ComboFix 10-10-20.04 - pc 21/10/2010 14.05.57.1.2 - x86
Eseguito da: C:\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\desktop.ini
c:\documents and settings\All Users\Dati applicazioni\.wtav
c:\documents and settings\pc\Dati applicazioni\avdrn.dat
C:\index.htm
C:\Install.exe
c:\programmi\AnVi
C:\Thumbs.db
c:\windows\PRAGMApwmdxvncvk
c:\windows\PRAGMAyfqjixncbv
c:\windows\PRAGMAyfqjixncbv\PRAGMAc.dll
c:\windows\PRAGMAyfqjixncbv\PRAGMAcfg.ini
c:\windows\PRAGMAyfqjixncbv\PRAGMAd.sys
c:\windows\PRAGMAyfqjixncbv\PRAGMAsrcr.dat
c:\windows\ST6UNST.000
c:\windows\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\windows\system32\drivers\hwinterface.sys
c:\windows\System32\drivers\vbma39d2.sys
c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABE.exe
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PRAGMAPWMDXVNCVK
-------\Legacy_PRAGMAYFQJIXNCBV
-------\Service_PRAGMApwmdxvncvk
-------\Service_PRAGMAyfqjixncbv
-------\Legacy_hwinterface
-------\Service_hwinterface
-------\Service_vbma39d2
((((((((((((((((((((((((( Files Creati Da 2010-09-21 al 2010-10-21 )))))))))))))))))))))))))))))))))))
.
2010-10-20 14:12 . 2010-10-20 14:12 110080 ----a-r- c:\documents and settings\pc\Dati applicazioni\Microsoft\Installer\{9EFA7323-47A0-48E2-8F77-35DB5EED500A}\IconF7A21AF7.exe
2010-10-20 14:12 . 2010-10-20 14:12 110080 ----a-r- c:\documents and settings\pc\Dati applicazioni\Microsoft\Installer\{9EFA7323-47A0-48E2-8F77-35DB5EED500A}\IconD7F16134.exe
2010-10-20 14:12 . 2010-10-20 14:12 -------- d-----w- C:\sh4ldr
2010-10-20 14:12 . 2010-10-20 14:12 -------- d-----w- c:\programmi\Enigma Software Group
2010-10-20 14:12 . 2010-10-20 14:12 -------- d-----w- c:\windows\9EFA732347A048E28F7735DB5EED500A.TMP
2010-10-20 14:12 . 2010-10-20 14:12 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2010-10-20 13:42 . 2010-10-20 13:42 -------- d-----w- c:\documents and settings\pc\Dati applicazioni\Malwarebytes
2010-10-20 13:42 . 2010-10-20 15:15 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-10-20 13:42 . 2010-10-20 13:42 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-10-20 11:03 . 2010-10-20 12:49 -------- d-----w- C:\!KillBox
2010-10-20 11:02 . 2010-09-20 13:49 92672 ----a-w- C:\KillBox.exe
2010-10-20 09:09 . 2010-10-20 09:09 -------- d-----w- c:\documents and settings\pc\Dati applicazioni\Apple Computer
2010-10-19 15:47 . 2010-10-19 15:47 -------- d-----w- c:\programmi\File comuni\Skype
2010-10-19 15:32 . 2010-10-19 15:32 -------- d-----w- c:\documents and settings\pc\Impostazioni locali\Dati applicazioni\Sunbelt Software
2010-10-19 15:32 . 2010-10-20 15:17 -------- dc-h--w- c:\documents and settings\All Users\Dati applicazioni\{E961CE1B-C3EA-4882-9F67-F859B555D097}
2010-10-15 10:46 . 2010-10-15 10:46 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\CMUV
2010-10-15 08:10 . 2010-10-15 08:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Technisat
2010-10-15 08:10 . 2010-10-15 08:10 -------- d-----w- c:\programmi\DVBViewer TE2
2010-10-15 08:10 . 2010-10-15 08:10 -------- d-----w- c:\programmi\MainConcept
2010-10-15 08:09 . 2010-10-15 08:11 -------- d-----w- c:\programmi\TechniSat DVB
2010-10-15 08:09 . 2005-11-13 21:22 757760 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2010-10-15 08:09 . 2005-11-13 21:22 69715 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2010-10-15 08:09 . 2005-11-13 21:21 274432 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2010-10-15 08:09 . 2005-11-13 21:20 204800 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2010-10-15 08:09 . 2005-11-13 21:19 5632 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2010-10-15 08:09 . 2010-10-15 08:09 331908 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2010-10-15 08:09 . 2010-10-15 08:09 200836 ----a-w- c:\programmi\File comuni\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2010-10-15 07:53 . 2010-05-10 07:09 627288 ----a-w- c:\windows\system32\drivers\SkyNET.sys
2010-10-14 05:37 . 2010-10-21 11:57 -------- d-----w- c:\documents and settings\pc\Dati applicazioni\Toqalu
2010-10-08 11:25 . 2009-05-14 10:54 143360 ----a-w- c:\windows\system32\wdapi1001.dll
2010-10-08 11:25 . 2006-10-18 13:29 102400 ----a-w- c:\windows\system32\wdapi811.dll
2010-10-08 11:25 . 2002-01-05 01:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2010-10-08 11:25 . 2009-07-07 06:31 290904 ----a-w- c:\windows\system32\vc6-re200l.dll
2010-10-08 11:25 . 2009-07-07 06:31 73728 ----a-w- c:\windows\system32\RWUXThemeS.dll
2010-10-08 11:25 . 2009-05-20 10:46 5752320 ----a-w- c:\windows\system32\BCGCBPRO103090.dll
2010-10-08 11:25 . 2009-01-29 15:25 4419584 ----a-w- c:\windows\system32\BCGCBPRO10180.dll
2010-10-08 11:21 . 2010-10-08 11:28 -------- d-----w- C:\avr
2010-10-01 09:29 . 2010-10-21 12:16 -------- d-----w- c:\documents and settings\pc\Impostazioni locali\Dati applicazioni\LogMeIn Hamachi
2010-10-01 09:29 . 2010-10-21 12:16 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\LogMeIn Hamachi
2010-10-01 09:28 . 2010-10-01 09:28 -------- d-----w- c:\programmi\LogMeIn Hamachi
2010-09-22 15:54 . 2010-09-22 15:55 -------- d--h--w- c:\windows\msdownld.tmp
2010-09-22 15:54 . 2010-09-22 15:54 -------- d-----w- c:\programmi\Windows Media Components
2010-09-22 15:52 . 2005-01-14 07:32 53248 ----a-w- c:\windows\system32\PAStiSvc.exe
2010-09-22 15:51 . 2010-09-22 15:54 -------- d-----w- c:\programmi\PC Camera
2010-09-22 15:51 . 2010-09-22 15:51 -------- d-----w- c:\windows\PixArt
2010-09-22 15:51 . 2010-09-22 15:51 -------- d-----w- c:\programmi\File comuni\PCCamera
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-02-21 21:51 . 2007-06-26 09:27 66672 ----a-w- c:\programmi\mozilla firefox\components\jar50.dll
2007-02-21 21:51 . 2007-06-26 09:27 54376 ----a-w- c:\programmi\mozilla firefox\components\jsd3250.dll
2007-02-21 21:51 . 2007-06-26 09:27 34952 ----a-w- c:\programmi\mozilla firefox\components\myspell.dll
2007-02-21 21:51 . 2007-06-26 09:27 46720 ----a-w- c:\programmi\mozilla firefox\components\spellchk.dll
2007-02-21 21:51 . 2007-06-26 09:27 172144 ----a-w- c:\programmi\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-08 99840]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-03-02 110592]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"DAEMON Tools"="c:\programmi\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2009-09-05 417792]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2010-03-23 202256]
"PCMAgent"="c:\programmi\CyberLink\PowerCinema\PCMAgent.exe" [2008-10-21 143360]
"CLMLServer"="c:\programmi\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe" [2008-10-21 196608]
"TVEService"="c:\programmi\CyberLink\TV Enhance\TVEService.exe" [2008-11-28 180224]
"PlayMovie"="c:\programmi\CyberLink\PlayMovie\PMVService.exe" [2008-09-24 172032]
"LogMeIn Hamachi Ui"="c:\programmi\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"DivXUpdate"="c:\programmi\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"SpyHunter Security Suite"="c:\programmi\Enigma Software Group\SpyHunter\SpyHunter4.exe" [2010-09-21 4086104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Server4PC.lnk - c:\programmi\TechniSat DVB\bin\Server4PC.exe [2010-10-15 309848]
Tasto di scelta rapida per l'avvio di AutoCAD.lnk - c:\programmi\File comuni\Autodesk Shared\acstart17.exe [2006-3-5 11000]
VOIP321.lnk - c:\programmi\Philips\VOIP321\VOIP321.exe [2006-8-29 771072]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Programmi\\Microsoft Visual Studio\\Common\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programmi\\TVAnts\\Tvants.exe"=
"c:\\Programmi\\Digi\\XCTU\\X-CTU.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\COOL.STF\\TSReaderLite\\TSReaderLite.exe"=
"c:\\idirect\\isite\\iSite.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\BitTorrent\\bittorrent.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\CyberLink\\PowerCinema\\PowerCinema.exe"=
"c:\\Programmi\\CyberLink\\PlayMovie\\PlayMovie.exe"=
"c:\\Programmi\\CyberLink\\PlayMovie\\PMVService.exe"=
"c:\\Programmi\\CyberLink\\TV Enhance\\TVEnhance.exe"=
"c:\\Programmi\\CyberLink\\TV Enhance\\TVEService.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9001:UDP"= 9001:UDP:iDirect
"47553:UDP"= 47553:UDP:bbiitt
"4662:TCP"= 4662:TCP:emule TCP
"4672:UDP"= 4672:UDP:emule UDP
R1 UserPort;UserPort;c:\windows\system32\drivers\UserPort.sys [17/09/2007 11.16.43 4256]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\programmi\CyberLink\PlayMovie\000.fcl [05/07/2010 12.14.15 61424]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\programmi\LogMeIn Hamachi\hamachi-2.exe [30/03/2010 11.16.12 1107336]
R2 MapMemPlus;MapMemPlus;c:\windows\system32\drivers\MapMemPlus.sys [17/09/2007 10.09.50 63136]
R2 PortTalk;PortTalk;c:\windows\system32\drivers\porttalk.sys [17/09/2007 11.48.46 3567]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [21/09/2010 14.51.54 327000]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\programmi\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [05/07/2010 12.16.06 372831]
R2 TVESched;TVEnhance Task Scheduler (TTS));c:\programmi\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [05/07/2010 12.16.06 184413]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [22/03/2007 14.17.16 21632]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [15/10/2010 9.53.48 627288]
R3 SNXPCARD;Sunix PCI Multi I/O Card Driver;c:\windows\system32\drivers\snxpcard.sys [19/02/2008 11.08.34 20864]
R3 SNXPSERX;Sunix PCI Serial Port Driver;c:\windows\system32\drivers\snxpserx.sys [19/02/2008 11.08.53 54528]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\programmi\Lavasoft\Ad-Aware\AAWService.exe" --> c:\programmi\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 5DE6C4AB;5DE6C4AB; [x]
S3 ce6230;Intel CE6230 Standalone USB Driver;c:\windows\system32\drivers\CE6230StandaloneDriver.sys [09/10/2008 9.47.38 44800]
S3 ce6230BDACAP;Realfine CE6230 BDA Driver;c:\windows\system32\drivers\CE6230BDA.sys [09/10/2008 9.47.39 19328]
S3 Cebal;Cebal Driver (cebal.sys);c:\windows\system32\drivers\cebal.sys [23/09/2009 10.10.05 22912]
S3 DLPortIO;DriverLINX Port I/O Driver;c:\windows\system32\drivers\DLPORTIO.SYS [19/07/2010 14.23.14 3584]
S3 E1USB;Renesas E-Series USB Driver;c:\windows\system32\drivers\E1usb.sys [06/03/2008 14.41.57 46976]
S3 HmseUsb;FDM;c:\windows\system32\drivers\HmseUsb.sys [06/03/2008 14.41.57 26368]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\programmi\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\programmi\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [29/06/2007 2.01.48 42512]
S3 PAC207;USB PC Cam Plus;c:\windows\system32\drivers\PFC027.sys [24/02/2005 12.29.14 162176]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28/10/2008 15.38.32 642560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contenuto della cartella 'Scheduled Tasks'
2010-10-20 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-04-23 16:17]
2010-10-21 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-04-23 16:17]
2010-10-21 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-299502267-73586283-725345543-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-10-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-299502267-73586283-725345543-1003.job
- c:\programmi\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page =
hxxp://www.yahoo.com/mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/def ... earch.htmluInternet Settings,ProxyOverride = local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://us.rd.yahoo.com/customize/ie/def ... .yahoo.comIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Read with DeskBot
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {4819DFDF-ABC4-488C-A323-919848C51175}
DPF: {7876E4A5-78B7-4020-B08F-C960A1ED54C9} -
hxxp://www.myremotevision.com/WinWebPush.cabFF - ProfilePath - c:\documents and settings\pc\Dati applicazioni\Mozilla\Firefox\Profiles\2s95x5m5.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www2.firesearch.com/FF - prefs.js: browser.search.defaulturl -
hxxp://search.yahoo.com/search?fr=ffsp1&p=FF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?fr=ffds1&p=FF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?fr=ffds1&p=FF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?fr=ffds1&p=FF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?fr=ffds1&p=FF - prefs.js: browser.search.selectedEngine - Ask
FF - component: c:\documents and settings\pc\Dati applicazioni\Mozilla\Firefox\Profiles\2s95x5m5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll
FF - component: c:\documents and settings\pc\Dati applicazioni\Mozilla\Firefox\Profiles\2s95x5m5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll
FF - component: c:\progra~1\MOZILL~1\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - component: c:\programmi\Mozilla Firefox\components\xpinstal.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
.
------- Associazioni dei file -------
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-wuaucldt - c:\documents and settings\pc\wuaucldt.exe
HKLM-Run-\\Antenna\EPSON Stylus D88 Series - c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE
HKLM-Run-Automatico EPSON Stylus D88 Series su CRISTINA - c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\programmi\CyberLink\PlayMovie\000.fcl"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(3348)
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\programmi\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\E_S00RP1.EXE
c:\windows\system32\nvsvc32.exe
c:\programmi\CyberLink\Shared files\RichVideo.exe
c:\windows\System32\PAStiSvc.exe
c:\programmi\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Ora fine scansione: 2010-10-21 14:21:41 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-10-21 12:21
Pre-Run: 156.169.322.496 byte disponibili
Post-Run: 156.049.559.552 byte disponibili
- - End Of File - - 52DF030C7439AED0287AE07B97FD210D
questo è il log del combofix