di sabino90 » 29/06/12 19:45
Penso di aver fatto tutto correttamente....
ComboFix 12-06-28.03 - Sabino 29/06/2012 20:17:44.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.3037.1711 [GMT 2:00]
Eseguito da: c:\users\Sabino\Desktop\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: STOPzilla Anti-Spyware *Disabled/Updated* {B2E69928-50DC-94CA-6A80-AAB054008761}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\IMinent Toolbar\tbHElper.dll
c:\programdata\master
c:\programdata\PCDr\5907\Downloads\9a727e3b-3b75-44f1-aa0c-b5b6cd760030.dll
c:\programdata\PCDr\5907\Downloads\a31dcb19-c462-4b91-b5af-0c0196d8d501.dll
c:\users\Public\Documents\bootracer.tmp
c:\users\Sabino\AppData\Local\TempDIR
c:\users\Sabino\AppData\Roaming\cacaoweb
c:\users\Sabino\AppData\Roaming\cacaoweb\npdfile.dat
c:\users\Sabino\AppData\Roaming\cacaoweb\replicating1AFB0C60785431CB71CDF4BB69EB92AC.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicating30190FED0394B9C907494415EB5F6D6A.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicating5E00F858D61F480D9F19FFB56F7229E5.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicating6057725AA684A842BF4E7F266453A8C6.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicating8A8C6E7EBECC3C0368C261096A91D74E.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicating8B23EEBC4D036AF175776980EE0E6F17.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicating9B64844528E43E5D3967A7D95DEF290D.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicating9FFB6F30563C1B5CB526667651E9B229.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicatingB805892A30CA8DA5A88BC7FCD4D80C93.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicatingB80CDD3EB56741670F735AD2658E54B9.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\replicatingE4EBDCD799A8BF41631B0C2C5D9CE662.cacao
c:\users\Sabino\AppData\Roaming\cacaoweb\storage.db
c:\users\Sabino\AppData\Roaming\OfferBox
c:\users\Sabino\AppData\Roaming\OfferBox\config.dat
c:\users\Sabino\AppData\Roaming\OfferBox\config.xml
c:\windows\security\Database\tmp.edb
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\system32\drivers\npf.sys
.
La copia infetta di c:\windows\system32\userinit.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_NPF
.
.
((((((((((((((((((((((((( Files Creati Da 2012-05-28 al 2012-06-29 )))))))))))))))))))))))))))))))))))
.
.
2012-06-29 18:33 . 2012-06-29 18:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-29 16:43 . 2012-06-29 16:43 388096 ----a-r- c:\users\Sabino\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-29 16:43 . 2012-06-29 16:43 -------- d-----w- c:\program files\Trend Micro
2012-06-29 16:33 . 2012-01-12 07:26 101112 ----a-r- c:\windows\system32\drivers\SBREDrv.sys
2012-06-29 16:32 . 2012-06-29 16:34 -------- d-----w- c:\program files\STOPzilla!
2012-06-29 16:32 . 2012-06-29 18:37 -------- d-----w- c:\programdata\STOPzilla!
2012-06-29 16:32 . 2012-06-29 16:32 -------- d-----w- c:\program files\Common Files\iS3
2012-06-26 08:12 . 2012-06-26 08:12 -------- d-----w- c:\users\Sabino\AppData\Roaming\CheckPoint
2012-06-26 08:01 . 2012-06-26 08:01 -------- d-----w- c:\programdata\CheckPoint
2012-06-25 23:51 . 2012-06-28 10:38 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-06-22 09:47 . 2012-06-29 10:18 -------- d-----w- c:\users\Sabino\AppData\Local\Spotify
2012-06-22 09:47 . 2012-06-29 16:28 -------- d-----w- c:\users\Sabino\AppData\Roaming\Spotify
2012-06-22 09:06 . 2012-06-22 09:06 -------- d-----w- c:\program files\Oracle
2012-06-22 08:50 . 2012-05-04 17:29 772504 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-21 15:40 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-21 15:40 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-21 15:40 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-21 15:40 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-21 15:40 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-21 15:40 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-21 15:40 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-21 15:39 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-21 15:39 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-14 09:28 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\system32\msi.dll
2012-06-14 09:28 . 2012-04-28 03:17 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-14 09:28 . 2012-05-15 01:05 2343936 ----a-w- c:\windows\system32\win32k.sys
2012-06-14 09:28 . 2012-04-26 04:45 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-06-14 09:28 . 2012-05-01 04:44 164352 ----a-w- c:\windows\system32\profsvc.dll
2012-06-14 09:28 . 2012-04-26 04:45 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-06-14 09:28 . 2012-04-26 04:41 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-06-14 09:28 . 2012-04-24 04:36 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2012-06-14 09:28 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\system32\crypt32.dll
2012-06-14 09:28 . 2012-04-24 04:36 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-06-10 18:06 . 2012-06-10 18:06 -------- d-----w- c:\programdata\TomTom
2012-06-10 17:58 . 2012-06-10 17:58 -------- d-----w- c:\program files\TomTom International B.V
2012-06-10 17:57 . 2012-06-10 17:57 -------- d-----w- c:\program files\TomTom HOME 2
2012-05-31 08:46 . 2012-05-31 08:46 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin7.dll
2012-05-31 08:46 . 2012-05-31 08:46 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin6.dll
2012-05-31 08:46 . 2012-05-31 08:46 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin5.dll
2012-05-31 08:46 . 2012-05-31 08:46 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin4.dll
2012-05-31 08:46 . 2012-05-31 08:46 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin3.dll
2012-05-31 08:46 . 2012-05-31 08:46 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin2.dll
2012-05-31 08:46 . 2012-05-31 08:46 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-29 18:20 . 2012-06-29 16:55 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B725F92D-E00B-433E-8D2C-56DE1F3ECCB6}\offreg.dll
2012-06-24 08:39 . 2012-04-07 08:42 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-24 08:39 . 2011-05-19 06:51 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-31 03:41 . 2012-06-29 09:23 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B725F92D-E00B-433E-8D2C-56DE1F3ECCB6}\mpengine.dll
2012-05-04 17:29 . 2010-05-03 13:48 687504 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-25 09:35 . 2012-04-25 09:35 23376 ----a-r- c:\windows\system32\SZIO5.dll
2012-04-25 09:35 . 2012-04-25 09:35 546640 ----a-r- c:\windows\system32\SZComp5.dll
2012-04-25 09:35 . 2012-04-25 09:35 481104 ----a-r- c:\windows\system32\SZBase5.dll
2012-04-25 09:21 . 2012-04-25 09:21 73136 ----a-r- c:\windows\system32\drivers\SZKGFS.sys
2012-04-19 15:39 . 2012-04-19 15:39 29008 ----a-r- c:\windows\system32\IS3XDat5.dll
2012-04-19 15:39 . 2012-04-19 15:39 231248 ----a-r- c:\windows\system32\IS3Win325.dll
2012-04-19 15:39 . 2012-04-19 15:39 390992 ----a-r- c:\windows\system32\IS3UI5.dll
2012-04-19 15:39 . 2012-04-19 15:39 100176 ----a-r- c:\windows\system32\IS3Svc5.dll
2012-04-19 15:39 . 2012-04-19 15:39 104272 ----a-r- c:\windows\system32\IS3Inet5.dll
2012-04-19 15:39 . 2012-04-19 15:39 67408 ----a-r- c:\windows\system32\IS3Hks5.dll
2012-04-19 15:39 . 2012-04-19 15:39 132944 ----a-r- c:\windows\system32\IS3HTUI5.dll
2012-04-19 15:39 . 2012-04-19 15:39 456528 ----a-r- c:\windows\system32\IS3DBA5.dll
2012-04-19 15:39 . 2012-04-19 15:39 808784 ----a-r- c:\windows\system32\IS3Base5.dll
2012-04-18 18:56 . 2012-04-18 18:56 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2012-04-18 18:56 . 2012-04-18 18:56 69632 ----a-w- c:\windows\system32\QuickTime.qts
2012-04-12 04:52 . 2011-09-24 13:34 27144 ----a-w- c:\windows\system32\nitrolocalmon2.dll
2012-04-12 04:52 . 2011-09-24 13:34 18440 ----a-w- c:\windows\system32\nitrolocalui2.dll
2012-04-04 13:56 . 2012-02-08 10:29 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2008-10-28 11:41 . 2009-12-05 08:58 238896 ----a-w- c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll
2008-10-28 11:41 . 2009-12-05 08:58 210320 ----a-w- c:\program files\mozilla firefox\plugins\ctdomemhelper.dll
2008-10-28 11:41 . 2009-12-05 08:58 83248 ----a-w- c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll
2008-10-28 11:41 . 2009-12-05 08:58 431512 ----a-w- c:\program files\mozilla firefox\plugins\ctplayerobject.dll
2008-10-28 11:41 . 2009-12-05 08:58 464176 ----a-w- c:\program files\mozilla firefox\plugins\imagickrt.dll
2008-10-28 11:41 . 2009-12-05 08:58 144688 ----a-w- c:\program files\mozilla firefox\plugins\rlcontentclass.dll
2008-10-28 11:41 . 2009-12-05 08:58 210224 ----a-w- c:\program files\mozilla firefox\plugins\RLMusicPacker.dll
2008-10-28 11:41 . 2009-12-05 08:58 111920 ----a-w- c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll
2008-10-28 11:41 . 2009-12-05 08:58 218416 ----a-w- c:\program files\mozilla firefox\plugins\RLVoicePacker.dll
2008-10-28 11:41 . 2009-12-05 08:58 173360 ----a-w- c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-12-16 258512]
.
c:\users\Sabino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
My 190.lnk - c:\program files\My 190\My 190.exe [2012-3-15 142336]
tcbhn.lnk - c:\users\Sabino\AppData\Roaming\BrowserCompanion\tcbhn.exe [2012-3-27 692888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
@="Service"
.
R0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [x]
R2 DeviceExpert;DeviceExpert;c:\manageengine\DeviceExpert\bin\wrapper.exe [x]
R2 gupdate;Servizio di Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 gupdatem;Servizio Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 KMWDFILTERx86;HIDServiceDesc;c:\windows\system32\DRIVERS\KMWDFILTER.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 ONDA_MW823UP_cdc_acm;ONDA MW823UP CDC-ACM driver;c:\windows\system32\DRIVERS\ONDA_MW823UP_cdc_acm.sys [x]
R3 ONDA_MW823UP_cdc_ecm;ONDA_MW823UP_cdc_ecm;c:\windows\system32\DRIVERS\ONDA_MW823UP_cdc_ecm.sys [x]
R3 ONDA_MW823UP_cpo;ONDA MW823UP Install;c:\windows\system32\DRIVERS\ONDA_MW823UP_cpo.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys [x]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys [x]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9334b3396d450a95\aestsrv.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Pianificatore;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 E2ECAP;CamDirector - WDM Video Capture;c:\windows\system32\DRIVERS\e2ecap.sys [x]
S2 MsgPlusService;Messenger Plus! Service;c:\program files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 NitroDriverReadSpool2;NitroPDFDriverCreatorReadSpool2;c:\program files\Nitro PDF\Professional 7\NitroPDFDriverService2.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe [x]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [x]
S3 ONDA_MW823UP_dc_enum;ONDA MW823UP DC Enumerator;c:\windows\system32\DRIVERS\ONDA_MW823UP_dc_enum.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-06-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 08:39]
.
2012-06-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1452159324-766955113-3666706478-1001Core.job
- c:\users\Sabino\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-08-29 11:04]
.
2012-06-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1452159324-766955113-3666706478-1001UA.job
- c:\users\Sabino\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-08-29 11:04]
.
2012-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-03 14:23]
.
2012-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-03 14:23]
.
2012-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1452159324-766955113-3666706478-1001Core.job
- c:\users\Sabino\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-07 17:28]
.
2012-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1452159324-766955113-3666706478-1001UA.job
- c:\users\Sabino\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-07 17:28]
.
2012-06-27 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-04-13 05:40]
.
2012-06-29 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-04-13 05:40]
.
.
------- Scansione supplementare -------
.
uInternet Settings,ProxyServer = 127.0.0.1:20069
IE: E&sporta in Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 62.101.93.101 83.103.25.250
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files\BrowserCompanion\tdataprotocol.dll
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files\BrowserCompanion\tdataprotocol.dll
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files\BrowserCompanion\tdataprotocol.dll
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Toolbar-10 - (no file)
WebBrowser-{08D495AB-A86C-47B0-82EF-DA87BF92F730} - (no file)
WebBrowser-{1D03A978-AC0C-4004-B9FD-9CF361C7BD3F} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
AddRemove-Revo Uninstaller - c:\program files\VS Revo Group\Revo Uninstaller\uninst.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe
AddRemove-{7585478E9D9B42108671C12F8714CEFE} - c:\program files\DivX\DivXConverterUninstall.exe
AddRemove-FoxTab PDF Converter - c:\program files\FoxTabPDFConverter\Uninstall\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{E9D79540-57D5953E-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"=hex:51,66,7a,6c,4c,1d,38,12,a2,ea,69,
93,b1,e1,86,00,e1,15,a1,39,87,48,a6,c1
"{99079A25-328F-4BD4-BE04-00955ACAA0A7}"=hex:51,66,7a,6c,4c,1d,38,12,4b,99,14,
9d,bd,7c,ba,0e,c1,12,43,d5,5f,94,e4,b3
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,
36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0
"{58124A0B-DC32-4180-9BFF-E0E21AE34026}"=hex:51,66,7a,6c,4c,1d,38,12,65,49,01,
5c,00,92,ee,04,e4,e9,a3,a2,1f,bd,04,32
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9D717F81-9148-4F12-8568-69135F087DB0}"=hex:51,66,7a,6c,4c,1d,38,12,ef,7c,62,
99,7a,df,7c,0a,fa,7e,2a,53,5a,56,39,a4
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{FAE12866-E91C-43AC-AF75-8D7E316F15B8}"=hex:51,66,7a,6c,4c,1d,38,12,08,2b,f2,
fe,2e,a7,c2,06,d0,63,ce,3e,34,31,51,ac
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:1a,65,ca,76,b0,e4,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,59,15,13,1b,ee,a7,e3,4e,a4,2a,84,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,59,15,13,1b,ee,a7,e3,4e,a4,2a,84,\
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariDownload"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (S-1-5-21-1452159324-766955113-3666706478-1001)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (S-1-5-21-1452159324-766955113-3666706478-1001)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariExtension"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (S-1-5-21-1452159324-766955113-3666706478-1001)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (S-1-5-21-1452159324-766955113-3666706478-1001)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (S-1-5-21-1452159324-766955113-3666706478-1001)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{085C8E5C-29C2-1D40-6C81-91F69A9F818C}*]
"danmlean"=hex:64,62,61,68,6d,69,66,6f,65,68,6c,62,69,6d,61,68,6a,68,6f,69,62,
69,70,64,68,6f,61,70,68,6b,6f,6e,69,66,65,63,64,6f,61,62,00,00
"iaehgpmbppdcjpekpd"=hex:6a,61,64,61,6f,65,6d,68,70,68,62,64,65,67,68,6b,70,67,
66,68,00,f8
"hakgahpcgjiieclf"=hex:6a,61,64,61,6f,65,6d,68,70,68,62,64,65,67,68,6b,70,67,
66,68,00,f2
.
[HKEY_USERS\S-1-5-21-1452159324-766955113-3666706478-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4D52BFF7-A97A-3BF5-1107-844FE0A90DB4}*]
@Allowed: (Read) (RestrictedCode)
"bbmhioncpnnecmaddhomogjfmbedcbmoljfg"=hex:6a,61,61,6e,66,70,6b,66,6a,6f,61,66,
65,62,63,6a,6d,6e,6c,61,00,00
"abgileelihjkjeophgjgbamcoblokpglnl"=hex:6a,61,61,6e,66,70,6b,66,6a,6f,61,66,
65,62,63,6a,6d,6e,6c,61,00,00
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'Explorer.exe'(2956)
c:\windows\System32\bthprops.cpl
c:\windows\System32\hgcpl.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Common Files\iS3\Anti-Spyware\SZServer.exe
c:\windows\system32\taskhost.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\program files\STOPzilla!\STOPzilla.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
c:\users\Sabino\AppData\Local\Google\Chrome\Application\chrome.exe
c:\users\Sabino\AppData\Local\Google\Chrome\Application\chrome.exe
c:\users\Sabino\AppData\Local\Google\Chrome\Application\chrome.exe
c:\users\Sabino\AppData\Local\Google\Chrome\Application\chrome.exe
c:\users\Sabino\AppData\Local\Google\Chrome\Application\chrome.exe
c:\users\Sabino\AppData\Local\Google\Chrome\Application\chrome.exe
.
**************************************************************************
.
Ora fine scansione: 2012-06-29 20:46:43 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-06-29 18:46
.
Pre-Run: 144.869.335.040 byte disponibili
Post-Run: 144.201.990.144 byte disponibili
.
- - End Of File - - D69A28545076B8F1652982DBC58435CB