ComboFix 09-03-06.02 - Antonypax 2009-03-08 16:53:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.1022.693 [GMT 1:00]
Eseguito da: c:\documents and settings\Antonypax\Desktop\od.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Antonypax\Application Data\drivers\downld
c:\documents and settings\Antonypax\Application Data\drivers\downld\14865812.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14865890.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14865906.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14875093.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14875625.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14875953.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14876531.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14877750.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14878140.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14913703.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14914500.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14914937.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\14934671.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15001671.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15001812.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15001906.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15004250.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15024468.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15024593.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15024687.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15027609.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15027640.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15027656.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15033203.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15039609.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15040515.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15040937.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15041640.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15042828.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15044015.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15061640.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15062093.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15062468.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15107609.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15107718.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15187500.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15191578.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15191781.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\15191843.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\161203.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\170562.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\170656.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\180781.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\181484.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\182062.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\182890.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\184421.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\184953.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\196031.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\196843.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\197250.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\200156.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\204609.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\204781.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\214750.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\215406.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\216000.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\216781.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\218281.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\218671.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\222640.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\226640.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\228140.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\228593.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\243906.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\245343.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\290750.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\291062.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\291078.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\316187.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\319531.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\319640.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\330828.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\334203.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\334234.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\336984.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\338343.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\338421.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\342671.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\343078.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\343453.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\343578.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\346453.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\347062.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\347218.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\348375.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\348859.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\349625.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\356187.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\357390.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\357859.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\358593.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\360718.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\362812.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\371390.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\372125.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\372578.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\382609.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\383156.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\383609.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\393000.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\393312.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\393437.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\398203.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\398375.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\398390.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\477171.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\478687.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\479500.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\479937.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\479984.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\480078.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\484703.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\485109.exe
c:\documents and settings\Antonypax\Application Data\drivers\downld\485171.exe
c:\documents and settings\Antonypax\Application Data\drivers\srosa2.sys
c:\documents and settings\Antonypax\Application Data\drivers\wfsintwq.sys
c:\documents and settings\Antonypax\Application Data\drivers\winupgro.exe
c:\documents and settings\Antonypax\Application Data\m
c:\documents and settings\Antonypax\Application Data\m\data.oct
c:\documents and settings\Antonypax\Application Data\m\flec006.exe
c:\documents and settings\Antonypax\Application Data\m\list.oct
c:\documents and settings\Antonypax\Application Data\m\shared\.zip
c:\documents and settings\Antonypax\Application Data\m\shared\[App-Ita].AVG.Antivirus.V.7.1.Italiano.Con.Seriale.zip
c:\documents and settings\Antonypax\Application Data\m\shared\3D Sound Tester 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\70-284 Microsoft MCSE Exchange Server 20 8.02.05.zip
c:\documents and settings\Antonypax\Application Data\m\shared\AA Mail Server 3.99.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Active Query Builder Free Edition 1.10.5.4.zip
c:\documents and settings\Antonypax\Application Data\m\shared\AEVITA Stop SPAM Email 1.01 (Key+Serial).zip
c:\documents and settings\Antonypax\Application Data\m\shared\Aluminium Drop-Down Menu 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Astrosiege 1.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Avex DVD to iPod Video Suite 4.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Awesome Antique Autos Lite 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Awesome Antique Autos Screen Saver 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Bluefox iPhone Video Converter 2.10.08.1127.zip
c:\documents and settings\Antonypax\Application Data\m\shared\BMI-HealthMonitor Calculator 1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\CalendarPro 2.43.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Colour Spy 1.5.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Convert XLS 3.44 (Crack).zip
c:\documents and settings\Antonypax\Application Data\m\shared\Coolexon 1.2.0006 (Serial).zip
c:\documents and settings\Antonypax\Application Data\m\shared\copy2calendar 2.0.0.25.zip
c:\documents and settings\Antonypax\Application Data\m\shared\CoreProfessional 7.5.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Creative MediaSource DVD-Audio Player 2.00.77 Beta.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Date V6.zip
c:\documents and settings\Antonypax\Application Data\m\shared\DeepTrawl 1.1 (KeyGen).zip
c:\documents and settings\Antonypax\Application Data\m\shared\DiamondCS Port Explorer 2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Dominions II The Ascension Wars 2.08.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Drive tray Manipulator 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Dungeon Master II demo.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Ease DVD Ripper 1.10 Key+Serial.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Easy calculator 1.23.zip
c:\documents and settings\Antonypax\Application Data\m\shared\EditURLs 2.02.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Encopy 4.52.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Event Manager 2.1.0.247.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Export Query to XML for SQL server 1.02.00 (Patch).zip
c:\documents and settings\Antonypax\Application Data\m\shared\Fast Shutdown Gadget 1.0.0.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\FastYub! 2.1.1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\FileInfo 2.9.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Fishing Expert 4.0a.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Flash Horizontal Menu Wizard 2.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Framing Station 4.22.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Grumpy Badger's Nine Men's Morris 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\HCM Toolbar 1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\HTML Protect 2.0 With Crack.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Imp's Recycle Bin 1.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Integrated Business Decisions 3.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\JRS Service Manager 0.1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Kaspersky.Anti-Virus.6.0.0.299.(español.-.spanish).+.key.zip
c:\documents and settings\Antonypax\Application Data\m\shared\LanHunter 1.50 Patch.zip
c:\documents and settings\Antonypax\Application Data\m\shared\LEC Translate DotNet 3.0r18.zip
c:\documents and settings\Antonypax\Application Data\m\shared\LED-Bar 1.0 Crack.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Los Padres Bank Mortgage Rates 1.6.zip
c:\documents and settings\Antonypax\Application Data\m\shared\M2ScreenMag 1.5.zip
c:\documents and settings\Antonypax\Application Data\m\shared\MacPing 3.0.4.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Magic Desktop Max 11.9.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Marspc Remote Desktop Computing 3.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\mdf2iso 0.3.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Message Sniffer 2.3.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\MiniCinema! 2.0.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Monitor On-Off 2.0.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\MyMoody Widget 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Neomesh Image Converter 2.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\NS-Batch 0.6e.zip
c:\documents and settings\Antonypax\Application Data\m\shared\OfficePopup 1.23.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Offline Page validator 0.3.zip
c:\documents and settings\Antonypax\Application Data\m\shared\OggCarton for Windows 1.0 Beta.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Omega Messenger 3.1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Open Video Joiner 3.2.1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Operation Flashpoint Cold War Crisis - Tour of War map (episode 9).zip
c:\documents and settings\Antonypax\Application Data\m\shared\Operation Flashpoint Resistance - Air Base Raid 1.05 map.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Optidraft 2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\ParaIrc 0.2.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\PassWallet 1.1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Paste From Console Plugin for Windows Live Writer 1.0.0.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\PCMark Vantage Basic 1.0.0.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\PDF Watermarks 1.0.0.0 [Key].zip
c:\documents and settings\Antonypax\Application Data\m\shared\PhpbbXtra 1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Pixel Pick 1.5.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Plato DVD to PSP + Video to PSP Package 4.84.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Ploing2 1.22.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Portable GIMP 2.2.17.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Portable Splitter Light 4.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Power Siphon 1.9.6.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\PowerTCP Emulation Tool 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\QCD AudioTracker 1.1.0.109.zip
c:\documents and settings\Antonypax\Application Data\m\shared\QualSoft Toshiba TEC BX Windows NT 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Quotator 1.2.0.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Recipes Galore 4.8.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Registry Genius 3.14.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Remote Desktop Enabler 2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Remover for I-Worm.Sobig 1.3.zip
c:\documents and settings\Antonypax\Application Data\m\shared\RudPad 0.5.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\S.M.A.R.T. Explorer 1.0.0.551.zip
c:\documents and settings\Antonypax\Application Data\m\shared\SayTunes 1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\SendTo 1.6 build 1016.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Server Watch 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\ShadowKeys 1.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Shell Jigsaw Puzzle 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Sirius Player 0.5.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Skater .NET Obfuscator 3.01.7.zip
c:\documents and settings\Antonypax\Application Data\m\shared\SlickRun 3.9.4.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Soldier of Fortune II Double Helix - Avanti map.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Space Classic 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Splash Screen Component 1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Split Video from CAM or Video FILE 3.16.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Spodradio 1.0.6.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Sri Bhajana Rahasya 1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\SubTool 2.6.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Super Puzzle Bobble 240x320 Nokia n92 n93 n73 e61 n71 e50 Adapted.zip
c:\documents and settings\Antonypax\Application Data\m\shared\SwitchBlade 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\TeoSoft AntiSpyware Pro 1.0.0.26.zip
c:\documents and settings\Antonypax\Application Data\m\shared\TimeCard for Outlook 4.1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Tinysoar DVD to PSP Converter 1.6.2.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Top Secret 1.1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Transparent Menus 1.0.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\TreeBase Generator 1.0.42d.zip
c:\documents and settings\Antonypax\Application Data\m\shared\UltraISO PE 8.6.3.2056 Cracked.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Unreal Tournament 2004 Jailbreak mod UMOD Version.zip
c:\documents and settings\Antonypax\Application Data\m\shared\ValueMaker 1.7.3b.zip
c:\documents and settings\Antonypax\Application Data\m\shared\vbMysqlBrowse 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Video to Apple TV Converter 2.9.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Web Alerts 1.zip
c:\documents and settings\Antonypax\Application Data\m\shared\What's In My Piggybank (WIMP) 1.23.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Windows Server 2008 Developer Training Kit 1.0 Beta 3.zip
c:\documents and settings\Antonypax\Application Data\m\shared\WISCO Word Power 2.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Wolga 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\shared\Zebra Screen Savers 5 1.0.zip
c:\documents and settings\Antonypax\Application Data\m\srvlist.oct
c:\documents and settings\Default\Application Data\FunWebProducts
c:\documents and settings\Default\Menu Avvio\Programmi\Videos.url
c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\windows\setup.exe
c:\windows\system32\ban_list.txt
c:\windows\system32\drivers\down
c:\windows\system32\drivers\down\304281.exe
c:\windows\system32\drivers\srosa2.sys
c:\windows\system32\lctryeff.ini
c:\windows\system32\mdelk.exe
c:\windows\system32\wintems.exe
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SROSA
-------\Legacy_SROSA
-------\Legacy_SK9OU0S
((((((((((((((((((((((((( Files Creati Da 2009-02-08 al 2009-03-08 )))))))))))))))))))))))))))))))))))
.
2009-03-06 20:10 . 2009-03-06 20:10 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Fighters
2009-03-06 16:08 . 2004-12-16 16:32 176,128 --a------ c:\windows\system32\NVUNINST.EXE
2009-03-06 16:07 . 2009-03-06 16:07 <DIR> d-------- c:\programmi\NVIDIA Corporation
2009-03-06 16:07 . 2009-03-06 16:07 <DIR> d-------- c:\programmi\File comuni\NVIDIA Shared
2009-03-06 16:07 . 2005-04-04 18:59 176,128 --a------ c:\windows\system32\nvumpu.exe
2009-03-06 16:07 . 2005-04-04 18:59 176,128 --a------ c:\windows\system32\nvuaudio.exe
2009-03-06 15:59 . 2009-03-06 15:59 <DIR> d-------- C:\NVIDIA
2009-03-05 20:54 . 2009-03-05 20:54 21,764 --a------ c:\windows\system32\CoreAAC-uninstall.exe
2009-03-04 16:45 . 2009-03-08 16:57 <DIR> d--h----- c:\documents and settings\Antonypax\Application Data\drivers
2009-02-24 18:45 . 2009-02-24 18:48 <DIR> d-------- c:\programmi\AutoCAD 2008
2009-02-24 18:45 . 2009-02-24 18:45 <DIR> d-------- c:\documents and settings\Antonypax\Application Data\Autodesk
2009-02-24 18:45 . 2009-02-24 18:49 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Autodesk
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-08 16:03 --------- d-----w c:\documents and settings\Antonypax\Application Data\Skype
2009-03-08 16:02 --------- d-----w c:\documents and settings\Antonypax\Application Data\skypePM
2009-03-08 15:21 --------- d-----w c:\programmi\ESET
2009-03-08 08:55 --------- d-----w c:\programmi\File comuni\Autodesk Shared
2009-03-06 22:28 --------- d-----w c:\programmi\Desktop XP
2009-03-06 21:14 --------- d-----w c:\programmi\Windows Live Safety Center
2009-03-06 15:07 --------- d--h--w c:\programmi\InstallShield Installation Information
2009-02-27 13:30 --------- d-----w c:\programmi\Microsoft Silverlight
2009-02-25 21:34 --------- d-----w c:\documents and settings\Antonypax\Application Data\gtk-2.0
2009-02-24 17:44 --------- d-----w c:\programmi\Autodesk
2009-02-22 22:26 --------- d-----w c:\documents and settings\Antonypax\Application Data\LimeWire
2009-02-21 10:30 --------- d-----w c:\programmi\iHabbix V3
2009-02-11 11:38 --------- d-----w c:\programmi\Messenger Plus! Live
2009-01-17 22:21 --------- d-----w c:\programmi\File comuni\Alias Shared
2009-01-17 22:18 47,616 ----a-w c:\windows\system32\drivers\Haspnt.sys
2009-01-10 23:30 --------- d-----w c:\programmi\File comuni\DAZ
2009-01-10 23:17 --------- d-----w c:\programmi\DAZ
2009-01-09 17:00 --------- d-----w c:\programmi\Google
2008-12-25 21:50 31,334,932 -c--a-w c:\programmi\Windows Live.zip
2008-10-23 17:23 22,368 ----a-w c:\documents and settings\Antonypax\eltnhiqo.exe
2008-10-23 17:21 22,368 ----a-w c:\documents and settings\Antonypax\vhnifcjd.exe
2008-10-22 16:28 22,368 ----a-w c:\documents and settings\Antonypax\xqfnfokf.exe
2008-10-22 16:27 22,368 ----a-w c:\documents and settings\Antonypax\vjyshqqu.exe
2008-10-22 16:26 22,368 ----a-w c:\documents and settings\Antonypax\hlwuwpdf.exe
2008-10-22 16:24 22,368 ----a-w c:\documents and settings\Antonypax\zzdhxzvw.exe
2008-10-22 16:21 22,368 ----a-w c:\documents and settings\Antonypax\tfyqzuah.exe
2008-10-22 16:19 22,368 ----a-w c:\documents and settings\Antonypax\dtmzkrrz.exe
2008-10-22 13:56 22,368 ----a-w c:\documents and settings\Antonypax\fdetmdap.exe
2008-10-22 13:31 22,368 ----a-w c:\documents and settings\Antonypax\xwlthquy.exe
2008-10-22 13:30 22,368 ----a-w c:\documents and settings\Antonypax\ekheodud.exe
2008-10-22 13:28 22,368 ----a-w c:\documents and settings\Antonypax\lobkqfpr.exe
2008-10-21 16:04 22,368 ----a-w c:\documents and settings\Antonypax\ywtukgrw.exe
2008-10-21 16:03 22,368 ----a-w c:\documents and settings\Antonypax\ppoxrnfb.exe
2008-10-21 15:17 22,368 ----a-w c:\documents and settings\Antonypax\xfajvpgj.exe
2008-10-20 18:57 22,368 ----a-w c:\documents and settings\Antonypax\olecuzak.exe
2008-10-20 18:54 22,368 ----a-w c:\documents and settings\Antonypax\smtqyzvs.exe
2008-10-20 18:52 22,368 ----a-w c:\documents and settings\Antonypax\pgrduvwy.exe
2008-10-20 18:49 22,368 ----a-w c:\documents and settings\Antonypax\rslxkbnu.exe
2008-10-20 18:46 22,368 ----a-w c:\documents and settings\Antonypax\hgjuaefu.exe
2008-10-20 18:46 22,368 ----a-w c:\documents and settings\Antonypax\dzswyzlw.exe
2008-10-20 18:42 22,368 ----a-w c:\documents and settings\Antonypax\pwsimtiy.exe
2008-10-20 18:39 22,368 ----a-w c:\documents and settings\Antonypax\uhqkxngl.exe
2008-10-20 16:51 0 -c--a-w c:\documents and settings\Antonypax\apczvrpo.exe
2008-10-20 16:50 22,368 ----a-w c:\documents and settings\Antonypax\gbbghcfe.exe
2008-10-20 16:49 22,368 ----a-w c:\documents and settings\Antonypax\xtjikdhe.exe
2008-10-20 16:46 22,368 ----a-w c:\documents and settings\Antonypax\gdsnusmu.exe
2008-10-20 16:45 22,368 ----a-w c:\documents and settings\Antonypax\vmaiqlme.exe
2008-10-20 16:44 22,368 ----a-w c:\documents and settings\Antonypax\sexgwzwt.exe
2008-10-20 16:41 22,368 ----a-w c:\documents and settings\Antonypax\yqvxexen.exe
2008-10-20 16:40 22,368 ----a-w c:\documents and settings\Antonypax\zbeloqnk.exe
2008-10-19 17:20 22,368 ----a-w c:\documents and settings\Antonypax\ppmnuquv.exe
2008-10-19 17:15 22,368 ----a-w c:\documents and settings\Antonypax\uahgvpnw.exe
2008-10-19 17:11 22,368 ----a-w c:\documents and settings\Antonypax\wwrxbvgn.exe
2008-10-19 17:10 22,368 ----a-w c:\documents and settings\Antonypax\kcgxngjn.exe
2008-10-19 16:22 0 -c--a-w c:\documents and settings\Antonypax\fcbupqrh.exe
2008-10-19 12:49 0 -c--a-w c:\documents and settings\Antonypax\rjyemahs.exe
2008-10-19 12:46 22,368 ----a-w c:\documents and settings\Antonypax\nkgaxbwy.exe
2008-10-19 12:33 22,368 ----a-w c:\documents and settings\Antonypax\rkozfzud.exe
2008-10-18 17:48 0 -c--a-w c:\documents and settings\Antonypax\hcpltqle.exe
2008-10-17 19:18 0 -c--a-w c:\documents and settings\Antonypax\ctnkvjxp.exe
2008-10-17 19:17 22,368 ----a-w c:\documents and settings\Antonypax\ynphplof.exe
2008-10-17 19:17 22,368 ----a-w c:\documents and settings\Antonypax\mubkejjv.exe
2008-10-17 17:34 22,368 ----a-w c:\documents and settings\Antonypax\zqmgkrbf.exe
2008-10-17 17:33 22,368 ----a-w c:\documents and settings\Antonypax\ndclskij.exe
2008-10-17 17:30 22,368 ----a-w c:\documents and settings\Antonypax\wbgciwfs.exe
2008-10-17 17:29 22,368 ----a-w c:\documents and settings\Antonypax\whrbpwoq.exe
2008-10-17 17:29 22,368 ----a-w c:\documents and settings\Antonypax\prxsxcih.exe
2008-10-17 17:28 22,368 ----a-w c:\documents and settings\Antonypax\tptjyjem.exe
2008-10-17 16:46 22,368 ----a-w c:\documents and settings\Antonypax\xvgudavv.exe
2008-10-17 16:44 22,368 ----a-w c:\documents and settings\Antonypax\zjawtfwr.exe
2008-10-17 16:40 22,368 ----a-w c:\documents and settings\Antonypax\eltgnfai.exe
2008-10-17 16:30 22,368 ----a-w c:\documents and settings\Antonypax\tperlkrd.exe
2008-10-17 16:29 22,368 ----a-w c:\documents and settings\Antonypax\xbfqzwpz.exe
2008-10-17 16:14 22,368 ----a-w c:\documents and settings\Antonypax\jiminsnq.exe
2008-10-17 13:29 22,368 ----a-w c:\documents and settings\Antonypax\dgzrmost.exe
2008-10-17 13:22 22,368 ----a-w c:\documents and settings\Antonypax\falziijw.exe
2008-10-17 13:18 22,368 ----a-w c:\documents and settings\Antonypax\pvtfpcgi.exe
2008-10-16 20:32 22,368 ----a-w c:\documents and settings\Antonypax\nglnvjiv.exe
2008-10-16 19:46 8,013 ----a-w c:\documents and settings\Antonypax\ptjqyzgy.exe
2008-10-16 15:10 22,368 ----a-w c:\documents and settings\Antonypax\zvmviwka.exe
2008-10-15 20:29 22,368 ----a-w c:\documents and settings\Antonypax\qpdltuqv.exe
2008-10-15 20:28 22,368 ----a-w c:\documents and settings\Antonypax\oehgchol.exe
2008-10-15 20:05 22,368 ----a-w c:\documents and settings\Antonypax\tfogevqe.exe
2008-10-14 19:01 22,368 ----a-w c:\documents and settings\Antonypax\uuugkfdw.exe
2008-10-14 18:59 22,368 ----a-w c:\documents and settings\Antonypax\vuzztzov.exe
2008-10-14 18:58 22,368 ----a-w c:\documents and settings\Antonypax\yzlnansu.exe
2008-10-14 16:39 22,368 ----a-w c:\documents and settings\Antonypax\uskresbw.exe
2008-10-14 16:33 22,368 ----a-w c:\documents and settings\Antonypax\swvcfuom.exe
2008-10-14 12:32 0 -c--a-w c:\documents and settings\Antonypax\Application Data\wklnhst.dat
2008-08-23 15:07 2,075 -c--a-w c:\documents and settings\Antonypax\Application Data\SAS7_000.DAT
2008-05-07 14:50 13,533 -c--a-w c:\documents and settings\Default\cesqmvln.exe
2008-03-08 19:54 0 -c--a-w c:\documents and settings\Default\Application Data\wklnhst.dat
2008-02-20 00:29 22 -csha-w c:\windows\SMINST\HPCD.sys
2008-08-25 12:25 88 -csh--r c:\windows\system32\E3BFE33ED7.sys
2008-08-25 12:42 3,452 -csha-w c:\windows\system32\KGyGaAvL.sys
2008-09-10 19:24 32,768 -csha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008091020080911\index.dat
.
------- Sigcheck -------
2008-04-14 03:14 978432 3d46c53ca961c49272037f98807537bd c:\windows\explorer.exe
2007-06-13 14:10 1035776 b4e85805be6d23de697f7b3ba7492d0b c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2006-04-11 05:00 976896 cb74a931e8ea461edebabf8a91c9cc11 c:\windows\$NtServicePackUninstall$\explorer.exe
2006-04-11 05:00 1034752 d009e427de2e129ff87b03d87f349c73 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-14 03:14 978432 3d46c53ca961c49272037f98807537bd c:\windows\ServicePackFiles\i386\explorer.exe
2008-10-16 14:09 66584 2275f45e257d46e6500558b2930cb9a4 c:\windows\ServicePackFiles\i386\wuauclt.exe
2008-10-16 14:09 66584 2275f45e257d46e6500558b2930cb9a4 c:\windows\system32\wuauclt.exe
2008-10-16 14:09 51224 e654b78d2f1d791b30d0ed9a8195ec22 c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-18 5724184]
"SpybotSD TeaTimer"="h:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
"Dancer"="c:\programmi\Windows Plus\Dancer\Dancer.exe" [2004-08-10 188416]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"ManyCam"="h:\programmi\ManyCam 2.3\ManyCam.exe" [2008-08-19 1725736]
"Skype"="c:\programmi\Skype\Phone\Skype.exe" [2008-08-12 21741864]
"RocketDock"="c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 630784]
"WMPNSCFG"="c:\programmi\Windows Media Player\WMPNSCFG.exe" [2006-11-02 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-18 64512]
"hpWirelessAssistant"="c:\programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 458752]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-20 86016]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"QPService"="c:\programmi\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
"QlbCtrl"="c:\programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\programmi\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"avgnt"="c:\programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2009-03-08 266497]
"HP Software Update"="c:\programmi\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\programmi\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"DAEMON Tools-1033"="c:\programmi\D-Tools\daemon.exe" [2004-08-22 81920]
"ISUSPM Startup"="c:\progra~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\programmi\File comuni\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"WebcamMaxMoniter"="h:\programmi\WebcamMax\CAMTHINS.exe" [2006-07-20 73728]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Ulead AutoDetector v2"="c:\programmi\File comuni\Ulead Systems\AutoDetector\monitor.exe" [2009-03-08 90112]
"UVS10 Preload"="h:\programmi\File comuni\uvPL.exe" [2006-03-07 36864]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-12-04 406016]
"avast!"="h:\progra~1\Avast\ashDisp.exe" [2009-03-08 79224]
"NVMixerTray"="c:\programmi\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"nwiz"="nwiz.exe" [2006-07-20 c:\windows\system32\nwiz.exe]
"MsmqIntCert"="mqrt.dll" [2008-04-14 c:\windows\system32\mqrt.dll]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 c:\windows\system32\CHDAudPropShortcut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Antonypax\Menu Avvio\Programmi\Esecuzione automatica\
CamTrack.lnk - h:\programmi\CamTrack\camtrack.exe [2008-08-29 376832]
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
TransBar.lnk - c:\windows\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 65536]
UberIcon.lnk - c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-05-21 155648]
c:\documents and settings\Administrator\Menu Avvio\Programmi\Esecuzione automatica\
CamTrack.lnk - h:\programmi\CamTrack\camtrack.exe [2008-08-29 376832]
c:\documents and settings\CODY\Menu Avvio\Programmi\Esecuzione automatica\
CamTrack.lnk - h:\programmi\CamTrack\camtrack.exe [2008-08-29 376832]
c:\documents and settings\PATTY\Menu Avvio\Programmi\Esecuzione automatica\
CamTrack.lnk - h:\programmi\CamTrack\camtrack.exe [2008-08-29 376832]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Avvio rapido HP Photosmart Premier.lnk - c:\programmi\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 73728]
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=tbjqft.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= vdrcodec.dll
"vidc.mjpg"= Pvmjpg21.dll
"msacm.dvacm"= c:\progra~1\FILECO~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\FILECO~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\FILECO~1\ULEADS~1\MPEG\ulmp3acm.acm
"VIDC.PIM1"= pclepim1.dll
"SENTINEL"= snti386.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0sprecovr \SystemRoot\sprecovr.txt
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Programmi\\AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"h:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"h:\\Programmi\\Programs\\RM.exe"=
"h:\\Programmi\\Programs\\PMSRegisterFile.exe"=
"h:\\Programmi\\Programs\\umi.exe"=
"h:\\Programmi\\Programs\\VideoSpin.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"h:\\Programmi\\Programs\\Studio.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
R2 CachemanXPService;CachemanXP;h:\programmi\CachemanXP\CachemanXP.exe [2009-01-17 244736]
R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-06-06 61952]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-01-14 21632]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys

c:\windows\system32\DRIVERS\aswFsBlk.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S2 CamthWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CamthWDM.sys [2006-07-03 242736]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 RMCDRWFV;RMCDRWFV;c:\docume~1\ANTONY~1\IMPOST~1\Temp\RMCDRWFV.exe

c:\docume~1\ANTONY~1\IMPOST~1\Temp\RMCDRWFV.exe
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys

c:\windows\system32\drivers\ScreamingBAudio.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7940f16e-652b-11dd-af14-001636b39327}]
\Shell\AutoRun\command - G:\ClickMe.exe
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{20D23232-AED6-490D-A3C2-F08BA539A1FE} - (no file)
BHO-{5A591F99-C0AF-4F19-B908-7426EF6D7355} - (no file)
BHO-{7bcf824f-eb31-493d-86ca-9c90eaf2de50} - c:\windows\system32\tbjqft.dll
BHO-{8555BE5E-457E-4DC4-A76E-D007AECACEE3} - (no file)
BHO-{98B48BCC-2F5E-4954-8643-1A2C25795271} - (no file)
BHO-{BFD6CF8D-1EF2-4A70-B714-69E8C92F1A31} - (no file)
BHO-{F68A626C-26F4-41B7-8D03-ED773A0E52D1} - (no file)
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
HKCU-Run-swg - c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU-Run-Uniblue RegistryBooster 2 - c:\programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKCU-Run-DesktopIconToy - h:\programmi\Desktop Icon Toy\DesktopIconToy.exe
HKCU-RunOnce-Shockwave Updater - c:\windows\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB5; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET
HKLM-Run-FileBackup - c:\program files\Optimark\OTB\OTB.exe
HKLM-Run-NWEReboot - (no file)
Notify-mlJBTnmm - (no file)
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/webhp?rls=iguSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
DPF: CabBuilder -
hxxp://kiw.imgag.com/imgag/kiw/toolbar/ ... ontrol.cab.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-08 17:06:01
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\programmi\Hewlett-Packard\Default Settings\cpqset.exe??@?????????????L?@?????????????`?@?????L?@
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-1387477-214851956-2962684071-1005\Software\SecuROM\License information*]
"datasecu"=hex:b0,2c,b0,04,cb,c7,93,98,f9,de,9e,79,99,16,20,bb,eb,a5,f5,d8,22,
ca,17,a7,28,48,cf,ac,4a,0b,3f,6a,b0,68,de,fb,30,4c,53,51,b5,db,c6,15,b0,e9,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,5d,11,df,0d,10,
6f,84,29,c8,28,51,af,b0,29,a3,98,3a,7c,46,41,a5,62,bf,7d,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,92,b7,2e,96,b0,
eb,9a,83,71,3b,04,66,8b,46,0d,96,47,95,f2,fa,18,43,93,b5,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,29,b6,85,2b,6f,
7e,99,b7,25,da,ec,7e,55,20,c9,26,9a,1f,06,e4,d7,f1,47,f3,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,6a,fe,69,70,06,
27,71,e8,3e,1e,9e,e0,57,5a,93,61,9b,f2,1a,f9,db,96,6e,16,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,1b,4e,94,52,7e,
63,9b,53,cd,44,cd,b9,a6,33,6c,cd,bb,e5,07,1f,5a,e2,d2,11,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,2f,79,9e,d7,f1,
b1,79,1c,b0,18,ed,a7,3f,8d,37,a4,e5,f7,a0,7a,a4,b1,6c,88,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,61,48,68,35,09,
96,13,8c,31,77,e1,ba,b1,f8,68,02,d2,2e,df,c8,21,9a,2c,07,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,a3,60,da,1b,94,
73,a2,39,83,6c,56,8b,a0,85,96,ab,a3,40,fe,d8,c5,e1,36,d4,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:b2,46,9a,e2,1b,fe,1b,94,d3,ff,3b,8b,65,
61,5a,9b,51,fa,6e,91,28,9e,14,cc,cf,8b,1e,8f,c7,8d,c7,d4,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,d9,03,ac,5b,27,
8f,af,88,b1,cd,45,5a,a8,c4,f8,b9,4a,aa,10,b0,2f,2e,d9,f6,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,e2,d6,83,1e,97,
d3,8b,7b,e3,0e,66,d5,eb,bc,2f,6b,d9,f0,a5,56,1c,b7,81,ee,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:05,73,21,dd,54,d8,4a,c5,ac,31,73,e2,5b,
1b,f6,9c,fa,ea,66,7f,d4,3b,6b,70,08,1e,e0,38,d9,e1,a0,64,6c,43,2d,1e,aa,22,\
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\msdtc.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\File comuni\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\mqsvc.exe
c:\programmi\Windows Media Player\wmpnetwk.exe
c:\programmi\HP\Digital Imaging\bin\hpqimzone.exe
c:\programmi\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\mqtgsvc.exe
c:\programmi\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\HP\Digital Imaging\bin\hpqste08.exe
c:\programmi\HP\Digital Imaging\bin\hpqbam08.exe
c:\programmi\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Ora fine scansione: 2009-03-08 17:19:15 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-03-08 16:19:11
Pre-Run: 48,696,180,736 byte disponibili
Post-Run: 51,082,842,112 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptOut
647 --- E O F --- 2009-02-26 22:10:51