ComboFix 12-08-18.03 - Samuele 19/08/2012 18:39:34.1.1 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.39.1040.18.958.410 [GMT 2:00]
Eseguito da: c:\users\Samuele\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Samuele\AppData\Roaming\Microsoft\Windows\lwE9H2ZWNTb4KlAE.dat
.
.
((((((((((((((((((((((((( Files Creati Da 2012-07-19 al 2012-08-19 )))))))))))))))))))))))))))))))))))
.
.
2012-08-19 16:47 . 2012-08-19 16:48 -------- d-----w- c:\users\Samuele\AppData\Local\temp
2012-08-19 16:47 . 2012-08-19 16:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-19 16:47 . 2012-08-19 16:47 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-08-19 15:44 . 2012-08-19 15:52 -------- d-----w- c:\users\Samuele\AppData\Roaming\driveridentifier
2012-08-17 19:51 . 2002-07-25 15:06 282624 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\agent.exe
2012-08-17 19:51 . 2002-12-05 12:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2012-08-17 19:51 . 2012-08-17 19:51 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2012-08-17 19:51 . 2012-08-17 19:51 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2012-08-17 19:51 . 2003-02-27 14:12 696320 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2012-08-17 19:51 . 2002-12-02 13:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2012-08-17 16:28 . 2012-08-17 16:28 388096 ----a-r- c:\users\Samuele\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-17 03:11 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-17 03:11 . 2012-08-17 03:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-17 02:35 . 2012-08-17 02:35 -------- d-----w- c:\program files\CDBurnerXP
2012-08-17 01:57 . 2012-08-17 01:57 -------- d-----w- c:\users\Samuele\AppData\Local\AskToolbar
2012-08-17 01:54 . 2012-08-17 01:54 -------- d-----w- c:\users\Samuele\AppData\Roaming\Avira
2012-08-17 01:39 . 2012-08-17 01:39 -------- d-----w- c:\program files\Ask.com
2012-08-17 01:38 . 2012-08-17 15:46 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-08-17 01:38 . 2012-08-17 15:46 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-08-17 01:38 . 2012-02-03 13:26 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-08-17 01:38 . 2012-08-17 01:38 -------- d-----w- c:\program files\Avira
2012-08-16 14:59 . 2012-08-16 15:19 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-16 14:59 . 2012-08-16 15:19 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 23:09 . 2012-08-15 23:11 8281168 ----a-w- c:\programdata\Microsoft\BingBar\BBSvc\7.1.391.0oemBingBarSetup-Partner.EXE
2012-08-15 17:43 . 2012-08-15 17:43 -------- d-----w- c:\program files\Trend Micro
2012-08-15 16:45 . 2012-07-18 17:47 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-08-15 16:45 . 2012-05-05 07:46 400896 ----a-w- c:\windows\system32\srcore.dll
2012-08-15 16:45 . 2012-02-11 05:43 492032 ----a-w- c:\windows\system32\win32spl.dll
2012-08-15 16:45 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-15 16:44 . 2012-07-04 21:14 102912 ----a-w- c:\windows\system32\browser.dll
2012-08-15 16:44 . 2012-07-04 21:14 41984 ----a-w- c:\windows\system32\browcli.dll
2012-08-15 16:44 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll
2012-08-11 18:34 . 2012-08-11 18:34 -------- d-----w- c:\users\Samuele\AppData\Local\APN
2012-08-09 00:15 . 2012-08-09 00:19 1660 ----a-w- c:\windows\system32\ASOROSet.bin
2012-08-07 16:46 . 2012-08-07 20:12 161264 ----a-w- c:\windows\system32\drivers\sfi.dat
2012-08-07 16:26 . 2012-05-29 15:19 31584 ----a-w- c:\windows\system32\TURegOpt.exe
2012-08-07 16:26 . 2012-05-29 15:19 21344 ----a-w- c:\windows\system32\authuitu.dll
2012-08-07 16:25 . 2012-08-07 16:26 -------- d-----w- c:\program files\TuneUp Utilities 2012
2012-08-07 16:22 . 2012-07-16 12:25 17320 ----a-w- c:\windows\system32\roboot.exe
2012-08-07 16:22 . 2012-08-07 16:22 -------- d-----w- c:\program files\RegClean Pro
2012-08-07 16:21 . 2012-08-07 20:23 -------- d-----w- c:\programdata\CPA_VA
2012-08-07 16:15 . 2012-08-07 16:16 -------- d-----w- c:\program files\Common Files\Adobe
2012-08-07 16:14 . 2012-08-07 16:14 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-08-07 16:14 . 2012-08-07 16:14 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2012-08-07 16:14 . 2012-08-07 16:14 1060864 ----a-w- c:\windows\system32\mfc71.dll
2012-08-07 16:08 . 2012-08-07 16:09 -------- d-----w- c:\program files\CCleaner
2012-07-29 06:35 . 2012-07-23 11:32 98192 ----a-w- c:\windows\system32\drivers\MsgPlusDriver.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-19 16:46 . 2012-08-19 16:46 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C83B37E5-4EA8-40E4-9739-5D774655560E}\offreg.dll
2012-07-23 13:59 . 2012-07-02 16:03 22400 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-07-07 14:21 . 2012-06-24 16:19 477240 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-07-02 16:05 . 2012-07-02 16:05 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-07-02 16:05 . 2012-07-02 16:05 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-07-02 16:05 . 2012-07-02 16:05 805376 ----a-w- c:\windows\system32\FntCache.dll
2012-06-30 16:07 . 2011-03-28 16:36 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-06-29 08:44 . 2012-08-17 13:58 6891424 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C83B37E5-4EA8-40E4-9739-5D774655560E}\mpengine.dll
2012-06-24 22:12 . 2012-06-24 22:12 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-06-24 22:12 . 2012-06-24 22:12 161792 ----a-w- c:\windows\system32\msls31.dll
2012-06-24 22:12 . 2012-06-24 22:12 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-06-24 22:12 . 2012-06-24 22:12 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-06-24 22:12 . 2012-06-24 22:12 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-06-24 22:12 . 2012-06-24 22:12 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-06-24 22:12 . 2012-06-24 22:12 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-06-24 22:12 . 2012-06-24 22:12 367104 ----a-w- c:\windows\system32\html.iec
2012-06-24 22:12 . 2012-06-24 22:12 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-06-24 22:12 . 2012-06-24 22:12 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-06-24 22:12 . 2012-06-24 22:12 152064 ----a-w- c:\windows\system32\wextract.exe
2012-06-24 22:12 . 2012-06-24 22:12 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-06-24 22:12 . 2012-06-24 22:12 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-06-24 22:12 . 2012-06-24 22:12 11776 ----a-w- c:\windows\system32\mshta.exe
2012-06-24 22:12 . 2012-06-24 22:12 101888 ----a-w- c:\windows\system32\admparse.dll
2012-06-24 22:12 . 2012-06-24 22:12 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-06-24 17:50 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2012-06-24 16:45 . 2012-06-24 16:46 8192 ----a-w- c:\windows\system32\srvany.exe
2012-06-24 16:45 . 2012-06-24 16:46 151552 ----a-w- c:\windows\KMService.exe
2012-06-06 06:49 . 2012-06-06 06:49 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-06 05:05 . 2012-07-11 07:18 1390080 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05 . 2012-07-11 07:18 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03 . 2012-07-11 07:18 805376 ----a-w- c:\windows\system32\cdosys.dll
2012-06-02 22:19 . 2012-06-28 21:26 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-28 21:26 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-28 21:25 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-28 21:25 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-28 21:26 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-28 21:26 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-28 21:25 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-28 21:24 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-28 21:24 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 04:45 . 2012-07-11 07:18 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45 . 2012-07-11 07:18 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40 . 2012-07-11 07:18 369336 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 04:40 . 2012-07-11 07:18 225280 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 04:39 . 2012-07-11 07:18 219136 ----a-w- c:\windows\system32\ncrypt.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
2010-11-04 15:58 297808 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-06-20 11:18 1519824 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-06-20 1519824]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-06-20 1519824]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-06-20 1568976]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-17 348664]
"PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2012-07-24 801792]
"SoundMan"="SOUNDMAN.EXE" [2007-03-09 598016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Browser Infrastructure Helper]
2012-06-25 10:10 19312 ----a-w- c:\users\Samuele\AppData\Local\Smartbar\Application\Smartbar.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"EPSON SX125 Series"=c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIGGE.EXE /FU "c:\windows\TEMP\E_S6E68.tmp" /EF "HKCU"
"Google Update"="c:\users\Samuele\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"CCleaner"=c:\program files\CCleaner\CCleaner.exe
"TuneUp Utilities - Interfaccia di avvio"=c:\program files\TuneUp Utilities 2012\Integrator.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
R4 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [x]
R4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R4 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Pianificatore;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Web Protection;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
S2 KMService;KMService;c:\windows\system32\srvany.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [x]
S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
S3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;c:\windows\system32\DRIVERS\fetnd6v.sys [x]
S3 MsgPlusDriver;Messenger Plus! Virtual Camera;c:\windows\system32\DRIVERS\MsgPlusDriver.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [x]
.
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-08-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-16 15:19]
.
2012-08-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-112170123-896870011-3457703113-1000Core.job
- c:\users\Samuele\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-17 01:27]
.
2012-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-112170123-896870011-3457703113-1000UA.job
- c:\users\Samuele\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-17 01:27]
.
2012-08-19 c:\windows\Tasks\RegClean Pro_DEFAULT.job
- c:\program files\RegClean Pro\RegCleanPro.exe [2012-08-07 12:25]
.
2012-08-19 c:\windows\Tasks\RegClean Pro_UPDATES.job
- c:\program files\RegClean Pro\RegCleanPro.exe [2012-08-07 12:25]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/uSearchAssistant =
hxxp://feed.plusnetwork.com/?publisher= ... sp=addr&q={searchTerms}&t=a0630
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: I&nvia a OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Scarica con Mipony -
file://c:\program files\MiPony\Browser\IEContext.htm
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\program files\PokerStars.IT\PokerStarsUpdate.exe
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.0.1
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2012-08-19 18:50:50
ComboFix-quarantined-files.txt 2012-08-19 16:50
.
Pre-Run: 42.366.849.024 byte disponibili
Post-Run: 42.292.379.648 byte disponibili
.
- - End Of File - - FFAF17AFE42792D1E8625C0E8B90C7B4