ComboFix 10-07-31.04 - Compaq_Proprietario 01/08/2010 23.22.12.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1534.1010 [GMT 2:00]
Eseguito da: c:\documents and settings\Compaq_Proprietario\Documenti\Download\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Compaq_Proprietario\Dati applicazioni\EurekaLog
c:\documents and settings\Compaq_Proprietario\Documenti\A0042534.dll
c:\windows\system32\Thumbs.db
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Creati Da 2010-07-01 al 2010-08-01 )))))))))))))))))))))))))))))))))))
.
2010-08-01 13:28 . 2010-08-01 13:51 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2010-07-31 19:55 . 2010-07-31 19:55 -------- d-----w- c:\programmi\File comuni\Java
2010-07-31 18:10 . 2010-07-31 18:10 -------- d-----w- c:\programmi\CCleaner
2010-07-31 09:54 . 2010-07-31 09:54 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Malwarebytes
2010-07-31 09:53 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-31 09:53 . 2010-07-31 09:53 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-07-31 09:53 . 2010-07-31 09:54 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-07-31 09:53 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 22:05 . 2010-07-29 16:01 85464 ----a-w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Mozilla\Firefox\Profiles\6iu7pzsf.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
2010-07-30 22:05 . 2010-07-29 16:01 38872 ----a-w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Mozilla\Firefox\Profiles\6iu7pzsf.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINCE\components\WeaveCrypto.dll
2010-07-30 21:56 . 2010-07-30 21:56 388096 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-30 21:11 . 2010-07-30 21:11 -------- d-----w- c:\programmi\Trend Micro
2010-07-30 17:00 . 2010-07-30 17:02 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\dvdcss
2010-07-26 20:10 . 2004-08-19 03:00 5632 ----a-w- c:\windows\system32\dllcache\smimsgif.dll
2010-07-26 20:10 . 2004-08-19 03:00 5632 ----a-w- c:\windows\system32\dllcache\smierrsy.dll
2010-07-26 20:10 . 2004-08-19 03:00 15872 ----a-w- c:\windows\system32\dllcache\smierrsm.dll
2010-07-26 20:10 . 2004-08-19 03:00 10240 ----a-w- c:\windows\system32\wbem\snmpstup.dll
2010-07-26 20:10 . 2004-08-19 03:00 10240 ----a-w- c:\windows\system32\dllcache\snmpstup.dll
2010-07-25 14:17 . 2010-07-25 14:17 -------- d-----w- c:\programmi\eMule
2010-07-25 13:04 . 2010-07-25 13:04 -------- d-----w- c:\programmi\uTorrent
2010-07-25 13:03 . 2010-08-01 21:20 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\uTorrent
2010-07-24 22:50 . 2010-07-24 22:50 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\WinBatch
2010-07-24 19:50 . 2010-07-24 19:50 -------- d-----w- c:\programmi\LSI SoftModem
2010-07-24 17:42 . 2005-10-31 17:17 135168 ------w- c:\windows\system32\RtlCPAPI.dll
2010-07-24 17:42 . 2005-07-15 15:48 40960 ------w- c:\windows\system32\ChCfg.exe
2010-07-24 17:42 . 2006-03-02 19:13 360448 ------w- c:\windows\RtlUpd.exe
2010-07-24 17:42 . 2010-07-24 17:42 -------- d-----w- c:\programmi\Realtek
2010-07-24 17:42 . 2005-04-16 21:20 487424 ------w- c:\windows\RtlExUpd.dll
2010-07-24 13:39 . 2010-07-24 13:39 10134 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
2010-07-24 00:04 . 2010-01-12 07:34 70664 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2010-07-24 00:04 . 2010-01-07 09:35 32680 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2010-07-24 00:03 . 2010-01-13 06:59 115216 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2010-07-24 00:03 . 2010-07-25 16:37 -------- d-----w- c:\programmi\PC Tools Firewall Plus
2010-07-23 23:32 . 2010-02-05 07:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-07-23 23:32 . 2010-03-29 08:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-07-23 23:32 . 2009-11-23 11:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-07-23 22:54 . 2008-04-14 02:13 26624 ----a-w- c:\documents and settings\LocalService\Dati applicazioni\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2010-07-23 06:34 . 2010-07-23 06:34 -------- d-----w- c:\documents and settings\LocalService\Menu Avvio
2010-07-22 20:29 . 2010-07-22 20:45 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Contacts
2010-07-21 22:21 . 2010-07-24 00:05 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\PCToolsFirewallPlus
2010-07-21 22:20 . 2010-07-21 22:20 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Spam Monitor
2010-07-21 22:17 . 2010-01-07 09:35 58816 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2010-07-21 22:16 . 2010-07-24 10:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Tools
2010-07-21 22:16 . 2010-07-23 20:28 -------- d-----w- c:\programmi\PC Tools Internet Security
2010-07-20 18:58 . 2010-07-20 18:58 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Acer
2010-07-20 18:57 . 2010-07-20 18:57 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Impostazioni locali\Dati applicazioni\ADDP
2010-07-20 17:48 . 2009-05-07 09:03 307200 ----a-w- c:\windows\system32\AscSQLite.dll
2010-07-20 17:48 . 2008-11-06 14:04 36864 ----a-w- c:\windows\system32\ascbalon.dll
2010-07-20 17:48 . 2008-11-06 14:04 20480 ----a-w- c:\windows\system32\SysRestore.dll
2010-07-20 17:48 . 2009-04-15 16:50 217088 ----a-w- c:\windows\system32\AscConTest.dll
2010-07-20 17:48 . 2010-07-20 23:02 -------- d-----w- c:\programmi\Ascentive
2010-07-18 22:41 . 2010-07-18 22:41 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\WinMaximizer
2010-07-18 22:39 . 2009-08-14 15:08 105984 ----a-w- c:\windows\system32\drivers\qcusbser.sys
2010-07-18 22:39 . 2010-07-18 22:39 -------- d-----w- c:\programmi\Microsoft Sync Framework
2010-07-18 16:30 . 2010-07-18 16:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Driver Mender
2010-07-18 15:22 . 2010-07-18 15:22 -------- d-----w- c:\programmi\File comuni\eSellerate
2010-07-18 15:22 . 2010-07-18 15:22 -------- d-----w- C:\E-Zsoft
2010-07-18 15:22 . 2010-07-18 15:22 -------- d-----w- c:\programmi\E-Zsoft
2010-07-18 00:17 . 2010-07-18 00:17 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\com.neurospeech.wsclient.suite
2010-07-18 00:17 . 2010-07-18 00:17 -------- d-----w- c:\programmi\File comuni\Adobe AIR
2010-07-17 13:56 . 2010-07-18 22:39 -------- d-----w- c:\programmi\Acer
2010-07-15 19:09 . 2010-07-23 22:39 -------- d-----w- c:\programmi\JPEGCompress
2010-07-13 22:12 . 2010-07-13 22:12 -------- d-----w- c:\windows\small photos
2010-07-13 21:54 . 2010-07-13 21:54 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Stormdance
2010-07-13 21:54 . 2010-07-13 21:54 -------- d-----w- c:\programmi\PhotoRazor
2010-07-13 06:12 . 2010-07-13 06:12 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Macrium
2010-07-13 00:00 . 2010-07-13 00:00 43646 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_E8107429428345802769A1.exe
2010-07-13 00:00 . 2010-07-13 00:00 43646 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_D707CE1C009F1381803C2C.exe
2010-07-13 00:00 . 2010-07-13 00:00 43646 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_21F3885A18D238E15AAE81.exe
2010-07-13 00:00 . 2010-07-13 00:00 43646 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_01A0E73821A82CA3751F06.exe
2010-07-13 00:00 . 2010-07-13 00:00 29926 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_7D9DC4673740B3F1827A58.exe
2010-07-13 00:00 . 2010-07-13 00:00 109534 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_6FEFF9B68218417F98F549.exe
2010-07-13 00:00 . 2010-07-13 00:00 -------- d-----w- c:\programmi\Macrium
2010-07-12 19:32 . 2010-07-12 19:32 -------- d-----w- C:\I386
2010-07-12 19:30 . 2010-07-12 19:30 -------- d-----w- C:\temp
2010-07-11 16:54 . 2010-07-11 16:54 5440 ----a-r- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Microsoft\Installer\{8FC72000-88A0-4B41-82B8-8905D4AA904C}\spy.exe
2010-07-11 16:54 . 2010-07-11 16:54 -------- d-----w- C:\Msispy
2010-07-11 16:28 . 2010-07-11 16:28 -------- d-----w- C:\MsiIntel.SDK
2010-07-08 07:03 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-07-08 07:00 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-07-08 07:00 . 2010-07-08 07:00 -------- d-----w- C:\1f58733359d726de6af17be1ea0a2713
2010-07-08 07:00 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-07-08 07:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-07-08 07:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-07-08 07:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-07-08 07:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-07-08 07:00 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-07-08 07:00 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-07-08 07:00 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-07-07 20:40 . 2010-07-07 20:40 -------- d-----w- c:\windows\Performance
2010-07-07 20:40 . 2010-07-07 20:40 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Impostazioni locali\Dati applicazioni\Microsoft Corporation
2010-07-06 20:41 . 2010-07-14 19:45 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\IObit
2010-07-05 20:42 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-07-03 14:22 . 2010-07-03 14:22 -------- d-----w- c:\programmi\PC Inspector File Recovery
2010-07-03 09:58 . 2010-08-01 21:15 -------- d-----w- c:\windows\system32\CatRoot2
2010-07-02 22:17 . 2010-07-02 22:18 -------- d-----w- c:\programmi\Glary Utilities
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-01 18:40 . 2010-02-26 22:34 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-08-01 15:50 . 2010-02-22 17:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2010-07-31 23:13 . 2010-03-11 21:41 -------- d-----w- c:\programmi\Mozilla Thunderbird
2010-07-31 19:53 . 2005-01-03 00:10 -------- d-----w- c:\programmi\Java
2010-07-31 16:12 . 2010-04-10 09:30 -------- d-----w- c:\programmi\Digisoft AntiDialer
2010-07-28 19:32 . 2010-04-25 14:46 -------- d-----w- c:\programmi\Windows Media Connect 2
2010-07-27 20:23 . 2010-02-17 20:41 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\U3
2010-07-27 19:22 . 2010-06-27 07:21 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\HpUpdate
2010-07-26 23:05 . 2010-02-17 20:54 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-07-26 20:10 . 2004-12-10 21:24 633002 ----a-w- c:\windows\system32\perfh010.dat
2010-07-26 20:10 . 2004-12-10 21:24 131772 ----a-w- c:\windows\system32\perfc010.dat
2010-07-24 17:42 . 2005-01-03 00:28 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-07-24 00:04 . 2010-02-26 22:34 -------- d-----w- c:\programmi\File comuni\PC Tools
2010-07-23 05:32 . 2010-03-11 21:41 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Thunderbird
2010-07-18 22:39 . 2010-03-07 12:58 -------- d-----w- c:\programmi\DIFX
2010-07-18 16:50 . 2010-06-18 21:57 -------- d-----w- c:\programmi\Driver Whiz
2010-07-18 13:22 . 2010-02-17 23:31 55568 ----a-w- c:\documents and settings\Compaq_Proprietario\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-07-18 00:08 . 2010-08-01 17:32 53632 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-07-17 13:56 . 2010-06-03 21:02 -------- d-----w- c:\programmi\Microsoft ActiveSync
2010-07-17 03:00 . 2010-06-27 08:20 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-12 17:12 . 2010-02-21 17:38 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\OfferBox
2010-07-06 22:21 . 2010-03-24 23:04 -------- d-----w- c:\programmi\SIW
2010-07-03 09:58 . 2010-07-03 09:58 76875 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-06-28 20:57 . 2010-03-19 06:54 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2010-03-19 06:55 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2010-03-19 06:55 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2010-03-19 06:55 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2010-03-19 06:55 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2010-03-19 06:55 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2010-03-19 06:55 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2010-03-19 06:55 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-27 18:04 . 2010-02-18 18:14 -------- d-----w- c:\programmi\Picasa2
2010-06-27 16:44 . 2010-06-26 22:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\eXPert PDF 6
2010-06-27 08:36 . 2010-06-27 08:36 503808 ----a-w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6ec8e6fe-n\msvcp71.dll
2010-06-27 08:36 . 2010-06-27 08:36 499712 ----a-w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6ec8e6fe-n\jmc.dll
2010-06-27 08:36 . 2010-06-27 08:36 348160 ----a-w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6ec8e6fe-n\msvcr71.dll
2010-06-27 08:22 . 2010-06-27 08:22 61440 ----a-w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3938736b-n\decora-sse.dll
2010-06-27 08:22 . 2010-06-27 08:22 12800 ----a-w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3938736b-n\decora-d3d.dll
2010-06-27 07:22 . 2010-06-27 07:22 -------- d-----w- c:\programmi\Hp
2010-06-26 22:49 . 2010-04-25 18:45 -------- d-----w- c:\programmi\K-Lite Codec Pack
2010-06-26 22:47 . 2010-06-26 22:47 -------- d-----w- c:\programmi\Visagesoft
2010-06-26 22:47 . 2010-06-26 22:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\eXPert PDF Jobs
2010-06-26 22:47 . 2010-06-26 22:47 -------- d-----w- c:\programmi\BVRP Software
2010-06-26 22:47 . 2010-06-26 22:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\BVRP Software
2010-06-26 22:45 . 2010-05-29 12:29 -------- d-----w- c:\programmi\Acer(2)
2010-06-26 22:28 . 2010-06-23 20:38 -------- d-----w- c:\programmi\Index.dat Suite
2010-06-26 16:00 . 2010-06-26 16:00 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Registry Mechanic
2010-06-26 15:40 . 2010-06-26 15:39 1840 ----a-w- c:\windows\pchealth\helpctr\PackageStore(2)\SkuStore.bin
2010-06-26 15:39 . 2010-06-26 15:39 76875 ----a-w- c:\windows\pchealth\helpctr\OfflineCache(2)\index.dat
2010-06-24 21:32 . 2010-06-24 21:32 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Uniblue
2010-06-22 13:59 . 2010-06-22 13:59 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Drivers HeadQuarters
2010-06-22 13:44 . 2010-06-22 13:44 -------- d-----w- c:\programmi\PC Drivers HeadQuarters
2010-06-21 09:58 . 2010-06-21 09:58 15328 ----a-w- c:\windows\system32\drivers\pssnap.sys
2010-06-21 09:57 . 2010-06-21 09:57 44512 ----a-w- c:\windows\system32\drivers\psmounter.sys
2010-06-20 15:35 . 2010-06-20 15:35 -------- d-----w- c:\programmi\MSBuild
2010-06-20 15:35 . 2010-06-20 15:35 -------- d-----w- c:\programmi\Reference Assemblies
2010-06-18 22:37 . 2010-06-18 22:35 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Acer
2010-06-18 22:18 . 2010-06-18 22:18 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Driver Whiz
2010-06-18 17:00 . 2010-03-07 12:58 -------- d-----w- c:\documents and settings\Compaq_Proprietario\Dati applicazioni\PC Suite
2010-06-17 19:23 . 2010-06-17 19:23 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\MSScanAppDataDir
2010-06-17 19:05 . 2010-02-21 17:37 304160 ----a-w- C:\PA207.DAT
2010-06-14 14:31 . 2008-11-11 05:24 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-06 10:32 . 2004-08-19 11:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-06 10:32 . 2004-08-19 11:00 916480 ----a-w- c:\windows\system32\wininet(2)(2).dll
2010-05-06 10:32 . 2004-08-19 11:00 1209344 ----a-w- c:\windows\system32\urlmon(2)(2).dll
2010-05-06 10:32 . 2007-08-13 17:34 1985536 ----a-w- c:\windows\system32\iertutil(2)(2).dll
2006-08-12 15:54 . 2010-02-18 04:08 32 --sha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\programmi\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
"Glary Memory Optimizer"="c:\programmi\Glary Utilities\memdefrag.exe" [2010-06-28 108344]
"uTorrent"="c:\programmi\uTorrent\uTorrent.exe" [2010-07-25 327984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"vspdfprsrv.exe"="c:\programmi\Visagesoft\eXPert PDF 6\vspdfprsrv.exe" [2009-01-15 1205760]
"HP Software Update"="c:\programmi\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2010-01-12 3168216]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 16010240]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-02-21 13670504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-27 561213]
Digisoft AntiDialer.lnk - c:\programmi\Digisoft AntiDialer\AntiDialer.exe [2003-8-19 730112]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [21/06/2010 11.58.08 15328]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19/03/2010 8.55.24 165456]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [24/07/2010 1.32.22 233136]
R2 AcerSyncServiceWinService;AcerSyncServiceWinService;c:\programmi\Acer\AcerSync\AcerSyncService.exe -p --> c:\programmi\Acer\AcerSync\AcerSyncService.exe -p [?]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19/03/2010 8.55.24 17744]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [24/07/2010 1.32.19 88040]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\programmi\Macrium\Reflect\ReflectService.exe [21/06/2010 11.57.42 220128]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14/05/2007 11.26.10 508288]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [24/07/2010 2.04.01 70664]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [22/07/2010 0.17.06 58816]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [24/07/2010 2.03.58 115216]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\DRIVERS\ONDAusbmdm6k.sys --> c:\windows\system32\DRIVERS\ONDAusbmdm6k.sys [?]
S3 ONDAusbnet;ONDA USB-NDIS miniport;c:\windows\system32\DRIVERS\ONDAusbnet.sys --> c:\windows\system32\DRIVERS\ONDAusbnet.sys [?]
S3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\DRIVERS\ONDAusbnmea.sys --> c:\windows\system32\DRIVERS\ONDAusbnmea.sys [?]
S3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\DRIVERS\ONDAusbser6k.sys --> c:\windows\system32\DRIVERS\ONDAusbser6k.sys [?]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [21/06/2010 11.57.56 44512]
S3 qcusbser;ACER Android USB Device for Legacy Serial Communication;c:\windows\system32\drivers\qcusbser.sys [19/07/2010 0.39.24 105984]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
.
Contenuto della cartella 'Scheduled Tasks'
2010-08-01 c:\windows\Tasks\GlaryInitialize.job
- c:\programmi\Glary Utilities\initialize.exe [2010-07-02 09:14]
2010-08-01 c:\windows\Tasks\User_Feed_Synchronization-{081C0CE3-ED28-446E-B3F1-DCC766CC62D1}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Scansione supplementare -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Mozilla\Firefox\Profiles\6iu7pzsf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://uk.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://it.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:it:official
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\Compaq_Proprietario\Dati applicazioni\Mozilla\Firefox\Profiles\6iu7pzsf.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
FF - plugin: c:\documents and settings\All Users\Dati applicazioni\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\programmi\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\programmi\Picasa2\npPicasa2.dll
FF - plugin: c:\programmi\Picasa2\npPicasa3.dll
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - truec:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programmi\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
Toolbar-Locked - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-01 23:28
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2010-08-01 23:30:44
ComboFix-quarantined-files.txt 2010-08-01 21:30
Pre-Run: 178.660.667.392 byte disponibili
Post-Run: 178.659.569.664 byte disponibili
- - End Of File - - F75EB45C3206EEB00656FAAE5998D550
operazione conclusa