Ciao a tutti,
nel mio computer si annida trj killAV.NH. Ho provato ad eliminarlo con diversi programmi suggeriti su questo forum e sono arrivata ad utilizzare Combo.Fix. Anche dopo l'utilizzo di ComboFix continuano a generarsi spyware durante la navigazione con Internet explorer. Potreste leggere il log di Combofix e suggerirmi che cos'altro devo eliminare? Grazie.
ComboFix 12-08-14.02 - user 21/08/2012 17:06:30.2.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.39.1040.18.3294.2348 [GMT 2:00]
Eseguito da: c:\users\user\Desktop\ComboFix.exe
AV: Panda Antivirus Pro 2012 *Disabled/Updated* {86971480-9989-6750-B122-681A86518D59}
SP: Panda Antivirus Pro 2012 *Disabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
- MODALITÀ CON FUNZIONALITÀ RIDOTTE -
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\user\AppData\Local\Temp\{527D14FB-2365-437E-9B76-68E92BAD70CA}\fpb.tmp
.
.
((((((((((((((((((((((((( Files Creati Da 2012-07-21 al 2012-08-21 )))))))))))))))))))))))))))))))))))
.
.
2012-08-21 15:08 . 2012-08-21 15:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-21 13:16 . 2012-08-21 13:16 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1AB31298-7E9B-4EEC-9D44-E6A40DC41FF3}\offreg.dll
2012-08-21 13:10 . 2012-08-01 22:51 7023536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1AB31298-7E9B-4EEC-9D44-E6A40DC41FF3}\mpengine.dll
2012-08-19 18:36 . 2012-06-29 00:00 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-08-19 18:36 . 2012-06-29 01:00 140920 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2012-08-19 18:36 . 2012-06-29 00:06 194560 ----a-w- c:\program files\Internet Explorer\ieproxy.dll
2012-08-19 18:36 . 2012-06-29 00:06 194048 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2012-08-19 18:36 . 2012-06-29 00:04 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-08-19 18:35 . 2012-06-29 00:16 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-08-19 18:35 . 2012-06-29 01:00 748664 ----a-w- c:\program files\Internet Explorer\iexplore.exe
2012-08-19 18:35 . 2012-06-29 00:10 387584 ----a-w- c:\program files\Internet Explorer\jsdbgui.dll
2012-08-19 18:35 . 2012-06-29 00:10 678912 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
2012-08-19 18:35 . 2012-06-29 00:08 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-19 16:35 . 2012-08-19 16:35 -------- d-----w- c:\programdata\Malwarebytes
2012-08-19 15:47 . 2012-07-04 21:14 41984 ----a-w- c:\windows\system32\browcli.dll
2012-08-19 15:47 . 2012-07-04 21:14 102912 ----a-w- c:\windows\system32\browser.dll
2012-08-19 15:47 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll
2012-08-14 19:07 . 2012-08-14 19:07 -------- d-----w- c:\programdata\Panda Software
2012-08-14 14:50 . 2012-08-14 15:01 -------- d-----w- c:\programdata\Tarma Installer
2012-08-14 14:50 . 2012-08-14 14:50 -------- d-----w- c:\programdata\Iminent
2012-08-14 14:49 . 2012-08-14 14:50 -------- d-----w- c:\program files\Iminent
2012-08-14 14:47 . 2012-08-14 14:47 -------- d-----w- c:\program files\Trend Micro
2012-08-14 13:57 . 2012-08-14 13:57 -------- d-----w- c:\programdata\Norton
2012-08-02 14:25 . 2012-08-02 14:25 1826624 ----a-w- c:\windows\system32\auto_reactivate.exe
2012-08-02 14:25 . 2012-08-02 14:25 -------- d-----r- C:\bootwiz
2012-08-02 12:44 . 2012-08-02 12:44 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-08-01 17:52 . 2008-03-17 09:57 103680 ----a-w- c:\windows\system32\drivers\ewusbfake.sys
2012-08-01 17:52 . 2008-03-17 09:05 101632 ----a-r- c:\windows\system32\drivers\ewusbmdm.sys
2012-08-01 17:52 . 2008-03-16 12:47 872192 ----a-w- c:\windows\system32\drivers\mod7700.sys
2012-08-01 17:52 . 2008-01-22 13:10 100864 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2012-08-01 17:52 . 2007-08-09 02:06 23424 ----a-r- c:\windows\system32\drivers\ewdcsc.sys
2012-08-01 17:52 . 2012-08-01 17:53 -------- d-----w- c:\program files\MD-@ HSUPA
2012-08-01 17:47 . 2012-08-01 17:47 -------- d-----w- c:\programdata\eMule
2012-07-31 17:06 . 2012-07-31 17:06 -------- d-----w- c:\program files\MSXML 4.0
2012-07-31 16:52 . 2012-07-31 16:52 159168 ----a-w- c:\windows\system32\drivers\afcdp.sys
2012-07-31 16:52 . 2012-07-31 16:52 911552 ----a-w- c:\windows\system32\drivers\tdrpm255.sys
2012-07-31 16:52 . 2012-07-31 16:52 570016 ----a-w- c:\windows\system32\drivers\timntr.sys
2012-07-31 16:52 . 2012-07-31 16:52 157248 ----a-w- c:\windows\system32\drivers\snapman.sys
2012-07-31 16:52 . 2012-07-31 16:52 -------- d-----w- c:\program files\Common Files\Acronis
2012-07-31 16:52 . 2012-07-31 16:52 -------- d-----w- c:\program files\Acronis
2012-07-31 16:43 . 2012-07-31 16:43 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2012-07-31 16:43 . 2012-07-31 16:44 -------- d-----w- c:\program files\DivX
2012-07-31 16:43 . 2012-07-31 16:43 -------- d-----w- c:\windows\tessdata
2012-07-31 16:43 . 2012-07-31 16:43 -------- d-----w- c:\program files\Softi Software
2012-07-31 16:41 . 2012-07-31 16:41 -------- d-----w- c:\program files\VideoLAN
2012-07-31 16:20 . 2012-07-31 16:20 -------- d-----w- C:\MiCla
2012-07-31 10:37 . 2012-07-31 10:37 -------- d-----w- c:\program files\Nuvoton Technology Corporation
2012-07-31 10:26 . 2012-07-31 10:31 -------- d-----w- c:\windows\Driver Cache
2012-07-31 10:26 . 2012-07-31 10:26 -------- d-----w- c:\program files\AVerMedia
2012-07-31 10:25 . 2009-06-09 11:28 64000 ------w- c:\windows\system32\agrsmdel.exe
2012-07-31 10:25 . 2012-07-31 10:25 -------- d-----w- c:\program files\LSI SoftModem
2012-07-31 10:24 . 2012-07-31 10:24 -------- d-----w- c:\windows\Options
2012-07-31 10:17 . 2012-07-31 10:17 -------- d-----w- c:\programdata\ATI
2012-07-31 10:15 . 2012-07-31 10:15 -------- d-----w- c:\program files\DIFX
2012-07-31 10:15 . 2012-07-31 10:15 -------- dc----w- c:\windows\system32\DRVSTORE
2012-07-31 10:15 . 2009-06-05 01:53 27320 ----a-w- c:\windows\system32\drivers\usbfilter.sys
2012-07-31 10:15 . 2012-07-31 10:15 -------- d-----w- c:\program files\AMD
2012-07-31 10:10 . 2012-07-31 10:13 -------- d-----w- c:\program files\ATI Technologies
2012-07-31 10:10 . 2012-07-31 10:10 -------- d-----w- c:\program files\ATI
2012-07-31 10:00 . 2009-08-10 09:06 171520 ----a-w- c:\windows\system32\drivers\RtsUStor.sys
2012-07-31 09:57 . 2009-07-24 16:08 1658880 ----a-w- c:\windows\Acer Crystal Eye webcam.EXE
2012-07-31 09:57 . 2009-07-24 13:44 8362 ----a-w- c:\windows\Suyin.reg
2012-07-31 09:57 . 2008-12-30 11:42 626688 ----a-w- c:\windows\Image.dll
2012-07-31 09:57 . 2008-07-29 17:29 200704 ----a-w- c:\windows\PLFSetI.exe
2012-07-31 09:57 . 2008-06-25 12:22 20480 ----a-w- c:\windows\USB_VIDEO_REG.exe
2012-07-31 09:47 . 2012-07-31 09:49 -------- d--h--w- c:\program files\Temp
2012-07-31 09:47 . 2009-06-24 08:43 831488 ----a-w- c:\windows\RtlExUpd.dll
2012-07-31 09:30 . 2012-07-31 09:30 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-07-31 09:29 . 2012-07-31 09:29 -------- d-----w- c:\windows\PCHEALTH
2012-07-31 09:29 . 2012-07-31 09:29 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-07-31 09:29 . 2012-07-31 09:29 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-07-31 09:27 . 2012-07-31 09:27 -------- d-----w- C:\IDE
2012-07-31 09:27 . 2012-07-31 09:27 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-07-31 09:26 . 2012-07-31 09:26 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-07-31 09:25 . 2012-08-19 18:39 -------- d-----w- c:\programdata\Microsoft Help
2012-07-31 09:25 . 2012-07-31 09:25 -------- d-----r- C:\MSOCache
2012-07-31 09:24 . 2012-07-31 09:41 -------- d-----w- c:\programdata\CyberLink
2012-07-31 09:20 . 2012-07-31 09:21 -------- d-----w- c:\program files\CyberLink
2012-07-31 07:45 . 2012-07-31 07:51 -------- d-----w- c:\programdata\Nero
2012-07-31 07:44 . 2012-07-31 07:45 -------- d-----w- c:\program files\Common Files\Nero
2012-07-31 07:44 . 2012-07-31 07:51 -------- d-----w- c:\program files\Nero
2012-07-31 07:36 . 2012-07-31 09:12 -------- d-----w- c:\program files\Microsoft.NET
2012-07-31 07:35 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2012-07-31 07:34 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2012-07-31 07:33 . 2008-10-15 04:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2012-07-31 07:33 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2012-07-31 07:32 . 2007-05-16 14:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2012-07-31 07:12 . 2012-07-31 07:12 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin7.dll
2012-07-31 07:12 . 2012-07-31 07:12 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin6.dll
2012-07-31 07:12 . 2012-07-31 07:12 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin5.dll
2012-07-31 07:12 . 2012-07-31 07:12 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin4.dll
2012-07-31 07:12 . 2012-07-31 07:12 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin3.dll
2012-07-31 07:12 . 2012-07-31 07:12 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin2.dll
2012-07-31 07:12 . 2012-07-31 07:12 159744 ----a-w- c:\program files\Internet Explorer\Plugin\npqtplugin.dll
2012-07-31 07:12 . 2012-07-31 07:12 -------- d-----w- c:\program files\QuickTime
2012-07-31 07:12 . 2012-07-31 07:12 -------- d-----w- c:\programdata\Apple Computer
2012-07-31 07:11 . 2012-07-31 07:11 -------- d-----w- c:\program files\Protector Suite
2012-07-31 07:11 . 2012-07-31 07:11 -------- d-----w- c:\program files\Common Files\Apple
2012-07-31 07:11 . 2012-07-31 07:11 -------- d-----w- c:\program files\Apple Software Update
2012-07-31 07:11 . 2012-07-31 07:11 -------- d-----w- c:\programdata\Apple
2012-07-31 07:10 . 2012-05-04 09:59 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-07-31 07:09 . 2012-07-31 07:10 -------- d-----w- c:\program files\Common Files\Adobe
2012-07-31 07:09 . 2009-07-21 12:18 1161760 ----a-w- c:\windows\system32\drivers\AGRSM.sys
2012-07-31 07:09 . 2009-06-09 11:28 64000 ----a-w- c:\windows\agrsmdel.exe
2012-07-31 07:09 . 2009-03-27 16:12 13824 ------w- c:\windows\system32\agrscoin.dll
2012-07-31 07:09 . 2009-08-23 05:01 103952 ----a-w- c:\windows\system32\drivers\AtiHdmi.sys
2012-07-31 07:09 . 2011-02-19 06:30 805376 ----a-w- c:\windows\system32\FntCache.dll
2012-07-31 07:09 . 2011-02-19 06:30 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-07-31 07:08 . 2012-08-19 18:39 -------- d-sh--w- c:\windows\Installer
2012-07-31 01:03 . 2012-03-01 05:46 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-07-31 01:03 . 2012-03-01 05:33 159232 ----a-w- c:\windows\system32\imagehlp.dll
2012-07-31 01:03 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2012-07-30 18:16 . 2012-01-04 08:58 442880 ----a-w- c:\windows\system32\ntshrui.dll
2012-07-30 18:14 . 2011-10-15 05:38 534528 ----a-w- c:\windows\system32\EncDec.dll
2012-07-30 18:13 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe
2012-07-30 18:05 . 2012-07-30 17:13 -------- d-----w- c:\windows\Panther
2012-07-30 18:01 . 2011-02-03 05:54 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2012-07-30 17:51 . 2012-05-31 10:25 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-07-30 17:29 . 2012-08-19 16:06 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-30 17:29 . 2012-08-19 16:06 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-30 17:29 . 2012-07-30 17:29 -------- d-----w- c:\windows\system32\Macromed
2012-07-30 17:25 . 2010-11-20 02:30 40704 ----a-w- c:\windows\system32\drivers\vmstorfl.sys
2012-07-30 17:20 . 2012-07-30 17:20 -------- d-----w- c:\windows\system32\EventProviders
2012-07-30 17:19 . 2012-02-17 05:34 826880 ----a-w- c:\windows\system32\rdpcore.dll
2012-07-30 17:19 . 2012-02-17 04:13 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-30 18:04 . 2012-07-30 18:04 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-07-30 18:04 . 2012-07-30 18:04 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-07-30 18:04 . 2012-07-30 18:04 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-07-30 18:04 . 2012-07-30 18:04 152064 ----a-w- c:\windows\system32\wextract.exe
2012-07-30 17:46 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2012-07-18 17:47 . 2012-08-19 15:48 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-06-29 00:09 . 2012-08-19 18:35 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-06 06:49 . 2012-06-06 06:49 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-02 22:19 . 2012-07-30 17:14 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-07-30 17:14 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-07-30 17:14 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-07-30 17:14 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-07-30 17:14 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-07-30 17:14 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-07-30 17:14 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-07-30 17:14 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-07-30 17:14 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 04:40 . 2012-07-30 18:15 225280 ----a-w- c:\windows\system32\schannel.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mobile Partner"="c:\program files\MD-@ HSUPA\MD-@ HSUPA.exe" [2012-08-01 110592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"APVXDWIN"="c:\program files\Panda Security\Panda Antivirus Pro 2012\APVXDWIN.EXE" [2011-04-13 1000768]
"SCANINICIO"="c:\program files\Panda Security\Panda Antivirus Pro 2012\Inicio.exe" [2011-02-02 70464]
"NBAgent"="c:\program files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-03-26 1234216]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-02-18 77824]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2007-11-14 91432]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-23 7625248]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-13 98304]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-10-06 5076088]
"Servizio Acronis Scheduler2"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-10-06 357688]
"Iminent"="c:\program files\Iminent\Iminent.exe" [2012-07-12 1073784]
"IminentMessenger"="c:\program files\Iminent\Iminent.Messengers.exe" [2012-07-12 884856]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2010-03-24 10:55 55552 ----a-w- c:\windows\System32\avldr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0auto_reactivate \\?\Volume{d81323cc-da68-11e1-84fb-806e6f6e6963}\bootwiz\asrm.bin
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 PavSRK.sys;PavSRK.sys;c:\windows\system32\PavSRK.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [x]
S0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [x]
S0 tdrpman255;Acronis Try&Decide and Restore Points filter (build 255);c:\windows\system32\DRIVERS\tdrpm255.sys [x]
S1 ShldDrv;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShlDrv51.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [x]
S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AmFSM;AmFSM;c:\windows\system32\DRIVERS\amm8660.sys [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 PavProc;Panda Process Protection Driver;c:\windows\system32\DRIVERS\PavProc.sys [x]
S2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Antivirus Pro 2012\PskSvc.exe [x]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x]
S3 nuvotoncir;Nuvoton IR Transceiver;c:\windows\system32\DRIVERS\nuvotoncir.sys [x]
S3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-08-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-30 16:06]
.
2012-08-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1272699340-3794242445-4243704677-1000Core.job
- c:\users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-30 17:29]
.
2012-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1272699340-3794242445-4243704677-1000UA.job
- c:\users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-30 17:29]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.facebook.com/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\program files\Panda Security\Panda Antivirus Pro 2012\TPSrv.exe
c:\program files\PANDA SECURITY\PANDA ANTIVIRUS PRO 2012\WebProxy.exe
c:\windows\system32\atieclxx.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\PsCtrls.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe
c:\program files\Common Files\Panda Security\PavShld\pavprsrv.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\pavsrvx86.exe
c:\program files\Panda Security\Panda Antivirus Pro 2012\AVENGINE.EXE
c:\program files\Panda Security\Panda Antivirus Pro 2012\PsImSvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\conhost.exe
c:\users\user\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\sppsvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Ora fine scansione: 2012-08-21 17:14:51 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-08-21 15:14
ComboFix2.txt 2012-08-14 16:34
.
Pre-Run: 112.635.944.960 byte disponibili
Post-Run: 112.494.862.336 byte disponibili
.
- - End Of File - - EADD3E832237F66E393AFA7D3CF64C13