ciao ti invio il log aggiornato:
ComboFix 11-09-30.05 - Giuseppe 02/10/2011 12.22.26.2.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2815.2365 [GMT 2:00]
Eseguito da: c:\documents and settings\Giuseppe\Desktop\abc.exe
Opzioni usate :: c:\documents and settings\Giuseppe\Desktop\CFScript.txt.txt
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: ActiveArmor Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
FILE ::
"c:\documents and settings\Giuseppe\Dati applicazioni\Dourk\oqkoz.exe"
"c:\programmi\Babylon\Babylon-Pro\Babylon.exe"
"c:\programmi\ConduitEngine\ConduitEngine.dll"
"c:\programmi\eBay\eBay Toolbar2\eBayTBDaemon.exe"
"c:\programmi\Enigma Software Group\SpyHunter\esgiguard.sys"
"c:\programmi\SSSP_Cccam1.3.1.exe"
"c:\programmi\uusee\UUSeePlayer.exe"
"c:\windows\D3F93A5A7A5D4867B2A16F46500D006C.TMP"
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\oP21703LiBmF21703
c:\documents and settings\All Users\Dati applicazioni\oP21703LiBmF21703\oP21703LiBmF21703
c:\documents and settings\Giuseppe\Dati applicazioni\BabylonToolbar
c:\documents and settings\Giuseppe\Impostazioni locali\Dati applicazioni\PUpdBHO
c:\documents and settings\Giuseppe\Impostazioni locali\Dati applicazioni\PUpdBHO\settings\settings.ini
c:\programmi\ConduitEngine
c:\programmi\ConduitEngine\appContextMenu.xml
c:\programmi\ConduitEngine\ConduitEngine.dll
c:\programmi\ConduitEngine\ConduitEngineHelper.exe
c:\programmi\ConduitEngine\engineContextMenu.xml
c:\programmi\ConduitEngine\EngineSettings.json
c:\programmi\ConduitEngine\toolbar.cfg
c:\programmi\Enigma Software Group
c:\programmi\Enigma Software Group\SpyHunter\Data\dns.dat
c:\programmi\Enigma Software Group\SpyHunter\Defs\cmp_2011092901.def
c:\programmi\Enigma Software Group\SpyHunter\gil.dat
c:\programmi\Enigma Software Group\SpyHunter\INSTALL.LOG
c:\programmi\Enigma Software Group\SpyHunter\Log\SpyHunter4_20110930_164419.log
c:\programmi\Enigma Software Group\SpyHunter\mon\autoexec.bat.bk
c:\programmi\Enigma Software Group\SpyHunter\mon\hosts.bk
c:\programmi\Enigma Software Group\SpyHunter\mon\system.ini.bk
c:\programmi\Enigma Software Group\SpyHunter\mon\win.ini.bk
c:\programmi\Enigma Software Group\SpyHunter\safeol.dat
c:\programmi\Enigma Software Group\SpyHunter\scanlog.log
c:\programmi\Enigma Software Group\SpyHunter\SH4.com
c:\programmi\Enigma Software Group\SpyHunter\supportlog.txt
c:\programmi\Enigma Software Group\SpyHunter\unkcache.dat
c:\programmi\SSSP_Cccam1.3.1.exe
c:\programmi\uusee
c:\programmi\uusee\AD\1\000\index_new.html
c:\programmi\uusee\AD\1\000\uue_new.jpg
c:\programmi\uusee\AD\1\001\index_new.html
c:\programmi\uusee\AD\1\001\uue_new.jpg
c:\programmi\uusee\AD\1\cy\cy.html
c:\programmi\uusee\AD\1\dm\dm.html
c:\programmi\uusee\AD\1\dsj\dsj.html
c:\programmi\uusee\AD\1\dst\dst.html
c:\programmi\uusee\AD\1\dy\dy.html
c:\programmi\uusee\AD\1\jk\jk.html
c:\programmi\uusee\AD\1\ty\ty.html
c:\programmi\uusee\AD\1\uu\uu.html
c:\programmi\uusee\AD\1\yl\yl.html
c:\programmi\uusee\AD\1\yx\yx.html
c:\programmi\uusee\AD\1\zx\zx.html
c:\programmi\uusee\AD\2\100\index.html
c:\programmi\uusee\AD\2\200\index.html
c:\programmi\uusee\AD\2\300\index.html
c:\programmi\uusee\AD\2\400\index.html
c:\programmi\uusee\AD\UUAD_Banner_1.html
c:\programmi\uusee\AD\UUAD_Banner_3.html
c:\programmi\uusee\AD\UUAD_Buffering.html
c:\programmi\uusee\AD\UUAD_Buffering.jpg
c:\programmi\uusee\AD\UUAD_TextLink_0.xml
c:\programmi\uusee\channelid_chatid.txt
c:\programmi\uusee\skins\UUPlayer\About.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_Compact_1.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_Compact_2.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_Compact_3.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_FullScreen_1.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_FullScreen_2.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_FullScreen_3.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_pause_1.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_pause_2.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_pause_3.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_pause_4.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_Recording_1.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_Recording_2.bmp
c:\programmi\uusee\skins\UUPlayer\Control_Button_Recording_3.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_CheckBox_1.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_CheckBox_2.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_CheckBox_3.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_CheckBox_4.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_CheckBox_C1.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_CheckBox_C2.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_CheckBox_C3.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_CheckBox_C4.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_ComboBox_1.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_ComboBox_2.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_ComboBox_3.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_ComboBox_4.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_Edit_1.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_Edit_4.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_PushButton_1.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_PushButton_2.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_PushButton_3.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_PushButton_4.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_RadioButton_1.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_RadioButton_2.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_RadioButton_3.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_RadioButton_4.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_RadioButton_C1.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_RadioButton_C2.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_RadioButton_C3.bmp
c:\programmi\uusee\skins\UUPlayer\Ctrl_RadioButton_C4.bmp
c:\programmi\uusee\skins\UUPlayer\Dlg_Back.bmp
c:\programmi\uusee\skins\UUPlayer\Dlg_Detect.bmp
c:\programmi\uusee\skins\UUPlayer\Dlg_Frame_1.bmp
c:\programmi\uusee\skins\UUPlayer\Dlg_Frame_2.bmp
c:\programmi\uusee\skins\UUPlayer\Dlg_Frame_3.bmp
c:\programmi\uusee\skins\UUPlayer\Dlg_Record_Task_1.bmp
c:\programmi\uusee\skins\UUPlayer\Icon_Information.bmp
c:\programmi\uusee\skins\UUPlayer\Icon_Question.bmp
c:\programmi\uusee\skins\UUPlayer\Icon_Stop.bmp
c:\programmi\uusee\skins\UUPlayer\ListHeader_1.bmp
c:\programmi\uusee\skins\UUPlayer\ListHeader_2.bmp
c:\programmi\uusee\skins\UUPlayer\ListHeader_3.bmp
c:\programmi\uusee\skins\UUPlayer\ListHeader_ArrowD.bmp
c:\programmi\uusee\skins\UUPlayer\ListHeader_ArrowU.bmp
c:\programmi\uusee\skins\UUPlayer\ListHeader_SP.bmp
c:\programmi\uusee\skins\UUPlayer\Play_Window_Rec_icon.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_Block_1.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_Block_2.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_Block_3.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_Block_4.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_BM_0.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_BM_1.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_BM_2.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_BM_3.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_BM_4.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_BM_5.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_BM_6.bmp
c:\programmi\uusee\skins\UUPlayer\Progressbar_BM_7.bmp
c:\programmi\uusee\skins\UUPlayer\Resource.h
c:\programmi\uusee\skins\UUPlayer\Setting_Group_1_1.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_1_2.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_1_3.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_2_1.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_2_2.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_2_3.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_3_1.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_3_2.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_3_3.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_4_1.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_4_2.bmp
c:\programmi\uusee\skins\UUPlayer\Setting_Group_4_3.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Button_1_1.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Button_1_2.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Button_1_3.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Group_1.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Group_2.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Group_3.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Group_x1.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Group_x2.bmp
c:\programmi\uusee\skins\UUPlayer\Sidebar_Group_x3.bmp
c:\programmi\uusee\skins\UUPlayer\Thumbs.db
c:\programmi\uusee\skins\UUPlayer\Titlebar_button_Res_1.bmp
c:\programmi\uusee\skins\UUPlayer\Titlebar_button_Res_2.bmp
c:\programmi\uusee\skins\UUPlayer\Titlebar_button_Res_3.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_Compact_1.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_Compact_2.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_Compact_3.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_FullScreen_1.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_FullScreen_2.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_FullScreen_3.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_TopMost_1.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_TopMost_2.bmp
c:\programmi\uusee\skins\UUPlayer\Toolbar_Button_TopMost_3.bmp
c:\programmi\uusee\skins\UUPlayer\TopTab_Browse.bmp
c:\programmi\uusee\skins\UUPlayer\TopTab_Browse1.bmp
c:\programmi\uusee\skins\UUPlayer\TopTab_Play.bmp
c:\programmi\uusee\skins\UUPlayer\TopTab_Play1.bmp
c:\programmi\uusee\skins\UUPlayer\TopTab_Record.bmp
c:\programmi\uusee\skins\UUPlayer\TopTab_Record1.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_Arrow.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_Collapse.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_Expand.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_Header.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_ScrollBar_D.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_ScrollBar_H.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_ScrollBar_N.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_ScrollBar_S.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_ScrollBarThumb_D.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_ScrollBarThumb_H.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_ScrollBarThumb_N.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_ScrollBarThumb_S.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_SortIconDown.bmp
c:\programmi\uusee\skins\UUPlayer\Tree_SortIconUp.bmp
c:\programmi\uusee\skins\UUPlayer\UUSEE.ui
c:\programmi\uusee\skins\UUPlayer\Volume_Bar_Block_1.bmp
c:\programmi\uusee\skins\UUPlayer\Volume_Bar_Block_2.bmp
c:\programmi\uusee\skins\UUPlayer\Volume_Bar_Block_3.bmp
c:\programmi\uusee\skins\UUPlayer\Volume_Button_2_1.bmp
c:\programmi\uusee\skins\UUPlayer\Volume_Button_2_2.bmp
c:\programmi\uusee\skins\UUPlayer\Volume_Button_2_3.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Browser_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Browser_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Browser_3.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_ChannelInfo.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_ChannelInfo_5.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Control_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Control_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Control_3.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Control_4.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Info.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Main_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Main_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Main_3.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Main_5.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Play_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Play_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Play_5.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Record_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Record_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Record_3.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Record_4.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Setting_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Setting_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Setting_3.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Side_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Side_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Side_3.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Toolbar_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Toolbar_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Toolbar_3.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Toolbar_4.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Top_1.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Top_2.bmp
c:\programmi\uusee\skins\UUPlayer\Wnd_Top_3.bmp
c:\programmi\uusee\UUPlayer.dll
c:\programmi\uusee\UUPlayer_update.ini
c:\programmi\uusee\UUSee.url
c:\programmi\uusee\UUSeePlayer.exe
c:\programmi\uusee\UUTV_Chat.xml
c:\programmi\uusee\UUTV_MY.xml
c:\programmi\uusee\UUTV_UUPlayer.xml
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ESGIGUARD
-------\Service_esgiguard
.
.
((((((((((((((((((((((((( Files Creati Da 2011-09-02 al 2011-10-02 )))))))))))))))))))))))))))))))))))
.
.
2011-10-01 16:37 . 2011-10-01 16:37 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\Malwarebytes
2011-10-01 16:37 . 2011-10-01 16:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-10-01 16:36 . 2011-10-01 16:37 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-10-01 16:36 . 2011-08-31 15:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-30 14:44 . 2011-09-30 15:32 -------- d-----w- C:\sh4ldr
2011-09-30 14:43 . 2011-09-30 15:32 -------- d-----w- c:\windows\D3F93A5A7A5D4867B2A16F46500D006C.TMP
2011-09-30 14:43 . 2011-09-30 14:43 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2011-09-30 14:13 . 2011-09-30 14:13 -------- d-----r- c:\documents and settings\NetworkService\Preferiti
2011-09-20 17:00 . 2011-09-20 17:00 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\Uniblue
2011-09-12 16:07 . 2011-09-18 18:45 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\Toolbar4
2011-09-12 14:09 . 2011-09-12 14:09 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\Burraconline
2011-09-12 14:04 . 2011-09-12 14:04 -------- d-----w- c:\programmi\Burraconline
2011-09-12 13:56 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-09-12 13:56 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-09-12 13:56 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2011-09-12 13:56 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-09-09 19:52 . 2011-09-18 18:47 -------- d-----w- c:\documents and settings\Giuseppe\Impostazioni locali\Dati applicazioni\PService
2011-09-09 19:52 . 2011-09-10 10:27 -------- d-----w- c:\documents and settings\Giuseppe\Impostazioni locali\Dati applicazioni\ServiceUpd
2011-09-09 08:44 . 2011-09-09 08:44 -------- d-----w- c:\documents and settings\Giuseppe\Dati applicazioni\DVDVideoSoftIEHelpers
2011-09-09 08:43 . 2011-09-18 18:42 -------- d-----w- c:\programmi\File comuni\DVDVideoSoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-18 18:39 . 2010-01-09 17:49 47360 -c--a-w- c:\documents and settings\Giuseppe\Dati applicazioni\pcouffin.sys
2011-09-12 16:00 . 2011-02-25 21:52 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-09-12 15:59 . 2011-03-01 13:09 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-09-12 15:59 . 2011-02-25 21:52 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-09-10 18:25 . 2011-02-25 21:52 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\sh4ldr ----
.
2011-09-30 14:44 . 2011-09-30 14:44 8192 ----a-w- c:\sh4ldr\shldr.mbr
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-01_17.42.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-02 10:36 . 2011-10-02 10:36 16384 c:\windows\temp\Perflib_Perfdata_70c.dat
+ 2009-04-09 06:42 . 2011-10-02 10:35 827424 c:\windows\system32\drivers\fidbox2.dat
- 2009-04-09 06:42 . 2011-10-01 17:40 827424 c:\windows\system32\drivers\fidbox2.dat
+ 2009-04-09 06:42 . 2011-10-02 10:35 3992608 c:\windows\system32\drivers\fidbox.dat
- 2009-04-09 06:42 . 2011-10-01 17:40 3992608 c:\windows\system32\drivers\fidbox.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CheckRubAnniversari"="c:\documents and settings\Giuseppe\Documenti\SeatCDItalia\127_0_0_1\chkrub_cdi.exe" [2009-08-03 630272]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-17 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-21 208616]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^EPSON Status Monitor 3 Environment Check.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\EPSON Status Monitor 3 Environment Check.lnk
backup=c:\windows\pss\EPSON Status Monitor 3 Environment Check.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^hp psc 1000 series.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\hp psc 1000 series.lnk
backup=c:\windows\pss\hp psc 1000 series.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^hpoddt01.exe.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Giuseppe^Menu Avvio^Programmi^Esecuzione automatica^Xfire.lnk]
path=c:\documents and settings\Giuseppe\Menu Avvio\Programmi\Esecuzione automatica\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 -c--a-w- c:\programmi\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 -c--a-w- c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 17:14 1695232 ------w- c:\programmi\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-31 06:35 86016 -c--a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-31 06:35 1622016 -c--a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-10 14:26 406016 -c--a-w- c:\windows\system32\PSDrvCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-06-18 16:17 148888 -c--a-w- c:\programmi\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-06-24 14:41 247144 -c--a-w- c:\programmi\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-01-21 10:40 395640 ----a-w- c:\programmi\uTorrent\uTorrent.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\italian\\setup.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
.
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 18.29.38 33808]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmi\TomTom HOME 2\TomTomHOMEService.exe [24/06/2010 16.41.38 92008]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 19.02.46 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 17.06.48 24592]
S2 gupdate;Servizio di Google Update (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [15/02/2011 23.08.10 136176]
S2 PowerOffer Upd Service;ServiceUpd;c:\documents and settings\Giuseppe\Impostazioni locali\Dati applicazioni\ServiceUpd\ServiceUpd.exe [09/09/2011 21.52.19 26112]
S3 gupdatem;Servizio Google Update (gupdatem);c:\programmi\Google\Update\GoogleUpdate.exe [15/02/2011 23.08.10 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [09/01/2010 19.49.02 47360]
S3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [19/09/2010 17.37.11 627288]
S3 ZD1211BU(SBS);SBS BW254 Wireless Wireless LAN Driver(SBS);c:\windows\system32\drivers\ZD1211BU.sys [21/12/2009 22.25.35 500736]
.
Contenuto della cartella 'Scheduled Tasks'
.
2010-06-29 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1100 series5E771253C1676EBED677BF361FDFC537825E15B8269502706.job
- c:\programmi\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
.
2011-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-02-15 21:08]
.
2011-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2011-02-15 21:08]
.
2011-08-21 c:\windows\Tasks\NeroLiveEpgUpdate-FAG-65354EA14BE_Giuseppe.job
- c:\programmi\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 11:51]
.
2011-10-02 c:\windows\Tasks\User_Feed_Synchronization-{EC8C2FBE-F613-47B9-A351-2385EE3DA6A4}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: videocoolstreaming.us
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-10-02 12:37
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(2128)
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\savedump.exe
c:\programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Nero\Nero BackItUp 4\NBService.exe
c:\programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\windows\system32\PnkBstrA.exe
c:\programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Ora fine scansione: 2011-10-02 12:40:59 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-10-02 10:40
ComboFix2.txt 2011-10-01 17:46
.
Pre-Run: 26.926.010.368 byte disponibili
Post-Run: 26.897.244.160 byte disponibili
.
- - End Of File - - 0B3687F6E96B08721EB300AB251B0296