creati Da 2010-05-27 al 2010-06-27 )))))))))))))))))))))))))))))))))))
.
2010-06-27 20:54 . 2010-06-27 20:54 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-06-27 14:22 . 2010-06-27 14:22 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-06-27 11:47 . 2010-06-27 11:47 -------- d-----w- c:\users\Administrator\AppData\Roaming\Malwarebytes
2010-06-27 11:46 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-27 11:46 . 2010-06-27 11:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-27 11:46 . 2010-06-27 11:46 -------- d-----w- c:\programdata\Malwarebytes
2010-06-27 11:46 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-27 07:43 . 2010-06-27 07:43 -------- d-----w- c:\program files\Trend Micro
2010-06-26 10:08 . 2010-06-26 10:09 -------- d-----w- c:\users\Administrator\AppData\Local\Abelssoft
2010-06-26 10:08 . 2010-06-26 10:08 -------- d-----w- c:\program files\CheckDrive
2010-06-26 08:54 . 2010-06-26 17:00 -------- d-----w- c:\users\Administrator\AppData\Roaming\vlc
2010-06-25 21:39 . 2010-06-25 21:39 -------- d-----w- c:\users\Administrator\AppData\Local\Xenocode
2010-06-25 21:39 . 2010-06-25 21:39 -------- d-----w- c:\program files\Xenocode
2010-06-24 21:51 . 2010-06-24 21:51 -------- d-----w- c:\users\Administrator\AppData\Roaming\FDRLab
2010-06-24 21:38 . 2010-06-24 21:38 -------- d-----w- C:\Cybia
2010-06-23 07:18 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 07:18 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 07:18 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 07:18 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 07:18 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-22 15:28 . 2010-06-22 15:28 -------- d-----w- c:\users\Administrator\AppData\Roaming\Avira
2010-06-22 15:18 . 2010-06-22 15:31 97608 ----a-w- c:\windows\system32\drivers\avfwot.sys
2010-06-22 15:18 . 2010-06-22 15:31 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-06-22 15:18 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-06-22 15:18 . 2009-02-24 11:06 69632 ----a-w- c:\windows\system32\drivers\avfwim.sys
2010-06-22 15:18 . 2010-06-22 15:18 -------- d-----w- c:\programdata\Avira
2010-06-22 15:18 . 2010-06-22 15:18 -------- d-----w- c:\program files\Avira
2010-06-20 07:44 . 2010-06-20 07:44 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-06-20 07:44 . 2010-06-20 07:44 -------- d-----w- c:\program files\Microsoft.NET
2010-06-20 07:41 . 2010-06-20 07:41 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-06-20 07:40 . 2010-06-20 07:40 -------- d-----r- C:\MSOCache
2010-06-19 15:04 . 2010-06-24 12:25 -------- d-----w- c:\users\Administrator\AppData\Roaming\uTorrent
2010-06-16 18:10 . 2010-06-16 18:10 -------- d-----w- c:\users\Administrator\AppData\Roaming\dvdcss
2010-06-15 07:35 . 2010-06-23 21:40 -------- d-----w- c:\users\Administrator\AppData\Roaming\Nitro PDF
2010-06-15 07:34 . 2010-06-07 13:37 17712 ----a-w- c:\windows\system32\nitrolocalui.dll
2010-06-15 07:34 . 2010-06-07 13:37 26416 ----a-w- c:\windows\system32\nitrolocalmon.dll
2010-06-15 07:34 . 2010-06-15 07:34 -------- d-----w- c:\programdata\Nitro PDF
2010-06-15 07:34 . 2010-06-15 07:34 -------- d-----w- c:\program files\Common Files\Nitro PDF
2010-06-15 07:34 . 2010-06-15 07:34 -------- d-----w- c:\program files\Nitro PDF
2010-06-15 07:33 . 2010-06-15 07:33 -------- d-----w- c:\users\Administrator\AppData\Roaming\Downloaded Installations
2010-06-14 13:41 . 2007-08-31 10:52 56496 ----a-w- c:\windows\system32\wbhelp2.dll
2010-06-14 13:41 . 2007-08-31 10:52 33968 ----a-w- c:\windows\system32\anim.dll
2010-06-14 13:41 . 2004-12-07 08:11 258352 ----a-w- c:\windows\system32\unicows.dll
2010-06-14 13:41 . 2001-08-24 06:25 1706800 ----a-w- c:\windows\system32\gdiplus.dll
2010-06-14 13:41 . 1999-11-22 13:50 4608 ----a-w- c:\windows\system32\W95INF32.DLL
2010-06-14 13:41 . 1999-11-22 13:50 2272 ----a-w- c:\windows\system32\W95INF16.DLL
2010-06-14 12:50 . 2010-06-14 12:50 -------- d-----w- c:\users\Administrator\AppData\Roaming\Tracker Software
2010-06-12 15:22 . 2010-06-12 15:22 -------- d-----w- c:\windows\Sun
2010-06-12 15:06 . 2010-06-12 15:19 -------- d-----w- c:\users\Administrator\AppData\Roaming\freeTVRadio
2010-06-12 15:06 . 2010-06-27 14:56 -------- d-----w- c:\users\Administrator\AppData\Roaming\OfferBox
2010-06-12 07:34 . 2010-06-12 07:34 -------- d-----w- c:\users\Administrator\AppData\Local\NeoSmart_Technologies
2010-06-12 07:34 . 2010-06-12 07:34 -------- d-----w- c:\program files\NeoSmart Technologies
2010-06-09 09:04 . 2010-06-25 21:39 -------- d-----w- c:\windows\XSxS
2010-06-09 07:58 . 2010-06-16 15:37 -------- d-----w- c:\users\Administrator\AppData\Roaming\Thinstall
2010-06-09 07:58 . 2010-06-09 07:58 -------- d-----w- c:\users\Administrator\AppData\Local\Thinstall
2010-06-09 07:00 . 2010-05-21 05:18 977920 ----a-w- c:\windows\system32\wininet.dll
2010-06-09 07:00 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-09 07:00 . 2010-05-01 14:49 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-06-09 07:00 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-09 07:00 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-06-03 09:07 . 2010-06-03 09:07 -------- d-----w- c:\users\Administrator\AppData\Roaming\Nero
2010-06-03 08:29 . 2010-06-03 08:29 -------- d-----w- c:\program files\Common Files\Nero
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-27 20:56 . 2009-12-15 13:32 -------- d-----w- c:\program files\cFosSpeed
2010-06-27 13:58 . 2009-07-14 08:21 691004 ----a-w- c:\windows\system32\perfh010.dat
2010-06-27 13:58 . 2009-07-14 08:21 125044 ----a-w- c:\windows\system32\perfc010.dat
2010-06-26 14:40 . 2009-12-15 13:26 -------- d-----w- c:\users\Administrator\AppData\Roaming\SolidDocuments
2010-06-25 15:32 . 2009-12-14 15:55 -------- d-----w- c:\programdata\Microsoft Help
2010-06-24 12:31 . 2010-05-17 13:46 -------- d-----w- c:\program files\Power Translator 14
2010-06-24 12:28 . 2009-12-14 15:55 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-06-24 12:28 . 2009-12-14 15:13 -------- d-----w- c:\programdata\avg9
2010-06-22 07:34 . 2010-04-29 20:00 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-06-21 07:53 . 2009-12-15 13:12 -------- d-----w- c:\users\Administrator\AppData\Roaming\VSO
2010-06-20 07:54 . 2009-12-14 14:31 111576 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-20 07:44 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-06-20 07:44 . 2010-04-24 17:11 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-06-16 14:09 . 2010-05-22 15:38 -------- d-----w- c:\program files\VDownloader
2010-06-14 15:56 . 2009-12-14 16:19 -------- d-----w- c:\program files\EPSON
2010-06-14 15:56 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Sidebar
2010-06-05 06:54 . 2010-04-24 16:59 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-30 16:46 . 2009-12-14 14:56 -------- d-----w- c:\users\Administrator\AppData\Roaming\IObit
2010-05-30 16:45 . 2010-05-17 13:10 -------- d-----w- c:\program files\IncrediMail
2010-05-30 15:15 . 2010-04-24 14:46 -------- d-----w- c:\program files\CCleaner
2010-05-26 16:50 . 2010-05-26 16:49 -------- d-----w- c:\program files\EasyPicture2Icon
2010-05-26 07:16 . 2010-04-24 17:00 -------- d-----w- c:\program files\Microsoft
2010-05-22 22:07 . 2010-05-22 22:07 -------- d-----w- c:\program files\Windows Mail
2010-05-22 22:07 . 2010-05-22 22:07 -------- d-----w- c:\program files\Windows Mail.old
2010-05-22 16:21 . 2010-05-22 16:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-05-22 16:21 . 2010-05-22 16:21 -------- d-----w- c:\program files\Java
2010-05-22 15:59 . 2010-05-22 15:52 -------- d-----w- c:\users\Administrator\AppData\Roaming\Orbit
2010-05-22 15:52 . 2010-05-22 15:52 -------- d-----w- c:\users\Administrator\AppData\Roaming\GrabPro
2010-05-22 14:14 . 2009-09-13 19:23 811520 ----a-w- c:\windows\system32\user32.dll
2010-05-22 13:25 . 2010-05-24 16:01 52224 ----a-w- c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\f9nxwhaw.default\extensions\{681322c2-653e-4791-9ba1-c10a20c3c793}\components\FFExternalAlert.dll
2010-05-22 13:25 . 2010-05-24 16:01 101376 ----a-w- c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\f9nxwhaw.default\extensions\{681322c2-653e-4791-9ba1-c10a20c3c793}\components\RadioWMPCore.dll
2010-05-21 12:14 . 2009-10-30 14:12 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-17 14:26 . 2010-05-17 14:26 63488 ----a-w- c:\users\Administrator\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-05-17 14:26 . 2010-04-29 20:01 117760 ----a-w- c:\users\Administrator\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-05-17 14:15 . 2010-05-17 14:15 -------- d-----w- c:\program files\EASEUS
2010-05-17 13:46 . 2010-05-17 13:46 -------- d-----w- c:\users\Administrator\AppData\Roaming\LEC
2010-05-17 12:32 . 2009-12-15 17:26 -------- d-----w- c:\program files\VS Revo Group
2010-05-17 12:21 . 2010-05-17 12:21 43646 ----a-r- c:\users\Administrator\AppData\Roaming\Microsoft\Installer\{DB35267F-B5C6-495C-8407-75ADC34E759D}\_D707CE1C009F1381803C2C.exe
2010-05-17 12:21 . 2010-05-17 12:21 43646 ----a-r- c:\users\Administrator\AppData\Roaming\Microsoft\Installer\{DB35267F-B5C6-495C-8407-75ADC34E759D}\_33E47820CFD4F5D3775329.exe
2010-05-17 12:21 . 2010-05-17 12:21 43646 ----a-r- c:\users\Administrator\AppData\Roaming\Microsoft\Installer\{DB35267F-B5C6-495C-8407-75ADC34E759D}\_25E0DDF4BB5DA2E0BB26B4.exe
2010-05-17 12:21 . 2010-05-17 12:21 43646 ----a-r- c:\users\Administrator\AppData\Roaming\Microsoft\Installer\{DB35267F-B5C6-495C-8407-75ADC34E759D}\_21F3885A18D238E15AAE81.exe
2010-05-17 12:21 . 2010-05-17 12:21 29926 ----a-r- c:\users\Administrator\AppData\Roaming\Microsoft\Installer\{DB35267F-B5C6-495C-8407-75ADC34E759D}\_EABE28F7A0A98A84188A78.exe
2010-05-17 12:21 . 2010-05-17 12:21 109534 ----a-r- c:\users\Administrator\AppData\Roaming\Microsoft\Installer\{DB35267F-B5C6-495C-8407-75ADC34E759D}\_6FEFF9B68218417F98F549.exe
2010-05-17 12:21 . 2010-05-17 12:21 -------- d-----w- c:\program files\Macrium
2010-04-29 20:01 . 2010-04-29 20:01 52224 ----a-w- c:\users\Administrator\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-04-29 20:00 . 2010-04-29 20:00 -------- d-----w- c:\users\Administrator\AppData\Roaming\SUPERAntiSpyware.com
2010-04-29 19:59 . 2010-04-29 19:59 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-04-26 20:10 . 2010-05-17 14:15 1718912 ----a-w- c:\windows\system32\BootMan.exe
2010-04-23 07:13 . 2010-05-26 07:16 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-10 02:18 . 2010-05-22 15:38 2131336 ----a-w- c:\program files\Common Files\AskToolbarInstaller.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
------- Sigcheck -------
[-] 2010-05-22 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
.
(((((((((((((((((((((((((((((
SnapShot@2010-06-27_16.17.29 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-12-14 14:15 . 2010-06-27 15:53 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-14 14:15 . 2010-06-27 20:56 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-14 14:15 . 2010-06-27 15:53 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-14 14:15 . 2010-06-27 20:56 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:41 . 2010-06-27 15:53 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:41 . 2010-06-27 20:56 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-27 13:51 . 2010-06-27 20:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-06-27 13:51 . 2010-06-27 13:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-06-27 13:51 . 2010-06-27 20:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-06-27 13:51 . 2010-06-27 13:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2010-02-28 00:20 561552 ----a-w- c:\progra~1\Microsoft Office\Office14\URLREDIR.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2008-02-25 243072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-30 7289376]
"MemoREX"="f:\programmi\MemoRex\MemoRexStart.exe" [2003-07-29 332288]
"cFosSpeed"="c:\program files\cFosSpeed\cFosSpeed.exe" [2007-08-22 854992]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 12:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-02-23 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-02-23 8456]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [2010-03-17 44512]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-05-17 12872]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-22 1343400]
S0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\DRIVERS\pssnap.sys [2010-03-17 15328]
S1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys [2010-06-22 97608]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-05-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-05-31 67656]
S2 AntiVirFirewallService;Avira Firewall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [2010-06-22 388865]
S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [2010-06-22 194817]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-06-22 108289]
S2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-06-22 434945]
S2 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool;c:\program files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [2010-06-07 196912]
S2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2010-03-17 220128]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\l160x86.sys [2009-10-13 49152]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys [2009-02-24 69632]
S3 KMWDFILTERx86;HIDServiceDesc;c:\windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 25088]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
IE: E&sporta in Microsoft Excel - c:\progra~1\Microsoft Office\Office14\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~1\Microsoft Office\Office14\ONBttnIE.dll/105
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\f9nxwhaw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2637690&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Fissa
FF - prefs.js: browser.startup.homepage - hxxp://www.virgilio.it/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\f9nxwhaw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\f9nxwhaw.default\extensions\{681322c2-653e-4791-9ba1-c10a20c3c793}\components\FFExternalAlert.dll
FF - component: c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\f9nxwhaw.default\extensions\{681322c2-653e-4791-9ba1-c10a20c3c793}\components\RadioWMPCore.dll
FF - plugin: c:\progra~1\Microsoft Office\Office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\Microsoft Office\Office14\NPSPWRAP.DLL
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Tracker Software\PDF-XChange Viewer\pdf-viewer\npPDFXCviewNPPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\AUDIODG.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\cFosSpeed\spd.exe
c:\program files\Power Translator 14\LogoMedia TranslateDotNet Server.exe
c:\program files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\conhost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
f:\programmi\MemoRex\MemoRex.exe
c:\program files\IncrediMail\bin\ImApp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Ora fine scansione: 2010-06-27 22:59:22 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-06-27 20:59
ComboFix2.txt 2010-06-27 16:20
Pre-Run: 36.236.599.296 byte disponibili
Post-Run: 36.095.160.320 byte disponibili
- - End Of File - - 8BD1D202268B2637796546D91D24D3C5
grazie