ecco l'altra meta
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 19:43 . 2010-01-05 19:43 20 ----a-w- c:\windows\system32\config\systemprofile\Dati applicazioni\fvgqad.dat
2010-01-05 17:47 . 2009-03-24 18:40 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\uTorrent
2010-01-05 15:30 . 2009-07-31 22:08 -------- d-----w- c:\programmi\File comuni\Nero
2010-01-05 15:29 . 2009-07-31 22:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2010-01-05 13:03 . 2008-03-23 11:53 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-29 19:43 . 2008-01-19 12:08 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\U3
2009-12-24 17:18 . 2009-11-18 10:44 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\ESET
2009-12-22 13:26 . 2009-06-28 19:36 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Audacity
2009-12-18 16:16 . 2009-03-21 21:22 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\gtk-2.0
2009-12-18 16:14 . 2009-05-27 16:57 -------- d-----w- c:\programmi\GIMP-2.0
2009-12-17 16:08 . 2009-11-11 12:02 -------- d-----w- c:\programmi\VS Revo Group
2009-12-06 19:03 . 2009-12-06 19:03 7276 ----a-w- c:\windows\system32\5cs9arse3z.dll
2009-12-02 15:10 . 2009-12-02 15:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Messenger Plus!
2009-12-02 13:44 . 2009-12-02 13:44 -------- d-----w- c:\programmi\Messenger Plus! Live
2009-11-30 14:28 . 2008-05-14 19:22 -------- d-----w- c:\programmi\Windows Live
2009-11-25 13:23 . 2009-11-25 13:23 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Thinstall
2009-11-10 12:50 . 2009-11-10 12:50 311053 ----a-w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\xpiar.exe
2009-10-25 13:08 . 2004-08-30 10:50 81512 ----a-w- c:\windows\system32\perfc010.dat
2009-10-25 13:08 . 2004-08-30 10:50 468772 ----a-w- c:\windows\system32\perfh010.dat
2009-03-16 12:36 . 2009-03-16 12:36 13264160 ----a-w- c:\programmi\dxnt.cab
2009-03-16 12:36 . 2009-03-16 12:36 1155483 ----a-w- c:\programmi\BDANT.cab
2009-03-16 12:36 . 2009-03-16 12:36 975148 ----a-w- c:\programmi\BDAXP.cab
2009-03-16 12:36 . 2009-03-16 12:36 95296 ----a-w- c:\programmi\dxupdate.cab
2009-03-16 12:36 . 2009-03-16 12:36 1691464 ----a-w- c:\programmi\dsetup32.dll
2009-03-16 12:36 . 2009-03-16 12:36 44444 ----a-w- c:\programmi\dxdllreg_x86.cab
2009-03-16 12:35 . 2009-03-16 12:35 525128 ----a-w- c:\programmi\DXSETUP.exe
2009-03-16 12:35 . 2009-03-16 12:35 94024 ----a-w- c:\programmi\DSETUP.dll
2008-07-18 18:42 . 2008-07-17 16:13 38860944 ----a-w- c:\programmi\GoogleSketchUpWIT.exe
2000-04-04 16:13 . 2009-01-07 21:12 13277 ----a-w- c:\programmi\FB63U.CAT
2000-04-04 16:12 . 2009-01-07 21:12 14605 ----a-w- c:\programmi\FB63UNT.CAT
2000-03-27 11:49 . 2009-01-07 21:12 5381 ----a-w- c:\programmi\FB63u.inf
2000-03-24 15:10 . 2009-01-07 21:12 2703 ----a-w- c:\programmi\Readme.txt
2009-06-05 10:31 . 2009-06-05 10:31 8 --sh--r- c:\windows\system32\6A317A8ED6.sys
2009-06-05 10:31 . 2009-06-05 10:30 3140 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
------- Sigcheck -------
[-] 2008-04-14 . 6DC43081C760EEC1130D2C8C145DF375 . 549888 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 . 6DC43081C760EEC1130D2C8C145DF375 . 549888 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[7] 2008-04-14 . 9259170D29B5A256735FCB8B80280857 . 510464 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe
[7] 2004-08-19 . 4166454E2BCFCC20D1B8A5AC9FEAB243 . 504832 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-04-14 . 97CBB1689BB951AD8DEE44C9F9C44318 . 724992 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-14 . 97CBB1689BB951AD8DEE44C9F9C44318 . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
[7] 2008-04-14 . 10AA0E13B4D20EE798E3382C9B89B3E3 . 617472 . . [5.82] . . c:\windows\VistaMizer\old\comctl32.dll
[-] 2006-08-25 . EFA21A3FE23BBCFDB6F61A3AF723E05A . 617472 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll
[7] 2004-08-19 . 0FE5F5912C30795C455A9645970E6C7C . 611328 . . [5.82] . . c:\windows\$NtUninstallKB923191$\comctl32.dll
[-] 2009-04-29 . 92769488990F34EDB22157AF360B2312 . 3821056 . . [7.00.6000.16850] . . c:\windows\ServicePackFiles\i386\mshtml.dll
[-] 2009-04-29 . 92769488990F34EDB22157AF360B2312 . 3821056 . . [7.00.6000.16850] . . c:\windows\system32\mshtml.dll
[-] 2009-04-29 . 92769488990F34EDB22157AF360B2312 . 3821056 . . [7.00.6000.16850] . . c:\windows\system32\dllcache\mshtml.dll
[7] 2009-04-29 . B49494080ED7D6D749D65786494ABD9A . 3596288 . . [7.00.6000.16850] . . c:\windows\VistaMizer\old\mshtml.dll
[7] 2009-04-29 . 2ECF7C62E692BBE1D7F9A72B42AECAA9 . 3598336 . . [7.00.6000.21045] . . c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\mshtml.dll
[7] 2009-02-21 . 2358FF7E9C728932FC3C075935978086 . 3596800 . . [7.00.6000.21015] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\mshtml.dll
[7] 2009-02-20 . DE364398A00B79DD448874155977EC0B . 3595264 . . [7.00.6000.16825] . . c:\windows\ie7updates\KB969897-IE7\mshtml.dll
[7] 2009-01-16 . 0FB585ED87F8D0B0F19934EE1D733B24 . 3594752 . . [7.00.6000.16809] . . c:\windows\ie7updates\KB963027-IE7\mshtml.dll
[7] 2009-01-16 . B868CBA86B7AA951131E511DC3436544 . 3596288 . . [7.00.6000.20996] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll
[7] 2008-12-13 . CA3BD4783DC7CA85E949EA6FF5906617 . 3593216 . . [7.00.6000.16788] . . c:\windows\ie7updates\KB961260-IE7\mshtml.dll
[7] 2008-12-13 . C352D6D2EFC11942BA84B996BAFFB182 . 3594752 . . [7.00.6000.20973] . . c:\windows\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
[7] 2008-10-17 . 6325783D4583E0EEBF26AA1286F26E70 . 3593216 . . [7.00.6000.16762] . . c:\windows\ie7updates\KB960714-IE7\mshtml.dll
[7] 2008-10-16 . 6EA04EE075C69345AB9B90C7A8740A04 . 3595264 . . [7.00.6000.20935] . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
[7] 2008-08-27 . BBB7E4E7A8A232AD5B995B8049B56711 . 3593216 . . [7.00.6000.16735] . . c:\windows\ie7updates\KB958215-IE7\mshtml.dll
[7] 2008-08-26 . FA61793E4E3F5C896C0728F350E30FAF . 3594752 . . [7.00.6000.20900] . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
[7] 2008-06-24 . 080DEB244585EB5772F6E6DEA75B4380 . 3592192 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB956390-IE7\mshtml.dll
[7] 2008-06-23 . 8E52FEC7D214C3B62871F8637F204114 . 3594240 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
[7] 2008-04-23 . 4BE72F3F57BF111BE500F6681006E3D4 . 3591680 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\mshtml.dll
[7] 2008-04-23 . 3B3A745E1C92A877C3F237ADFBA8348C . 3593728 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mshtml.dll
[-] 2008-02-16 . 8DFA721537D325795C6FA53911F3BCB7 . 3080704 . . [6.00.2900.3314] . . c:\windows\ie7\mshtml.dll
[-] 2008-02-16 . 7651992743B4FA4D3F361258CCE69076 . 3087872 . . [6.00.2900.3314] . . c:\windows\$hf_mig$\KB947864\SP2QFE\mshtml.dll
[7] 2007-08-13 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13] . . c:\windows\ie7updates\KB950759-IE7\mshtml.dll
[-] 2006-02-01 . F3701B305DBD8A6CD781AC4DA76FF23B . 3035648 . . [6.00.2900.2838] . . c:\windows\$hf_mig$\KB912945\SP2QFE\mshtml.dll
[-] 2006-01-31 . 0FA644C92A6E8601CBD9497AA747D5E3 . 3033088 . . [6.00.2900.2838] . . c:\windows\$NtUninstallKB947864$\mshtml.dll
[-] 2005-07-20 . 2F50312900A9DD0DFFB5E72D26819A0C . 3014144 . . [6.00.2900.2722] . . c:\windows\$hf_mig$\KB896727\SP2QFE\mshtml.dll
[7] 2004-08-19 . B0D7B00D4FDC5BB8203E0A38D15CBAA2 . 3003392 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB896727$\mshtml.dll
[-] 2009-08-04 . B591BF7D603926A0465B42E93F6AA44D . 2192896 . . [5.1.2600.5857] . . c:\windows\SoftwareDistribution\Download\dc391c8477770a35114bb8ac1f9d4164\SP3GDR\ntoskrnl.exe
[-] 2009-08-04 . 66C0988D9B1BB7F41437D91DBCFDF927 . 2193024 . . [5.1.2600.5857] . . c:\windows\SoftwareDistribution\Download\dc391c8477770a35114bb8ac1f9d4164\SP3QFE\ntoskrnl.exe
[-] 2009-08-04 . 1A170E77374594CA4C5D4CA2AB1DE2FF . 2189696 . . [5.1.2600.3610] . . c:\windows\SoftwareDistribution\Download\dc391c8477770a35114bb8ac1f9d4164\SP2QFE\ntoskrnl.exe
[-] 2009-08-04 . 76E56DCF3A82E429115900175F235FB2 . 2184064 . . [5.1.2600.3610] . . c:\windows\SoftwareDistribution\Download\dc391c8477770a35114bb8ac1f9d4164\SP2GDR\ntoskrnl.exe
[7] 2009-02-10 . 3B5928FCD0DD3E10DEB1C13CA35201F6 . 2192896 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[7] 2009-02-09 . AAC0F03E70F066D2E13FA2BA534BB2A8 . 2192768 . . [5.1.2600.5755] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2009-02-09 . AA2688C803A7528C825184412DF97716 . 2406400 . . [5.1.2600.5755] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[-] 2009-02-09 . AA2688C803A7528C825184412DF97716 . 2406400 . . [5.1.2600.5755] . . c:\windows\system32\ntoskrnl.exe
[-] 2009-02-09 . AA2688C803A7528C825184412DF97716 . 2406400 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\ntoskrnl.exe
[7] 2009-02-09 . 592F44BB500F995BEAD0EB8BA06BC104 . 2148864 . . [5.1.2600.5755] . . c:\windows\VistaMizer\old\ntoskrnl.exe
[7] 2008-08-14 . 0EE73494680235D59F4E57301D7AD580 . 2192896 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[7] 2008-08-14 . ED4846E64DE6152FBE327FF720EF27BE . 2146304 . . [5.1.2600.3427] . . c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
[7] 2008-08-14 . 0F93D9366B222D63F9402F7ED45CF2A4 . 2192896 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
[7] 2008-08-14 . 15315CDC4A67DCBBAE59967F08129499 . 2148864 . . [5.1.2600.5657] . . c:\windows\$NtUninstallKB956572$\ntoskrnl.exe
[7] 2008-04-14 . 85B6D05F83DFBAFEF5F58836CE39586C . 2148864 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
[-] 2007-02-28 . 342E4C3B30464ACBE454693FC8A099A0 . 2141184 . . [5.1.2600.3093] . . c:\windows\$NtUninstallKB956841_0$\ntoskrnl.exe
[-] 2005-10-12 . 86D9C7EC538AD1CC6F81A91C4C7370C8 . 2139648 . . [5.1.2600.2774] . . c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
[-] 2005-09-29 . 20006884C3930819DB5FA8766135ECA1 . 2139648 . . [5.1.2600.2765] . . c:\windows\$NtUninstallKB909095$\ntoskrnl.exe
[-] 2005-03-02 . C120A33C71E706545CF26D6276BC0344 . 2183296 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
[7] 2004-08-19 . 8AB08C18BED548F7A534E9650911F660 . 2151936 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896256$\ntoskrnl.exe
[-] 2008-04-14 . 3DBD6DC6D74C517D55A1B3AECA88EF48 . 588800 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-14 . 3DBD6DC6D74C517D55A1B3AECA88EF48 . 588800 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[7] 2008-04-14 . FA94696C0727BD59E517C674CD6E7C72 . 579584 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\user32.dll
[-] 2007-03-08 . BAB4F995E526484A235A276E269AAF7F . 579072 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 . 9DAA2190A18739B657B58F794ACF2E47 . 578560 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2005-03-02 . 488019BFE2B0F9F8CD8394276D5B664A . 578048 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2005-03-02 . 14B5D6B20467DBA209853D65D1F6A124 . 578048 . . [5.1.2600.2622] . . c:\windows\$NtUninstallKB925902$\user32.dll
[7] 2004-08-19 . 08447BDFCE5D1B1956F962602381F5C1 . 578048 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB890859$\user32.dll
[-] 2009-04-29 . 93F9E68FF045D1B569990C6AB6D9C9C2 . 928768 . . [7.00.6000.16850] . . c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2009-04-29 . 93F9E68FF045D1B569990C6AB6D9C9C2 . 928768 . . [7.00.6000.16850] . . c:\windows\system32\wininet.dll
[-] 2009-04-29 . 93F9E68FF045D1B569990C6AB6D9C9C2 . 928768 . . [7.00.6000.16850] . . c:\windows\system32\dllcache\wininet.dll
[7] 2009-04-29 . B7DFEFC4FC10B8AC464FCDCA309267B6 . 827392 . . [7.00.6000.16850] . . c:\windows\VistaMizer\old\wininet.dll
[7] 2009-04-29 . D327397F4448DCB912E9FE78C9A94C88 . 828928 . . [7.00.6000.21045] . . c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\wininet.dll
[7] 2009-03-03 . C04C42D707CDB4129B86C4E96FA5C24B . 828416 . . [7.00.6000.21020] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll
[7] 2009-03-03 . 0F74B461F95EC8373FFF5990DC619A75 . 826368 . . [7.00.6000.16827] . . c:\windows\ie7updates\KB969897-IE7\wininet.dll
[7] 2008-12-20 . 3F7320E0F75F2B5A7A9AD32AEA08BF21 . 827904 . . [7.00.6000.20978] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
[7] 2008-12-20 . EF1520F95DD25F48C18502005F5EE995 . 826368 . . [7.00.6000.16791] . . c:\windows\ie7updates\KB963027-IE7\wininet.dll
[7] 2008-10-16 . A4C79606C0D9835E8A5A8E5E5804AE60 . 826368 . . [7.00.6000.16762] . . c:\windows\ie7updates\KB961260-IE7\wininet.dll
[7] 2008-10-16 . F303CFED3D8B8348A54F7A53DDC7CCA0 . 827904 . . [7.00.6000.20935] . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
[7] 2008-08-26 . 8E694EC9DA095E518D9447B3293208EA . 827904 . . [7.00.6000.20900] . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
[7] 2008-08-26 . D590241CADEC69A1BC157DC0452C92D1 . 826368 . . [7.00.6000.16735] . . c:\windows\ie7updates\KB958215-IE7\wininet.dll
[7] 2008-06-23 . 4B54220877703198E55F61CB7B87979E . 826368 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB956390-IE7\wininet.dll
[7] 2008-06-23 . BF9D17259082632F03F3FF5759C6AE32 . 827904 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
[7] 2008-04-23 . FE184A2B736F216CCC22ABEEBB40787D . 827392 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
[7] 2008-04-23 . C1089010BCC3FD01056D26E9A36BBB79 . 826368 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\wininet.dll
[-] 2008-02-16 . 3CBCB268E9DCF7AC46B66559B3D7AF97 . 668672 . . [6.00.2900.3314] . . c:\windows\$hf_mig$\KB947864\SP2QFE\wininet.dll
[-] 2008-02-16 . 0B53B6830E676391968768A29ACDF91F . 662016 . . [6.00.2900.3314] . . c:\windows\ie7\wininet.dll
[7] 2007-08-13 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . c:\windows\ie7updates\KB950759-IE7\wininet.dll
[-] 2006-01-09 . B196C4C7C33B1233FA005490BE7D54F9 . 660992 . . [6.00.2900.2823] . . c:\windows\$NtUninstallKB947864$\wininet.dll
[-] 2006-01-09 . B404779B16EB2CD8C574FB343D277521 . 664576 . . [6.00.2900.2823] . . c:\windows\$hf_mig$\KB912945\SP2QFE\wininet.dll
[-] 2005-07-03 . 70133360C8BD14D3C8345F5EE54BAC5B . 662016 . . [6.00.2900.2713] . . c:\windows\$hf_mig$\KB896727\SP2QFE\wininet.dll
[7] 2004-08-19 . 27966534A0820CD3BD988BD1517C8FF2 . 658944 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB896727$\wininet.dll
[-] 2008-04-14 . 287B3020F1324E99F313C9E7FCFCCCCC . 1554944 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 287B3020F1324E99F313C9E7FCFCCCCC . 1554944 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2008-04-14 . 70D7F99D95615C3C278367756287DB71 . 1036288 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe
[-] 2007-06-13 . 7E2817A623E16F830B660F81C0FD63DA . 1035776 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2007-06-13 . B4E85805BE6D23DE697F7B3BA7492D0B . 1035776 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[7] 2004-08-19 . 178D42BD8FC34A9837417A6CE1D6BB7B . 1034752 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
[-] 2008-04-14 . 91B6AAC828F8BBE1796275424E44DFB0 . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . 91B6AAC828F8BBE1796275424E44DFB0 . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[7] 2008-04-14 . F53CDDEF33A4C41336A782BE3D170158 . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe
[7] 2004-08-19 . 5B33B4265966EE063C7FBEA28958D9C2 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
[7] 2004-08-19 . 5B33B4265966EE063C7FBEA28958D9C2 . 15360 . . [5.1.2600.2180] . . c:\windows\system32\bak\ctfmon.exe
[-] 2009-08-04 . 845344F22D2BA7CDD2847B0B0A5D0EDD . 2069888 . . [5.1.2600.5857] . . c:\windows\SoftwareDistribution\Download\dc391c8477770a35114bb8ac1f9d4164\SP3QFE\ntkrnlpa.exe
[-] 2009-08-04 . 7DF79C43603FBDB4399841FD7FC4C50A . 2069760 . . [5.1.2600.5857] . . c:\windows\SoftwareDistribution\Download\dc391c8477770a35114bb8ac1f9d4164\SP3GDR\ntkrnlpa.exe
[-] 2009-08-04 . 050E3F721A57B5B33313F3EB202EDC30 . 2066688 . . [5.1.2600.3610] . . c:\windows\SoftwareDistribution\Download\dc391c8477770a35114bb8ac1f9d4164\SP2QFE\ntkrnlpa.exe
[-] 2009-08-04 . 5756F58B3B4C1285969EDB847D559F18 . 2061440 . . [5.1.2600.3610] . . c:\windows\SoftwareDistribution\Download\dc391c8477770a35114bb8ac1f9d4164\SP2GDR\ntkrnlpa.exe
[7] 2009-02-10 . 310B4DD8E34D9281D609B5EBDFDE34A7 . 2069760 . . [5.1.2600.5755] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2009-02-09 . 883A042A1658B37C9AB4ECB2B2624CE4 . 2285056 . . [5.1.2600.5755] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2009-02-09 . 883A042A1658B37C9AB4ECB2B2624CE4 . 2285056 . . [5.1.2600.5755] . . c:\windows\system32\ntkrnlpa.exe
[-] 2009-02-09 . 883A042A1658B37C9AB4ECB2B2624CE4 . 2285056 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[7] 2009-02-09 . 844C5BC1F022E7790BA6DD2610823BE6 . 2027520 . . [5.1.2600.5755] . . c:\windows\VistaMizer\old\ntkrnlpa.exe
[7] 2009-02-09 . FF69166080436A31A3EAC9CC7C3F1847 . 2069888 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[7] 2008-08-14 . C812D8551FD3B6ACDBF7EB6B18B1B992 . 2069760 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[7] 2008-08-14 . 158FC15417E99D04ECB58A7BB34201A8 . 2024448 . . [5.1.2600.3427] . . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
[7] 2008-08-14 . 93FB9D817B37DF1191B73DB7BC2F4006 . 2069760 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
[7] 2008-08-14 . BC8D2FF46D42B76655F443EF1386930F . 2027520 . . [5.1.2600.5657] . . c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe
[7] 2008-04-14 . FE93732DE7D6EA191E2FF816341D6FFF . 2027520 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
[-] 2007-02-28 . 7EDDC44BFACB2CDC0AE4D555D7FFDF8E . 2020864 . . [5.1.2600.3093] . . c:\windows\$NtUninstallKB956841_0$\ntkrnlpa.exe
[-] 2005-10-12 . 471DFE4FB561DE9CBAAD45FF3A13DFB8 . 2018816 . . [5.1.2600.2774] . . c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
[-] 2005-09-29 . ADFCEEF3FEE09B2C0FFC8C8BFEFE6D13 . 2019328 . . [5.1.2600.2765] . . c:\windows\$NtUninstallKB909095$\ntkrnlpa.exe
[-] 2005-03-02 . DE16030E8209FD96EEB06D9E3D8C84A8 . 2060672 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
[7] 2004-08-19 . 4B42A1C0085CE18E4BE81A25A3D1C9CF . 2018816 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896256$\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2005-05-20 08:11 . 2005-05-20 08:11 925696 c:\programmi\Analog Devices\Core\bak\smax4pnp.exe
2006-08-21 18:08 . 2005-05-06 12:06 716800 c:\programmi\Analog Devices\SoundMAX\bak\Smax4.exe
2007-02-25 16:52 . 2004-01-14 01:10 409600 c:\programmi\Canon\Easy-PrintToolBox\bak\BJPSMAIN.EXE
2003-11-28 01:19 . 2003-11-28 01:19 733184 c:\programmi\Corel\Corel Graphics 12\Languages\IT\Programs\bak\Registration.exe
2007-02-09 16:00 . 2007-02-09 16:00 406016 c:\programmi\Grisoft\AVG Free\bak\avgcc.exe
2005-02-16 21:11 . 2005-02-16 21:11 49152 c:\programmi\Hp\HP Software Update\bak\HPWuSchd2.exe
2006-08-21 18:33 . 2006-02-22 06:03 40960 c:\programmi\HPQ\Default Settings\bak\cpqset.exe
2006-08-21 18:20 . 2006-02-14 09:56 122880 c:\programmi\HPQ\HP ProtectTools Security Manager\bak\PTHOSTTR.EXE
2007-02-09 13:01 . 2005-11-08 10:59 184320 c:\programmi\InterVideo\DVD Check\bak\DVDCheck.exe
2006-08-21 18:13 . 2005-11-10 11:03 36975 c:\programmi\Java\jre1.5.0_06\bin\bak\jusched.exe
2006-06-15 11:36 . 2006-06-15 11:36 229376 c:\programmi\Nokia\Nokia PC Suite 6\bak\LAUNCH~1.EXE
2006-06-27 15:21 . 2006-06-27 15:21 1449984 c:\programmi\Nokia\Nokia PC Suite 6\bak\PcSync2.exe
2007-02-16 08:54 . 2007-02-16 08:54 282624 c:\programmi\QuickTime\bak\qttask.exe
2009-01-05 14:18 . 2009-01-05 14:18 413696 c:\programmi\QuickTime\QTTask.exe
2006-08-21 18:24 . 2005-11-10 18:04 761945 c:\programmi\Synaptics\SynTP\bak\SynTPEnh.exe
2006-08-21 18:24 . 2005-11-10 18:04 761945 c:\programmi\Synaptics\SynTP\SynTPEnh.exe
2007-02-13 21:30 . 2007-02-13 21:30 40960 c:\windows\bak\NCLAUNCH.EXe
2007-02-13 21:30 . 2008-05-23 12:06 40960 c:\windows\NCLAUNCH.EXe
2006-08-21 18:41 . 2006-01-23 14:11 802816 c:\windows\CREATOR\bak\Remind_XP.exe
2006-08-21 18:40 . 2005-12-20 13:51 1187840 c:\windows\SMINST\bak\Recguard.exe
2006-08-21 18:41 . 2006-02-15 13:43 892928 c:\windows\SMINST\bak\Scheduler.exe
2004-08-19 08:00 . 2004-08-19 08:00 15360 c:\windows\system32\bak\ctfmon.exe
2004-08-19 08:00 . 2008-04-14 02:14 25088 c:\windows\system32\ctfmon.exe
2006-03-23 12:13 . 2006-03-23 12:13 77824 c:\windows\system32\bak\hkcmd.exe
2006-03-23 12:17 . 2006-03-23 12:17 118784 c:\windows\system32\bak\igfxpers.exe
2006-03-23 12:17 . 2006-03-23 12:17 94208 c:\windows\system32\bak\igfxtray.exe
2007-02-09 13:11 . 2001-07-09 10:50 155648 c:\windows\system32\bak\NeroCheck.exe
2006-08-21 18:22 . 2005-08-31 03:20 122940 c:\windows\system32\DLA\bak\DLACTRLW.EXE
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{daea5450-a4f3-4d85-a790-f8cda835546a}"= "c:\programmi\Download-ES\tbDown.dll" [2009-01-07 1880600]
[HKEY_CLASSES_ROOT\clsid\{daea5450-a4f3-4d85-a790-f8cda835546a}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-05-19 11:37 1144712 ----a-w- c:\programmi\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{daea5450-a4f3-4d85-a790-f8cda835546a}]
2009-01-07 12:51 1880600 ----a-w- c:\programmi\Download-ES\tbDown.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{daea5450-a4f3-4d85-a790-f8cda835546a}"= "c:\programmi\Download-ES\tbDown.dll" [2009-01-07 1880600]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\programmi\Ask.com\GenericAskToolbar.dll" [2009-05-19 1144712]
[HKEY_CLASSES_ROOT\clsid\{daea5450-a4f3-4d85-a790-f8cda835546a}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{DAEA5450-A4F3-4D85-A790-F8CDA835546A}"= "c:\programmi\Download-ES\tbDown.dll" [2009-01-07 1880600]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\programmi\Ask.com\GenericAskToolbar.dll" [2009-05-19 1144712]
[HKEY_CLASSES_ROOT\clsid\{daea5450-a4f3-4d85-a790-f8cda835546a}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2008-05-23 40960]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [N/A]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-20 39408]
"WMPNSCFG"="c:\programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 204288]
"GetChristmas"="c:\documents and settings\Administrator\Desktop\GetChristmas.exe" [N/A]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 25088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"hpWirelessAssistant"="c:\programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 454656]
"CognizanceTS"="c:\progra~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 17920]
"QlbCtrl"="c:\programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 131072]
"WatchDog"="c:\programmi\InterVideo\DVD Check\bak\DVDCheck.exe" [2005-11-08 184320]
"fssui"="c:\programmi\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"OpwareSE4"="c:\programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Mouse Suite 98 Daemon"="ICO.EXE" [2004-07-14 57344]
"LogitechQuickCamRibbon"="c:\programmi\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2005-11-10 761945]
"CloneCDTray"="c:\programmi\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"egui"="c:\programmi\ESET\ESET NOD32 Antivirus\egui.exe" [2008-10-24 1451264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 25088]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Software Bluetooth\BTTray.exe [2006-2-15 581693]
Logitech Desktop Messenger.lnk - c:\programmi\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-1-9 66864]
Nikon Monitor.lnk - c:\programmi\File comuni\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2007-2-9 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2005-07-25 18:41 40960 ----a-w- c:\programmi\HPQ\IAM\Bin\AsWlnPkg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2fe0bbd7]
c:\windows\system32\jafotemu.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM2cd3884b]
c:\windows\system32\geyufede.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crtfmon]
c:\docume~1\ADMINI~1\IMPOST~1\Temp\1189326549.dat.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ksiysyk]
c:\documents and settings\administrator\impostazioni locali\dati applicazioni\ksiysyk.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\latotuwisu]
c:\windows\system32\repeseza.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-09-28 12:16 185896 ----a-w- c:\programmi\File comuni\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVCHOST.EXE]
c:\windows\system32\drivers\svchost.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-11-02 20:56 204288 ----a-w- c:\programmi\Windows Media Player\wmpnscfg.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\Ares\\Ares.exe"=
"c:\\Programmi\\File comuni\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Programmi\\iPod\\bin\\iPodService.exe"=
"c:\\Programmi\\ESET\\ESET NOD32 Antivirus\\ekrn.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\WIDCOMM\\Software Bluetooth\\bin\\btwdins.exe"=
"c:\\Programmi\\File comuni\\Microsoft Shared\\VS7DEBUG\\MDM.EXE"=
"c:\\Programmi\\BitLord2\\BitLord.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\stefano\\utorrent.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4760:TCP"= 4760:TCP:htivodh
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [24/10/2008 20.53.28 34824]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\programmi\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [16/09/2008 11.03.18 169312]
R2 ASChannel;Canale di comunicazione locale;c:\windows\System32\svchost.exe -k Cognizance [19/08/2004 9.00.00 14336]
R2 ekrn;Eset Service;c:\programmi\ESET\ESET NOD32 Antivirus\ekrn.exe [24/10/2008 20.51.16 468224]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [06/01/2009 21.50.43 55152]
R2 fsssvc;Windows Live Family Safety;c:\programmi\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18.08.58 533360]
S2 gupdate1ca2240a5d49d0a;Servizio di Google Update (gupdate1ca2240a5d49d0a);c:\programmi\Google\Update\GoogleUpdate.exe [21/08/2009 10.20.30 133104]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [19/08/2004 9.00.00 25600]
S2 reitohvq;Network Windows;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 9.00.00 14336]
S2 zbxuvxlfw;Task Shell;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 9.00.00 14336]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - dqmnru
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
lhptkinq
zbxuvxlfw
reitohvq
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-08-21 09:20]
2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-08-21 09:20]
2010-01-05 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2010-01-06 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2010-01-05 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\programmi\Ask.com\UpdateTask.exe [2009-05-19 11:37]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.com/uSearchMigratedDefaultURL =
hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Settings,ProxyOverride = local
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: Aggiungi all'elenco di stampa Easy-WebPrint - c:\programmi\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Anteprima Easy-WebPrint - c:\programmi\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Invia a &Bluetooth - c:\programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
IE: Stampa ad alta velocità Easy-WebPrint - c:\programmi\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Stampa Easy-WebPrint - c:\programmi\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
Trusted Zone: whataboutadog.com
Trusted Zone: whataboutarabit.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\programmi\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\wy1yafqv.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - prefs.js: keyword.URL -
hxxp://www.google.com/search?ie=UTF-8&o ... &gfns=1&q=FF - plugin: c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\wy1yafqv.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
AddRemove-nmtcab - c:\documents and settings\administrator\impostazioni locali\dati applicazioni\nmtcab.exe
AddRemove-{26fb76a7-4b1e-442d-8b9d-7704cbb56b2a} - c:\programmi\File comuni\Nero\Nero ProductInstaller 4\SetupX.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-06 17:56
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dqmnru]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\reitohvq]
"ServiceDll"="c:\windows\system32\xrzikwje.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zbxuvxlfw]
"ServiceDll"="c:\windows\system32\xrzikwje.dll"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1987944545-1339218757-4151644466-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,94,a6,58,1b,cb,6a,77,4b,b1,8f,f7,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,94,a6,58,1b,cb,6a,77,4b,b1,8f,f7,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(864)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\programmi\HPQ\IAM\Bin\AsWlnPkg.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
c:\windows\system32\msi.dll
- - - - - - - > 'lsass.exe'(920)
c:\windows\system32\setupapi.dll
c:\windows\system32\scecli.dll
c:\windows\system32\psbase.dll
- - - - - - - > 'explorer.exe'(8968)
c:\windows\system32\SHDOCVW.dll
c:\programmi\File comuni\Logishrd\LVMVFM\LVPrcInj.dll
c:\programmi\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\COMRes.dll
c:\programmi\HPQ\IAM\Bin\SFSShell.dll
c:\programmi\HPQ\IAM\bin\ItMsg.dll
c:\programmi\HPQ\IAM\bin\1040\SFSShell.dll
c:\windows\System32\cscui.dll
c:\windows\system32\LINKINFO.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\msi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\DllHost.exe
c:\programmi\HPQ\IAM\bin\asghost.exe
c:\windows\system32\msdtc.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\windows\system32\ICO.EXE
c:\programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\mqsvc.exe
c:\programmi\Windows Media Player\WMPNetwk.exe
c:\programmi\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\mqtgsvc.exe
c:\programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
c:\programmi\File comuni\Logishrd\LQCVFX\COCIManager.exe
c:\programmi\iPod\bin\iPodService.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-06 18:06:40 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-06 17:06
Pre-Run: 5.737.410.560 byte disponibili
Post-Run: 7.241.953.280 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 1C5E4D4E17485D10277D2C9CE97AAF1F