Rieccomi... ecco il log di combofix
ComboFix 10-10-05.01 - Salvatore Iardino 06/10/2010 21.27.26.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.2037.1457 [GMT 2:00]
Eseguito da: c:\documents and settings\Salvatore Iardino\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Salvatore Iardino\Desktop\CFScript.txt
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: Outpost Firewall *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
FILE ::
"c:\windows\system32\rlvqlev.dll"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_KDRYFGPSS
-------\Service_kdryfgpss
((((((((((((((((((((((((( Files Creati Da 2010-09-06 al 2010-10-06 )))))))))))))))))))))))))))))))))))
.
2010-10-06 13:30 . 2010-06-01 17:37 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-10-06 13:12 . 2010-10-06 13:13 -------- d-----w- c:\programmi\Microsoft Security Essentials
2010-10-06 12:20 . 2010-10-06 12:20 -------- d-----w- C:\GoogleChromePortable
2010-10-06 10:58 . 2009-04-06 09:37 704384 ----a-w- c:\windows\system32\drivers\SandBox.sys
2010-10-06 10:57 . 2009-02-10 14:15 257432 ----a-w- c:\windows\system32\drivers\afwcore.sys
2010-10-06 10:55 . 2009-02-18 15:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys
2010-10-06 10:55 . 2010-10-06 10:55 -------- d-----w- c:\programmi\Agnitum
2010-10-06 10:55 . 2010-10-06 10:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Agnitum
2010-10-06 10:44 . 2010-10-06 10:44 -------- d-----w- c:\programmi\CCleaner
2010-10-06 07:48 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-06 07:48 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-06 07:48 . 2010-10-06 07:48 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-10-06 07:42 . 2010-10-06 07:42 -------- d-----w- c:\documents and settings\Salvatore Iardino\Dati applicazioni\Malwarebytes
2010-10-06 07:42 . 2010-10-06 07:42 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-10-05 12:49 . 2010-10-05 12:49 -------- d-----w- c:\windows\system32\wbem\Repository
2010-10-05 12:39 . 2010-10-06 07:52 -------- d-----w- c:\programmi\Opera
2010-10-05 12:39 . 2010-10-05 12:39 -------- d-----w- c:\windows\Nightfall Mysteries - The Asylum Conspiracy
2010-10-05 10:36 . 2010-10-05 12:48 -------- d-----w- c:\documents and settings\Salvatore Iardino\Dati applicazioni\.purple
2010-10-05 10:30 . 2010-10-05 12:49 -------- d-----w- c:\programmi\Pidgin
2010-10-05 10:23 . 2010-10-05 10:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Chit Chat For Facebook
2010-10-05 10:15 . 2010-10-05 10:15 -------- d-----w- c:\documents and settings\Salvatore Iardino\Impostazioni locali\Dati applicazioni\Opera
2010-09-28 19:33 . 2010-09-28 19:33 -------- d-----w- c:\documents and settings\Salvatore Iardino\Dati applicazioni\Vast Studios
2010-09-28 19:27 . 2010-10-05 12:39 -------- d-----w- c:\programmi\Nightfall Mysteries - The Asylum Conspiracy
2010-09-16 16:41 . 2009-02-06 19:07 3698584 -c--a-w- c:\windows\system32\dllcache\ieapfltr.dat
2010-09-16 14:40 . 2010-09-16 14:40 -------- d-----w- c:\documents and settings\Salvatore Iardino\IECompatCache
2010-09-16 13:35 . 2010-09-16 13:35 -------- d-----w- c:\documents and settings\Salvatore Iardino\PrivacIE
2010-09-16 13:34 . 2010-09-16 13:34 -------- d-----w- c:\documents and settings\LocalService\IETldCache
2010-09-16 13:33 . 2010-09-16 13:33 -------- d-----w- c:\documents and settings\Salvatore Iardino\IETldCache
2010-09-16 13:30 . 2010-09-16 13:30 -------- d-----w- c:\windows\ie8updates
2010-09-16 13:26 . 2010-10-05 12:48 -------- dc----w- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-06 14:20 . 2005-07-02 08:55 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-10-06 13:22 . 2009-09-10 18:26 -------- d-----w- c:\programmi\File comuni\Symantec Shared
2010-10-06 13:22 . 2009-09-10 18:28 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Symantec
2010-10-06 10:49 . 2009-09-10 17:54 68448 ----a-w- c:\documents and settings\Salvatore Iardino\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-10-05 12:17 . 2005-06-30 18:28 48012 ----a-w- c:\windows\system32\perfc010.dat
2010-10-05 12:17 . 2005-06-30 18:28 345620 ----a-w- c:\windows\system32\perfh010.dat
2010-09-30 20:12 . 2010-07-25 10:21 -------- d-----w- c:\programmi\Big Kahuna Reef 2
2010-09-27 21:09 . 2010-08-06 10:53 -------- d-----w- c:\programmi\Magic Vines
2010-09-16 15:03 . 2010-07-25 09:29 -------- d-----w- c:\programmi\Onda Connection Manager
2010-09-06 11:06 . 2009-12-08 16:54 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-09-05 15:44 . 2010-09-02 09:17 -------- d-----w- c:\documents and settings\Salvatore Iardino\Dati applicazioni\uTorrent
2010-09-03 11:40 . 2010-09-03 11:40 -------- d-----w- c:\programmi\File comuni\BitSpirit
2010-09-03 11:40 . 2010-09-03 11:40 -------- d-----w- c:\programmi\BitSpirit
2010-09-02 09:18 . 2010-09-02 09:18 -------- d-----w- c:\programmi\uTorrent
2010-08-20 14:04 . 2010-08-20 14:04 0 ----a-w- c:\windows\popcinfo.dat
2010-08-20 14:03 . 2010-08-20 14:02 -------- d-----w- c:\programmi\Big Kahuna Reef
2010-08-20 14:00 . 2010-08-20 14:00 -------- d-----w- c:\programmi\Super Mahjong
2010-08-20 13:36 . 2010-08-20 13:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Playrix Entertainment
2010-08-20 13:35 . 2010-08-06 11:15 -------- d-----w- c:\programmi\Fishdom 2 - Premium Edition
2010-08-20 13:00 . 2010-08-20 13:00 -------- d-----w- c:\documents and settings\Salvatore Iardino\Dati applicazioni\Dream Farm Games
2010-08-20 13:00 . 2010-08-20 12:59 -------- d-----w- c:\programmi\The Book of Wanderer The Story of Dragons
2010-08-17 13:17 . 2005-06-30 18:28 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-10 13:17 . 2010-08-10 13:17 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Big Fish Games Vancouver
2010-08-10 13:17 . 2010-08-10 13:16 -------- d-----w- c:\programmi\Unwell Mel
2010-07-22 15:48 . 2005-06-30 18:27 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
.
(((((((((((((((((((((((((((((
SnapShot@2010-10-06_07.34.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 00:19 . 2007-11-07 00:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 04:07 . 2008-07-29 04:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 04:07 . 2008-07-29 04:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2005-06-30 18:28 . 2010-06-21 14:46 46080 c:\windows\system32\tzchange.exe
- 2005-06-30 18:28 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
+ 2005-06-30 18:27 . 2010-06-17 14:03 80384 c:\windows\system32\iccvid.dll
- 2005-06-30 18:27 . 2008-04-14 12:00 80384 c:\windows\system32\iccvid.dll
+ 2005-06-30 18:28 . 2010-08-17 13:17 58880 c:\windows\system32\dllcache\spoolsv.exe
+ 2005-06-30 18:27 . 2010-03-05 14:38 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2005-06-30 18:27 . 2010-03-05 14:38 65536 c:\windows\system32\asycfilt.dll
+ 2010-10-06 13:13 . 2010-10-06 13:13 47104 c:\windows\Installer\31f1d.msi
+ 2005-07-02 09:00 . 2010-10-06 14:20 35088 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\oisicon.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 35088 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\oisicon.exe
+ 2005-07-02 09:00 . 2010-10-06 14:20 18704 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\mspicons.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 18704 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\mspicons.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 20240 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\cagicon.exe
+ 2005-07-02 09:00 . 2010-10-06 14:20 20240 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-04-03 16:01 . 2009-04-03 16:01 71504 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\XL12CNVP.DLL
+ 2009-04-03 15:57 . 2009-04-03 15:57 21320 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\WRD12EXE.EXE
+ 2009-03-04 15:24 . 2009-03-04 15:24 54088 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\SCANOST.EXE
+ 2009-03-04 15:24 . 2009-03-04 15:24 75608 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\RM.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 38240 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\RECALL.DLL
+ 2009-01-06 19:31 . 2009-01-06 19:31 48512 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\PUBTRAP.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 52072 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OUTLVBA.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 34192 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\DUMPSTER.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 87392 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\DLGSETP.DLL
+ 2006-10-26 20:58 . 2006-10-26 20:58 33080 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.4518\VPREVIEW.EXE
+ 2010-10-06 14:07 . 2008-07-08 13:06 26488 c:\windows\$hf_mig$\KB971737\update\spcustom.dll
+ 2010-10-06 14:07 . 2008-07-08 13:06 18808 c:\windows\$hf_mig$\KB971737\spmsg.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 01:54 . 2008-07-29 01:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
- 2005-06-30 18:28 . 2008-04-14 12:00 293888 c:\windows\system32\winsrv.dll
+ 2005-06-30 18:28 . 2010-06-18 17:45 293888 c:\windows\system32\winsrv.dll
+ 2005-06-30 18:28 . 2009-08-25 09:18 354816 c:\windows\system32\winhttp.dll
+ 2005-06-30 18:28 . 2010-04-16 15:37 406016 c:\windows\system32\usp10.dll
- 2005-06-30 18:28 . 2008-04-14 12:00 406016 c:\windows\system32\usp10.dll
+ 2005-06-30 18:27 . 2010-06-30 12:31 149504 c:\windows\system32\schannel.dll
+ 2005-06-30 09:41 . 2010-06-09 07:43 692736 c:\windows\system32\inetcomm.dll
+ 2005-06-30 11:34 . 2010-10-06 18:43 263824 c:\windows\system32\FNTCACHE.DAT
+ 2010-03-25 19:30 . 2010-03-25 19:30 151216 c:\windows\system32\drivers\MpFilter.sys
+ 2005-06-30 18:28 . 2010-06-18 17:45 293888 c:\windows\system32\dllcache\winsrv.dll
- 2005-06-30 18:28 . 2008-04-14 12:00 293888 c:\windows\system32\dllcache\winsrv.dll
+ 2005-06-30 18:28 . 2009-08-25 09:18 354816 c:\windows\system32\dllcache\winhttp.dll
+ 2005-06-30 18:28 . 2010-04-16 15:37 406016 c:\windows\system32\dllcache\usp10.dll
- 2005-06-30 18:28 . 2008-04-14 12:00 406016 c:\windows\system32\dllcache\usp10.dll
+ 2005-06-30 18:27 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
+ 2005-06-30 18:27 . 2010-07-22 15:48 590848 c:\windows\system32\dllcache\rpcrt4.dll
+ 2005-06-30 09:41 . 2010-06-09 07:43 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2010-04-28 14:41 . 2010-02-12 10:03 293376 c:\windows\system32\browserchoice.exe
+ 2010-10-06 10:56 . 2010-10-06 10:56 228352 c:\windows\Installer\850ae.msi
+ 2010-10-06 13:13 . 2010-10-06 13:13 272384 c:\windows\Installer\31f14.msi
+ 2010-10-06 13:12 . 2010-10-06 13:12 254976 c:\windows\Installer\31f0e.msi
+ 2010-10-06 13:12 . 2010-10-06 13:12 301056 c:\windows\Installer\31f08.msi
+ 2010-08-04 13:13 . 2010-08-04 13:13 686080 c:\windows\Installer\2ff492.msp
+ 2009-05-26 16:53 . 2009-05-26 16:53 579072 c:\windows\Installer\2ff3fc.msp
+ 2005-07-02 09:00 . 2010-10-06 14:20 888080 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\wordicon.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 888080 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\wordicon.exe
+ 2005-07-02 09:00 . 2010-10-06 14:20 272648 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\pubs.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 272648 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\pubs.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 922384 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\pptico.exe
+ 2005-07-02 09:00 . 2010-10-06 14:20 922384 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\pptico.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 845584 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\outicon.exe
+ 2005-07-02 09:00 . 2010-10-06 14:20 845584 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\outicon.exe
+ 2005-07-02 09:00 . 2010-10-06 14:20 217864 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\misc.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 217864 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\misc.exe
+ 2009-04-03 16:11 . 2009-04-03 16:11 408424 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\WINWORD.EXE
+ 2009-03-06 00:37 . 2009-03-06 00:37 501640 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\SOA.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 282032 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\SCNPST64.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 273320 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\SCNPST32.DLL
+ 2009-03-06 00:06 . 2009-03-06 00:06 407904 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\RTFHTML.DLL
+ 2009-03-06 01:41 . 2009-03-06 01:41 589704 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\PUBCONV.DLL
+ 2009-01-08 08:59 . 2009-01-08 08:59 624520 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\PTXT9.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 420696 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\PSTPRX32.DLL
+ 2008-10-25 04:21 . 2008-10-25 04:21 136072 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\PRTF9.DLL
+ 2009-04-03 16:04 . 2009-04-03 16:04 521064 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\POWERPNT.EXE
+ 2008-11-20 22:49 . 2008-11-20 22:49 169360 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OUTLPH.DLL
+ 2009-03-06 00:05 . 2009-03-06 00:05 593288 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OUTLMIME.DLL
+ 2008-10-30 19:24 . 2008-10-30 19:24 137552 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OUTLCTL.DLL
+ 2009-03-06 02:55 . 2009-03-06 02:55 194448 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OMSXP32.DLL
+ 2009-03-06 02:55 . 2009-03-06 02:55 661888 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OMSMAIN.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 253808 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OLKFSTUB.DLL
+ 2008-11-03 22:04 . 2008-11-03 22:04 498072 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\MORPH9.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 340304 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\MIMEDIR.DLL
+ 2009-03-04 15:24 . 2009-03-04 15:24 138072 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\IMPMAIL.DLL
+ 2008-11-20 22:48 . 2008-11-20 22:48 116600 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\EMABLT32.DLL
+ 2009-03-06 00:05 . 2009-03-06 00:05 127336 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\CONTAB32.DLL
+ 2008-10-26 04:26 . 2008-10-26 04:26 162680 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\ACCWIZ.DLL
+ 2010-10-06 14:07 . 2009-05-26 11:41 402296 c:\windows\$hf_mig$\KB971737\update\updspapi.dll
+ 2010-10-06 14:07 . 2009-05-26 11:41 763768 c:\windows\$hf_mig$\KB971737\update\update.exe
+ 2010-10-06 14:07 . 2008-07-08 13:06 233848 c:\windows\$hf_mig$\KB971737\spuninst.exe
+ 2009-08-25 09:30 . 2009-08-25 09:30 354816 c:\windows\$hf_mig$\KB971737\SP3QFE\winhttp.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2005-06-30 18:28 . 2010-04-08 12:03 2113536 c:\windows\system32\WMVCore.dll
+ 2005-06-30 18:28 . 2010-06-24 09:02 1851904 c:\windows\system32\win32k.sys
+ 2005-06-30 18:27 . 2010-07-27 06:29 8491520 c:\windows\system32\shell32.dll
+ 2005-06-30 18:27 . 2010-02-05 18:25 1296896 c:\windows\system32\quartz.dll
- 2005-06-30 18:27 . 2009-11-27 17:12 1296896 c:\windows\system32\quartz.dll
- 2008-04-13 18:54 . 2010-02-16 19:05 2149888 c:\windows\system32\ntoskrnl.exe
+ 2008-04-13 18:54 . 2010-04-28 05:41 2149888 c:\windows\system32\ntoskrnl.exe
- 2008-04-13 18:55 . 2010-02-16 19:05 2028032 c:\windows\system32\ntkrnlpa.exe
+ 2008-04-13 18:55 . 2010-04-28 05:41 2028032 c:\windows\system32\ntkrnlpa.exe
+ 2005-06-30 18:27 . 2010-06-14 07:41 1172480 c:\windows\system32\msxml3.dll
- 2005-06-30 18:27 . 2009-07-31 04:32 1172480 c:\windows\system32\msxml3.dll
+ 2009-08-17 21:33 . 2009-08-17 21:33 1193832 c:\windows\system32\FM20.DLL
+ 2005-06-30 18:28 . 2010-04-08 12:03 2113536 c:\windows\system32\dllcache\WMVCore.dll
+ 2005-06-30 18:28 . 2010-06-24 09:02 1851904 c:\windows\system32\dllcache\win32k.sys
+ 2005-06-30 18:27 . 2010-07-27 06:29 8491520 c:\windows\system32\dllcache\shell32.dll
+ 2005-06-30 18:27 . 2010-02-05 18:25 1296896 c:\windows\system32\dllcache\quartz.dll
- 2005-06-30 18:27 . 2009-11-27 17:12 1296896 c:\windows\system32\dllcache\quartz.dll
+ 2010-04-26 21:30 . 2010-04-28 18:11 2193664 c:\windows\system32\dllcache\ntoskrnl.exe
- 2010-04-26 21:30 . 2010-02-17 12:05 2193664 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2010-04-26 21:30 . 2010-04-28 05:41 2028032 c:\windows\system32\dllcache\ntkrpamp.exe
- 2010-04-26 21:30 . 2010-02-16 19:05 2028032 c:\windows\system32\dllcache\ntkrpamp.exe
- 2009-02-10 17:02 . 2010-02-16 19:05 2070528 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-02-10 17:02 . 2010-04-28 05:41 2070528 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2010-04-26 21:30 . 2010-02-16 19:05 2149888 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2010-04-26 21:30 . 2010-04-28 05:41 2149888 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2005-06-30 18:27 . 2009-07-31 04:32 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2005-06-30 18:27 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2005-06-30 09:41 . 2010-01-29 14:59 1315328 c:\windows\system32\dllcache\msoe.dll
- 2005-06-30 09:41 . 2009-07-10 13:26 1315328 c:\windows\system32\dllcache\msoe.dll
- 2005-06-30 09:41 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2005-06-30 09:41 . 2010-06-18 13:36 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2009-08-05 05:49 . 2009-08-05 05:49 3457024 c:\windows\Installer\2ff490.msp
+ 2010-03-24 16:54 . 2010-03-24 16:54 2516992 c:\windows\Installer\2ff47a.msp
+ 2009-07-27 02:31 . 2009-07-27 02:31 3738624 c:\windows\Installer\2ff466.msp
+ 2010-04-24 15:07 . 2010-04-24 15:07 4667392 c:\windows\Installer\2ff452.msp
+ 2010-08-19 15:57 . 2010-08-19 15:57 3395584 c:\windows\Installer\2ff43c.msp
+ 2010-05-20 17:57 . 2010-05-20 17:57 4989952 c:\windows\Installer\2ff428.msp
+ 2010-05-20 17:57 . 2010-05-20 17:57 5907456 c:\windows\Installer\2ff427.msp
+ 2009-10-16 05:08 . 2009-10-16 05:08 2237952 c:\windows\Installer\2ff410.msp
+ 2010-04-24 15:05 . 2010-04-24 15:05 4199424 c:\windows\Installer\2ff3e9.msp
+ 2009-08-18 11:08 . 2009-08-18 11:08 1373696 c:\windows\Installer\2ff3d0.msp
+ 2010-04-24 15:10 . 2010-04-24 15:10 8486400 c:\windows\Installer\2ff3bc.msp
+ 2010-07-10 18:14 . 2010-07-10 18:14 2850816 c:\windows\Installer\2ff3a7.msp
- 2005-07-02 09:00 . 2010-04-27 14:28 1172240 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\xlicons.exe
+ 2005-07-02 09:00 . 2010-10-06 14:20 1172240 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\xlicons.exe
- 2005-07-02 09:00 . 2010-04-27 14:28 1165584 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\accicons.exe
+ 2005-07-02 09:00 . 2010-10-06 14:20 1165584 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-04-03 15:57 . 2009-04-03 15:57 4671320 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\WRD12CNV.DLL
+ 2008-11-21 01:12 . 2008-11-21 01:12 3750256 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\VVIEWER.DLL
+ 2008-10-25 07:35 . 2008-10-25 07:35 1847160 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\VVIEWDWG.DLL
+ 2008-08-25 20:50 . 2008-08-25 20:50 2585592 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\VBE6.DLL
+ 2009-04-03 16:04 . 2009-04-03 16:04 8468840 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\PPCORE.DLL
+ 2009-03-06 00:05 . 2009-03-06 00:05 2964336 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OLMAPI32.DLL
+ 2009-02-05 09:36 . 2009-02-05 09:36 1640800 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OGL.DLL
+ 2009-03-06 01:41 . 2009-03-06 01:41 9589096 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\MSPUB.EXE
+ 2009-03-06 02:26 . 2009-03-06 02:26 5291376 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\IPEDITOR.DLL
+ 2008-11-20 21:06 . 2008-11-20 21:06 1194848 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\FM20.DLL
+ 2010-04-26 21:30 . 2010-04-28 18:11 2193664 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2010-04-26 21:30 . 2010-02-17 12:05 2193664 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2010-04-26 21:30 . 2010-04-28 05:41 2028032 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2010-04-26 21:30 . 2010-02-16 19:05 2028032 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-02-10 17:02 . 2010-02-16 19:05 2070528 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-02-10 17:02 . 2010-04-28 05:41 2070528 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2010-04-26 21:30 . 2010-02-16 19:05 2149888 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2010-04-26 21:30 . 2010-04-28 05:41 2149888 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2010-10-06 14:07 . 2010-09-10 12:34 35552200 c:\windows\system32\MRT.exe
+ 2010-07-22 23:04 . 2010-07-22 23:04 11395072 c:\windows\Installer\2ff391.msp
+ 2010-07-22 23:04 . 2010-07-22 23:04 11395072 c:\windows\Installer\198077.msp
+ 2010-07-10 18:06 . 2010-07-10 18:06 10120192 c:\windows\Installer\198075.msp
+ 2009-04-03 16:01 . 2009-04-03 16:01 15108448 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\XL12CNV.EXE
+ 2009-04-03 16:11 . 2009-04-03 16:11 17740136 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\WWLIB.DLL
+ 2009-03-06 00:06 . 2009-03-06 00:06 12707696 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\OUTLOOK.EXE
+ 2009-03-06 00:37 . 2009-03-06 00:37 10222432 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6425\MSACCESS.EXE
.
-- Snapshot per reimpostare la data corrente --
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-08 16862208]
"ITSecMng"="c:\programmi\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"MGSysCtrl"="c:\programmi\System Control Manager\MGSysCtrl.exe" [2008-10-09 688128]
"PWRISOVM.EXE"="c:\programmi\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\programmi\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"MSSE"="c:\programmi\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Bluetooth Manager.lnk - c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-2-22 2938184]
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2010-4-5 494920]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\BitSpirit\\BitSpirit.exe"=
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [06/10/2010 12.58.01 704384]
R2 Micro Star SCM;Micro Star SCM;c:\programmi\System Control Manager\MSIService.exe [02/07/2005 10.48.49 159744]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [06/10/2010 12.55.47 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [06/10/2010 12.57.14 257432]
R3 MSILiveVirtualCamera;MSI Live Virtual Camera;c:\windows\system32\drivers\MSILiveVirtualCamera.sys [29/01/2007 7.40.22 449408]
R3 ONDA_MW823UP_dc_enum;ONDA MW823UP DC Enumerator;c:\windows\system32\drivers\ONDA_MW823UP_dc_enum.sys [27/01/2010 16.43.48 80000]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [02/07/2005 9.48.35 156160]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [02/07/2005 10.46.40 704384]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [06/10/2010 12.55.44 1195008]
S3 ONDA_MW823UP_cdc_acm;ONDA MW823UP CDC-ACM driver;c:\windows\system32\drivers\ONDA_MW823UP_cdc_acm.sys [27/01/2010 16.43.46 86016]
S3 ONDA_MW823UP_cdc_ecm;ONDA_MW823UP_cdc_ecm;c:\windows\system32\drivers\ONDA_MW823UP_cdc_ecm.sys [27/01/2010 16.43.48 49920]
S3 ONDA_MW823UP_cpo;ONDA MW823UP Install;c:\windows\system32\drivers\ONDA_MW823UP_cpo.sys [27/01/2010 16.43.46 9728]
.
Contenuto della cartella 'Scheduled Tasks'
2010-10-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmi\Microsoft Security Essentials\MpCmdRun.exe [2010-03-25 19:40]
2010-10-06 c:\windows\Tasks\MpIdleTask.job
- c:\programmi\Microsoft Security Essentials\MpCmdRun.exe [2010-03-25 19:40]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = hxxp://www.msi.com.tw/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Scarica usando &BitSpirit - c:\programmi\BitSpirit\bsurl.htm
.
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Microsoft Security Essentials\MsMpEng.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2010-10-06 21:40:23 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-10-06 19:40
ComboFix2.txt 2010-10-06 07:36
Pre-Run: 2.067.132.416 byte disponibili
Post-Run: 2.098.270.208 byte disponibili
- - End Of File - - 87278F1754FB2E06ED8BDC5D2D74E451
volevo finalmente dire che funzionano anche gli altri browser... ora cosa mi consigliate di fare un punto di ripristino e fare l'aggiornamento di windows update così tanto per andarci coi piedi di piombo
Voglio ringraziarvi davvero tanto anche ad Alfonso che ci ha perso un giorno intero con me e a r16 per la dritta finale