Ringrazio anticipatamente
- Codice: Seleziona tutto
ComboFix 13-10-30.01 - Alberto 31/10/2013 16:49:10.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.8183.5930 [GMT 1:00]
Eseguito da: c:\users\Alberto\Desktop\ComboFix.exe
AV: McAfee Antivirus e antispyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
FW: McAfee Firewall *Disabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
SP: McAfee Antivirus e antispyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((( Files Creati Da 2013-09-28 al 2013-10-31 )))))))))))))))))))))))))))))))))))
.
.
2013-10-31 15:53 . 2013-10-31 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-29 18:14 . 2013-10-29 18:14 -------- d-----w- c:\programdata\Rumbic Studio
2013-10-29 18:10 . 2013-10-29 18:10 -------- d-----w- c:\program files (x86)\GameTop.com
2013-10-29 17:57 . 2013-10-29 17:57 -------- d-----w- c:\users\Alberto\AppData\Local\FilesFrog Update Checker
2013-10-29 17:57 . 2013-10-29 17:57 652020 ----a-w- c:\users\Alberto\AppData\Roaming\dosearches.exe
2013-10-29 17:56 . 2013-10-29 17:58 -------- d-----w- c:\program files (x86)\Songr
2013-10-29 17:56 . 2013-10-29 17:56 -------- d-----w- C:\Songr
2013-10-26 13:44 . 2013-10-26 13:44 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-10-25 17:26 . 2013-10-25 17:26 -------- d-----w- c:\program files (x86)\Bus Simulator 2
2013-10-23 16:38 . 2013-10-23 16:38 -------- d-----w- c:\users\Alberto\AppData\Local\McAfee File Lock
2013-10-23 16:35 . 2013-09-23 11:49 197704 ----a-w- c:\windows\system32\drivers\HipShieldK.sys
2013-10-23 16:25 . 2013-09-09 09:11 74560 ----a-w- c:\windows\system32\drivers\McPvDrv.sys
2013-10-23 16:25 . 2013-10-23 16:25 -------- d-----w- c:\users\Alberto\AppData\Local\McAfee Anti-Theft
2013-10-23 16:25 . 2013-10-23 16:34 -------- d-----w- c:\program files (x86)\Common Files\McAfee
2013-10-23 16:25 . 2013-09-24 18:29 70112 ----a-w- c:\windows\system32\drivers\cfwids.sys
2013-10-23 16:25 . 2013-09-24 18:25 343568 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2013-10-23 16:25 . 2013-09-24 18:22 781312 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2013-10-23 16:25 . 2013-09-24 18:21 519192 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2013-10-23 16:25 . 2013-09-24 18:20 310224 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2013-10-23 16:25 . 2013-09-24 18:19 179664 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2013-10-23 16:25 . 2013-10-25 09:19 -------- d-----w- c:\program files\McAfee
2013-10-23 16:24 . 2013-10-30 10:21 -------- d-----w- c:\program files (x86)\McAfee
2013-10-23 16:15 . 2013-10-23 16:36 -------- d-----w- c:\program files\Common Files\McAfee
2013-10-23 16:03 . 2013-10-23 16:03 -------- d-----w- c:\program files\stinger
2013-10-23 16:03 . 2013-10-23 16:03 -------- d-----w- C:\Stinger_Quarantine
2013-10-22 17:14 . 2013-10-24 17:16 -------- d-----w- c:\programdata\McAfee
2013-10-22 17:13 . 2013-10-22 17:13 -------- d-----w- C:\SiteAdvisor
2013-10-22 16:57 . 2013-10-22 16:57 -------- d-----w- c:\users\Alberto\AppData\Roaming\Malwarebytes
2013-10-22 16:56 . 2013-10-22 16:56 -------- d-----w- c:\programdata\Malwarebytes
2013-10-22 09:30 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0725B73-0703-4285-AE0C-7AF2EEAAC919}\mpengine.dll
2013-10-20 11:13 . 2013-10-20 11:15 -------- d-----w- c:\windows\system32\MRT
2013-10-19 14:55 . 2013-10-19 14:55 -------- d-----w- C:\Nuova cartella
2013-10-14 16:51 . 2013-10-30 10:31 -------- d-----w- C:\STELLA
2013-10-12 13:33 . 2013-09-04 12:12 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-12 13:33 . 2013-09-04 12:11 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-12 13:33 . 2013-09-04 12:11 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-10-12 13:33 . 2013-09-04 12:11 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-12 13:33 . 2013-09-04 12:11 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-12 13:33 . 2013-09-04 12:11 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-10-12 13:33 . 2013-09-04 12:11 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-10-10 16:36 . 2013-10-10 16:36 -------- d-----w- c:\users\Alberto\AppData\Local\Diagnostics
2013-10-10 15:35 . 2013-10-10 15:35 -------- d-----w- c:\program files (x86)\eMule
2013-10-09 16:48 . 2013-10-10 15:31 -------- d-----w- c:\program files (x86)\lsm
2013-10-09 16:41 . 2013-10-09 16:41 -------- d-----w- c:\program files (x86)\Rooby Run
2013-10-09 16:38 . 2013-10-09 16:38 -------- d-----w- C:\FRUTTI
2013-10-09 16:28 . 2013-10-22 16:21 -------- d-----w- c:\programdata\Playrix Entertainment
2013-10-09 15:51 . 2013-10-09 15:51 -------- d-----w- c:\program files (x86)\Bus Driver
2013-10-09 15:45 . 2013-10-09 16:03 -------- d-----w- c:\programdata\SugarGames
2013-10-09 15:42 . 2013-10-29 18:11 -------- d-----w- C:\GIOCHI
2013-10-09 15:41 . 2013-10-09 17:49 -------- d-----w- c:\users\Alberto\AppData\Local\eMule
2013-10-09 15:40 . 2013-10-09 15:40 -------- d-----w- c:\users\Alberto\AppData\Roaming\AlderGames
2013-10-09 15:32 . 2013-10-09 16:21 -------- d-----w- c:\program files (x86)\MyPlayCity.com
2013-10-09 15:23 . 2013-10-09 15:23 -------- d-----w- c:\programdata\BigFishGames
2013-10-09 15:21 . 2013-10-09 15:21 -------- d-----w- c:\program files (x86)\Chuzzle - Christmas Edition
2013-10-09 15:19 . 2013-10-09 15:19 -------- d-----w- c:\programdata\Big Fish
2013-10-09 15:19 . 2013-10-09 15:21 -------- d-----w- c:\program files (x86)\bfgclient
2013-10-09 15:17 . 2013-10-09 15:21 -------- d-----w- c:\users\Alberto\AppData\Local\Big Fish
2013-10-09 15:17 . 2013-10-09 15:22 -------- d-----w- C:\BigFishCache
2013-10-08 18:05 . 2012-06-09 18:21 178688 ----a-w- c:\windows\SysWow64\unrar.dll
2013-10-08 18:05 . 2013-10-08 18:05 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack
2013-10-08 18:05 . 2013-10-08 18:05 -------- d-----w- c:\users\Alberto\AppData\Local\Programs
2013-10-08 18:04 . 2013-10-08 18:04 -------- d-----w- c:\program files (x86)\Alfabook
2013-10-08 12:07 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-10-08 12:07 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-10-07 18:45 . 2013-10-07 18:45 388096 ----a-r- c:\users\Alberto\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-10-07 18:45 . 2013-10-07 18:45 -------- d-----w- c:\program files (x86)\Trend Micro
2013-10-07 18:28 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-10-07 18:28 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-10-07 17:43 . 2013-10-07 17:43 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-07 17:42 . 2013-10-13 14:27 -------- d-----w- c:\users\Alberto\AppData\Local\ElevatedDiagnostics
2013-10-07 17:30 . 2013-10-07 17:30 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2013-10-07 17:18 . 2013-10-10 20:00 -------- d-----w- c:\program files\Microsoft Silverlight
2013-10-07 17:18 . 2013-10-10 20:00 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2013-10-07 17:12 . 2013-10-07 17:12 -------- d-----w- c:\windows\it
2013-10-07 17:12 . 2013-10-07 17:12 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-10-07 17:11 . 2013-10-07 17:11 -------- dc----w- c:\windows\system32\DRVSTORE
2013-10-07 17:11 . 2013-02-05 20:06 57840 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2013-10-07 17:11 . 2013-10-07 17:11 -------- d-----w- c:\program files\Windows Live
2013-10-07 17:11 . 2013-10-07 17:12 -------- d-----w- c:\program files (x86)\Windows Live
2013-10-07 17:10 . 2010-06-02 02:55 77656 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2013-10-07 17:10 . 2010-06-02 02:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2013-10-07 17:10 . 2010-06-02 02:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2013-10-07 17:10 . 2010-06-02 02:55 518488 ----a-w- c:\windows\system32\XAudio2_7.dll
2013-10-07 17:10 . 2010-05-26 09:41 2526056 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2013-10-07 17:10 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2013-10-07 17:10 . 2010-05-26 09:41 276832 ----a-w- c:\windows\system32\d3dx11_43.dll
2013-10-07 17:10 . 2010-05-26 09:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2013-10-07 17:07 . 2009-09-04 15:29 453456 ----a-w- c:\windows\SysWow64\d3dx10_42.dll
2013-10-07 17:07 . 2009-09-04 15:29 523088 ----a-w- c:\windows\system32\d3dx10_42.dll
2013-10-07 17:05 . 2006-11-29 11:06 4398360 ----a-w- c:\windows\system32\d3dx9_32.dll
2013-10-07 17:05 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\SysWow64\d3dx9_32.dll
2013-10-07 17:05 . 2013-10-07 17:05 -------- d-----w- c:\program files (x86)\Microsoft SkyDrive
2013-10-07 17:05 . 2013-10-07 17:05 -------- d-----w- c:\programdata\Microsoft SkyDrive
2013-10-07 17:04 . 2013-10-07 17:40 -------- d-----w- c:\users\Alberto\AppData\Local\Windows Live
2013-10-07 17:03 . 2013-10-07 17:03 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2013-10-07 17:02 . 2013-06-06 09:52 63096 ----a-w- c:\windows\system32\drivers\TMUSB64.sys
2013-10-07 16:54 . 2013-10-07 16:54 -------- d-----w- c:\programdata\UDL
2013-10-07 16:52 . 2002-07-25 15:06 282624 ----a-w- c:\program files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2013-10-07 16:50 . 2002-12-05 12:10 155648 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2013-10-07 16:50 . 2002-12-02 13:22 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2013-10-07 16:50 . 2002-12-02 11:33 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2013-10-07 16:50 . 2002-12-02 11:33 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2013-10-07 16:50 . 2013-10-07 16:50 282756 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2013-10-07 16:50 . 2013-10-07 16:50 163972 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2013-10-07 16:50 . 2003-02-27 14:12 696320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2013-10-07 16:50 . 2013-10-30 18:48 -------- d-----w- C:\WEB
2013-10-07 16:48 . 2013-10-07 17:36 -------- d-----w- c:\users\Alberto\AppData\Roaming\Epson
2013-10-07 16:48 . 2013-10-07 16:53 -------- d-----w- c:\program files (x86)\Epson Software
2013-10-07 16:47 . 2013-10-07 16:47 -------- d-----w- c:\program files\EpsonNet
2013-10-07 16:46 . 2013-10-07 16:46 -------- d-----w- c:\program files (x86)\Common Files\EPSON
2013-10-07 16:45 . 2013-10-13 15:21 -------- d-----w- c:\program files (x86)\EpsonNet
2013-10-07 16:43 . 2007-06-21 22:10 501912 ----a-w- c:\windows\SysWow64\PICSDK2.dll
2013-10-07 16:43 . 2006-10-30 22:10 71840 ----a-w- c:\windows\SysWow64\EPPicMgr.dll
2013-10-07 16:43 . 2006-10-30 22:10 120992 ----a-w- c:\windows\SysWow64\EpPicPrt.dll
2013-10-07 16:43 . 2006-10-19 22:10 80024 ----a-w- c:\windows\SysWow64\PICSDK.dll
2013-10-07 16:43 . 2006-10-19 22:10 108704 ----a-w- c:\windows\SysWow64\PICEntry.dll
2013-10-07 16:43 . 2013-10-07 16:43 -------- d-----w- c:\users\Alberto\AppData\Roaming\InstallShield
2013-10-07 16:42 . 2008-11-12 12:00 118784 ----a-w- c:\windows\system32\E_ILMFRE.DLL
2013-10-07 16:42 . 2008-11-12 12:00 81920 ----a-w- c:\windows\system32\E_IBCBFRE.DLL
2013-10-07 16:42 . 2007-04-10 10:06 10752 ----a-w- c:\windows\system32\E_GCINST.DLL
2013-10-07 16:42 . 2013-10-07 16:56 -------- d-----w- c:\programdata\EPSON
2013-10-07 16:42 . 2009-04-30 22:00 17408 ----a-w- c:\windows\system32\esxcdev.dll
2013-10-07 16:42 . 2009-04-30 22:00 128392 ----a-w- c:\windows\system32\esdevapp.exe
2013-10-07 16:42 . 2008-11-16 22:00 459776 ----a-w- c:\windows\system32\esxwiaud.dll
2013-10-07 16:42 . 2013-10-07 16:55 -------- d-----w- c:\program files (x86)\epson
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-07 17:11 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-10-07 09:57 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2013-10-07 09:57 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2013-09-25 23:46 . 2013-03-13 09:55 80541720 ----a-w- c:\windows\system32\MRT.exe
2013-09-24 18:25 . 2012-04-13 19:15 182752 ----a-w- c:\windows\system32\mfevtps.exe
2013-09-20 07:38 . 2013-09-20 07:38 10856 ----a-w- c:\windows\system32\drivers\mfeclnrk.sys
2013-09-20 07:38 . 2013-09-20 07:38 95984 ----a-w- c:\windows\system32\drivers\mfencrk.sys
2013-09-20 07:37 . 2013-09-20 07:37 390552 ----a-w- c:\windows\system32\drivers\mfencbdc.sys
2013-09-03 12:35 . 2013-03-13 07:59 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-29 01:48 . 2013-10-10 15:22 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-07-15 1668664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2009-06-22 60464]
"UpdatePRCShortCut"="c:\program files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"FUFAXSTM"="c:\program files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-06-04 843776]
"EEventManager"="c:\progra~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-09-24 537512]
"mcpltui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-09-24 537512]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
c:\users\Stella\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ritaglio schermata e avvio di OneNote 2007.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R2 Log S.M.;Log Session Manager;c:\program files (x86)\LSM\lsm.exe;c:\program files (x86)\LSM\lsm.exe [x]
R2 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys;c:\windows\SYSNATIVE\drivers\HipShieldK.sys [x]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe;c:\progra~1\mcafee\msc\mcawfwk.exe [x]
R3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\DRIVERS\mfencrk.sys;c:\windows\SYSNATIVE\DRIVERS\mfencrk.sys [x]
R3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 ahcix64s;ahcix64s;c:\windows\system32\DRIVERS\ahcix64s.sys;c:\windows\SYSNATIVE\DRIVERS\ahcix64s.sys [x]
S0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys;c:\windows\SYSNATIVE\drivers\McPvDrv.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys [x]
S2 AUS;Auto Update Service;c:\program files (x86)\LSM\aus.exe;c:\program files (x86)\LSM\aus.exe [x]
S2 HomeNetSvc;McAfee Home Network;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
S2 McAPExe;McAfee AP Service;c:\program files\McAfee\MSC\McAPExe.exe;c:\program files\McAfee\MSC\McAPExe.exe [x]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
S2 mcpltsvc;McAfee Platform Services;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
S2 mfecore;McAfee Anti-Malware Core;c:\program files\Common Files\McAfee\AMCore\mcshield.exe;c:\program files\Common Files\McAfee\AMCore\mcshield.exe [x]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys [x]
S3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\DRIVERS\mfencbdc.sys;c:\windows\SYSNATIVE\DRIVERS\mfencbdc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 WSDScan;Supporto digitalizzazione WSD tramite UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contenuto della cartella 'Scheduled Tasks'
.
2013-10-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-07 17:44]
.
2013-10-30 c:\windows\Tasks\Epson Printer Software Downloader.job
- c:\program files (x86)\EPSON\EPAPDL\E_SAPDL2.EXE [2009-05-26 09:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-04 186904]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2009-07-08 610360]
"fssui"="c:\program files (x86)\Windows Live\Family Safety\fsui.exe" [2013-02-05 892416]
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://www.dosearches.com/?utm_source=b&utm_medium=smt&utm_campaign=eXQ&utm_content=hp&from=smt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5P46379863798&ts=1383069428
mStart Page = hxxp://www.dosearches.com/?utm_source=b&utm_medium=smt&utm_campaign=eXQ&utm_content=hp&from=smt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5P46379863798&ts=1383069428
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Alberto\AppData\Roaming\Mozilla\Firefox\Profiles\id4cghps.default\
FF - prefs.js: browser.search.selectedEngine - Casella di ricerca Secure
FF - prefs.js: browser.startup.homepage - hxxp://www.dosearches.com/?utm_source=b&utm_medium=smt&utm_campaign=eXQ&utm_content=hp&from=smt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5P46379863798&ts=1383069428
FF - prefs.js: keyword.URL - hxxp://it.search.yahoo.com/search?fr=mcafee&p=
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
ShellIconOverlayIdentifiers-{F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
ShellIconOverlayIdentifiers-{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
ShellIconOverlayIdentifiers-{BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
ShellIconOverlayIdentifiers-{F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
ShellIconOverlayIdentifiers-{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
ShellIconOverlayIdentifiers-{BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{F36B3A4C-F95654BD-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2013-10-31 16:55:05
ComboFix-quarantined-files.txt 2013-10-31 15:55
.
Pre-Run: 914.985.926.656 byte disponibili
Post-Run: 915.193.528.320 byte disponibili
.
- - End Of File - - 57A64CDAC8EA01237C814C7144D04511
A36C5E4F47E84449FF07ED3517B43A31
- Codice: Seleziona tutto
# AdwCleaner v3.010 - Report created 31/10/2013 at 17:49:11
# Updated 20/10/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Alberto - ALBERTO-PC
# Running from : C:\Users\Alberto\Desktop\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16720
-\\ Mozilla Firefox v19.0.2 (it)
[ File : C:\Users\Alberto\AppData\Roaming\Mozilla\Firefox\Profiles\id4cghps.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2192 octets] - [23/10/2013 16:40:20]
AdwCleaner[R1].txt - [2252 octets] - [23/10/2013 16:43:56]
AdwCleaner[R2].txt - [2045 octets] - [31/10/2013 17:25:46]
AdwCleaner[R3].txt - [1078 octets] - [31/10/2013 17:48:46]
AdwCleaner[S0].txt - [2357 octets] - [23/10/2013 16:44:19]
AdwCleaner[S1].txt - [1835 octets] - [31/10/2013 17:26:11]
AdwCleaner[S2].txt - [1001 octets] - [31/10/2013 17:49:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1061 octets] ##########