fatto!ecco il report
ComboFix 12-06-28.01 - MAILA 28/06/2012 18:42:30.3.4 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.39.1040.18.2935.1719 [GMT 2:00]
Eseguito da: c:\users\MAILA\Desktop\ComboFix.exe
Opzioni usate :: c:\users\MAILA\Documents\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Creati Da 2012-05-28 al 2012-06-28 )))))))))))))))))))))))))))))))))))
.
.
2012-06-28 16:46 . 2012-06-28 16:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-27 14:56 . 2012-06-28 16:46 -------- d-----w- c:\users\MAILA\AppData\Local\temp
2012-06-27 14:44 . 2012-06-28 15:36 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{76816FC7-1FD9-49AD-B92B-CCD433B30AEE}\offreg.dll
2012-06-27 11:36 . 2012-06-27 11:36 -------- d-----w- c:\program files\Common Files\Adobe
2012-06-27 10:59 . 2012-06-27 10:59 -------- d-----w- c:\users\MAILA\AppData\Roaming\Malwarebytes
2012-06-27 10:59 . 2012-06-27 10:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-06-27 10:59 . 2012-06-27 10:59 -------- d-----w- c:\programdata\Malwarebytes
2012-06-27 10:59 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-27 10:52 . 2012-06-27 10:52 -------- d-----w- c:\users\MAILA\AppData\Local\Ilivid Player
2012-06-26 20:48 . 2012-06-26 20:48 388096 ----a-r- c:\users\MAILA\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-26 20:48 . 2012-06-26 20:48 -------- d-----w- c:\program files\Trend Micro
2012-06-26 20:36 . 2012-03-30 10:29 1287024 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-26 20:36 . 2012-04-28 03:19 177152 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-26 20:35 . 2012-04-02 04:40 936960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-06-26 20:35 . 2012-04-02 04:41 1221632 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-06-26 20:35 . 2012-04-02 04:40 989184 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-06-26 20:35 . 2012-04-02 04:40 969216 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-06-26 20:35 . 2012-04-24 04:47 1156608 ----a-w- c:\windows\system32\crypt32.dll
2012-06-26 20:35 . 2012-04-24 04:47 139264 ----a-w- c:\windows\system32\cryptsvc.dll
2012-06-26 20:35 . 2012-04-24 04:47 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-06-26 20:33 . 2012-04-02 04:46 3902320 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-06-26 20:33 . 2012-04-02 04:46 3958128 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-26 20:32 . 2012-05-15 01:12 2342400 ----a-w- c:\windows\system32\win32k.sys
2012-06-26 20:32 . 2012-03-17 07:20 56688 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-26 20:32 . 2012-05-02 04:52 163328 ----a-w- c:\windows\system32\profsvc.dll
2012-06-26 20:32 . 2012-04-26 04:48 57856 ----a-w- c:\windows\system32\rdpwsx.dll
2012-06-26 20:32 . 2012-04-26 04:48 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-06-26 20:32 . 2012-04-26 04:43 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-06-26 20:31 . 2012-03-03 05:40 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2012-06-26 20:31 . 2012-03-03 05:40 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-06-26 20:31 . 2012-03-03 05:40 1074176 ----a-w- c:\windows\system32\DWrite.dll
2012-06-26 20:31 . 2012-03-03 05:40 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-06-26 20:30 . 2012-03-03 05:40 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2012-06-26 20:05 . 2012-06-26 20:05 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-26 20:05 . 2012-06-26 20:05 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-26 14:21 . 2012-05-31 03:41 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{76816FC7-1FD9-49AD-B92B-CCD433B30AEE}\mpengine.dll
2012-06-23 17:15 . 2012-06-23 17:15 -------- d-----w- c:\programdata\boost_interprocess
2012-06-22 10:07 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-22 10:07 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-22 10:07 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-22 10:07 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-22 10:07 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-22 10:07 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-22 10:07 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-22 10:07 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-22 10:07 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-15 18:05 . 2012-06-26 22:07 -------- d-----w- c:\users\MAILA\AppData\Roaming\vlc
2012-06-15 18:02 . 2012-06-15 18:02 -------- d-----w- c:\program files\VideoLAN
2012-06-12 15:57 . 2012-06-12 15:57 -------- d-----w- c:\program files\Microsoft SDKs
2012-06-12 15:41 . 2012-06-12 15:41 -------- d-----w- C:\Hauppauge
2012-06-12 15:34 . 2001-01-12 09:02 53248 ----a-w- c:\windows\system32\MDCustomPanels.ocx
2012-06-12 15:34 . 2000-07-14 21:00 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2012-06-12 15:34 . 1999-05-06 21:00 244232 ----a-w- c:\windows\system32\MsFlxGrd.ocx
2012-06-12 15:34 . 1998-06-25 21:00 89600 ----a-w- c:\windows\system32\MSCAL.OCX
2012-06-12 15:34 . 2002-12-27 10:33 65536 ----a-w- c:\windows\system32\dmcrypto.dll
2012-06-12 15:34 . 1998-06-18 09:33 598288 ----a-w- c:\windows\system32\temp.011
2012-06-12 15:34 . 1998-06-18 09:33 164112 ----a-w- c:\windows\system32\temp.012
2012-06-12 15:34 . 1998-06-18 09:32 147728 ----a-w- c:\windows\system32\temp.013
2012-06-12 15:34 . 1998-06-16 22:13 17920 ----a-w- c:\windows\system32\temp.014
2012-06-12 15:33 . 2012-06-12 15:42 -------- d-----w- c:\program files\WinTV
2012-06-12 15:33 . 2000-03-07 14:22 278581 ----a-w- c:\windows\system32\temp.00F
2012-06-12 15:33 . 2000-02-11 15:58 995383 ----a-w- c:\windows\system32\temp.010
2012-06-12 15:33 . 1998-06-25 00:43 1409024 ----a-w- c:\windows\system32\temp.015
2012-06-12 15:33 . 1998-06-16 18:45 77878 ----a-w- c:\windows\system32\temp.00E
2012-06-12 15:33 . 1998-05-31 14:06 22288 ----a-w- c:\windows\system32\temp.016
2012-06-12 15:32 . 2012-06-12 15:32 -------- d-----w- C:\hcw21nova-t
2012-06-05 09:17 . 2012-06-05 09:17 -------- d-----w- c:\programdata\Microsoft Help
2012-06-05 09:17 . 2012-06-05 09:17 -------- d-----w- c:\users\MAILA\AppData\Local\Microsoft Help
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\boost_interprocess ----
.
2012-06-23 17:15 . 2012-06-23 17:15 12 ----atw- c:\programdata\boost_interprocess\20076B58D850CD01\{1832B446-3F6D-4880-99C1-0B3B26170D94}
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\MAILA\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-03-19 137536]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2010-04-07 5758976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-01-07 1602856]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-04-06 495708]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-08 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-08 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-08 170008]
"FreeFallProtection"="c:\program files\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-08-02 726640]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-11-29 5249024]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-20 487562]
"DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2010-05-20 206336]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-11-04 2219184]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DBRMTray"="c:\dell\DBRM\Reminder\TrayApp.exe" [2010-02-04 7168]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}\Icon3E5562ED7.ico [2011-3-21 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer9"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\Drivers\CtAudDrv.sys [x]
R3 gupdatem;Servizio Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run [x]
S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe86.sys [x]
S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe86.sys [x]
S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe86.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [x]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Audio schermo Intel(R);c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-06-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-26 20:05]
.
2012-06-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2719283518-2909302424-3632810199-1000Core.job
- c:\users\MAILA\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-19 23:06]
.
2012-06-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2719283518-2909302424-3632810199-1000UA.job
- c:\users\MAILA\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-19 23:06]
.
2012-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-16 16:06]
.
2012-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-16 16:06]
.
.
------- Scansione supplementare -------
.
uStart Page =
https://www.google.it/IE: Invia immagine alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Invia pagina alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30po\UserChoice]
@Denied: (2) (S-1-5-21-2719283518-2909302424-3632810199-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30po"
.
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30pp\UserChoice]
@Denied: (2) (S-1-5-21-2719283518-2909302424-3632810199-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30pp"
.
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30ppf\UserChoice]
@Denied: (2) (S-1-5-21-2719283518-2909302424-3632810199-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30ppf"
.
[HKEY_USERS\S-1-5-21-2719283518-2909302424-3632810199-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (S-1-5-21-2719283518-2909302424-3632810199-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2012-06-28 18:47:35
ComboFix-quarantined-files.txt 2012-06-28 16:47
ComboFix2.txt 2012-06-28 14:22
ComboFix3.txt 2012-06-27 15:01
.
Pre-Run: 205.138.452.480 byte disponibili
Post-Run: 205.129.125.888 byte disponibili
.
- - End Of File - - AE615B14B7C6F0A8D71EE2B1DAF6A907