Sul mio pc fisso con Windows 7 Home Premium e, utilizzando come browser internet Explorer, avevo installato una versione di prova di AVG. Scaduto il tempo di prova, ho ignorato per alcuni giorni l'invito a rinnovare e questo è stato per me fatale. Navigando su un sito, mi sono visto chiudere tutte le finestre, spegnere il pc, e riavviare da solo. Alchè ho fatto subito una scansione con Malware antimalware che avevo già presente sul Pc. Mi trova alcuni Trojan, li elimino e riavvio. Una volta riavviato mi metto subito alla ricerca di un nuovo antivirus da installare, ma aimè il pc non mi permette l'installazione. Riesco a scaricarli, ma al momento dell'installazione mi dà errore che vedremo più avanti. Provo quindi in modalità provvisoria ma niente, stesso problema. Rifaccio una scansione con malware anti.. e il trojan è di nuovo lì: (Trojan.Agent , registry value HKLM\Software\Microsoft\Windows\Current version\Policies\Explorer\Run|3744). Provo quindi a farmi un disco di ripristino preparandomi alla formattazione, ma anche qua il pc non me lo permette. Armato quindi di Vostra giuda, con il pc del lavoro mi scarico su pennetta Avira Antivir, Combofix e Hijackthis. Dopo aver disattivato "Ripristino configurazione di sistema" scarico in modalità provv i programmi sul pc e parto con l'installazione. Avira però mi da subito un messaggio di errore: "C:\users\utente\appdata\local\temp\rarsfx0" Verzeichnis kann nicht angesprochen werden. Premo OK e non succede altro. Ho provato quindi a disattivare in modalità normale i servizi relativi, ma nella mia finestra non compare "Servizio trasferimento intelligente in background", "Windows defender" e neanche "Windows update". Quindi Avira non riesco ad utilizzarlo.
In provvisoria faccio scansione con Malware Anti-Malware, che mi ritrova il solito trojan, e poi proseguo con l'utilizzo di Combofix, che procede fino alla fine generando il file di log. Proseguo poi con Hijackthis ma al momento dell'installazione mi compare questa finestra di errore:" Run-time error '481' Invalid Picture". A questo punto non so come procedere, intanto metto il log di combofix, e se qualche anima nobile mi aiuta lo ringrazio tanto :-) .
ComboFix 14-01-04.03 - Utente 08/01/2014 21:50:19.1.2 - x64 NETWORK
Eseguito da: C:\Users\Utente\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
* Resident AV is active
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\@
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\L\00000004.@
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\L\76603ac3
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\U\00000004.@
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\U\00000008.@
C:\Program Files (x86)\WinRAR\Leggimi.Txt
C:\Program Files (x86)\WinRAR\Leggimi_1a.Txt
C:\Program Files (x86)\WinRAR\Licenza.Txt
C:\Program Files (x86)\WinRAR\NoteTecniche.Txt
C:\Program Files (x86)\WinRAR\Ordin.htm
C:\Program Files (x86)\WinRAR\Ordina.htm
C:\Program Files (x86)\WinRAR\SorgUnRAR.Txt
C:\ProgramData\Local Settings\Temp
C:\Users\Utente\AppData\Local\cygwin1.dll
C:\Users\Utente\AppData\Local\Google\Desktop\Install
C:\Users\Utente\AppData\Local\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\2E2F~1\28F0~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\@
C:\Users\Utente\AppData\Local\wuauclt.exe
C:\Users\Utente\AppData\Roaming\7go.ico
((((((((((((((((((((((((( Files Creati Da 2013-12-08 al 2014-01-08 )))))))))))))))))))))))))))))))))))
2014-01-08 20:54:48 . 2014-01-08 20:54:48 -------- d-----w- C:\Users\Default\AppData\Local\temp
2014-01-07 21:09:05 . 2014-01-07 21:09:05 422216 ----a-w- C:\Windows\system32\drivers\xinwaihy.sys
2014-01-07 21:09:04 . 2014-01-07 21:09:04 -------- d-----w- C:\ProgramData\AVAST Software
2013-12-30 20:38:46 . 2013-12-30 20:38:47 -------- d-----w- C:\Windows\7zS6637.tmp
2013-12-30 19:34:47 . 2013-12-30 19:34:47 422216 ----a-w- C:\Windows\system32\drivers\fefnpaue.sys
2013-12-30 18:32:51 . 2013-12-30 18:32:51 422216 ----a-w- C:\Windows\system32\drivers\llrowzja.sys
2013-12-30 17:54:53 . 2013-12-30 17:54:53 -------- d-----w- C:\Program Files (x86)\AVG Secure Search
2013-12-30 17:21:29 . 2013-12-30 17:21:29 422216 ----a-w- C:\Windows\system32\drivers\mwxpjilt.sys
2013-12-30 14:47:50 . 2013-12-30 14:47:50 422216 ----a-w- C:\Windows\system32\drivers\zhfvymlc.sys
2013-12-30 14:42:54 . 2013-12-30 14:42:54 422216 ----a-w- C:\Windows\system32\drivers\mbufbarj.sys
2013-12-30 14:38:24 . 2013-12-30 14:38:24 422216 ----a-w- C:\Windows\system32\drivers\avwqopgy.sys
2013-12-30 14:37:25 . 2013-12-30 14:37:25 422216 ----a-w- C:\Windows\system32\drivers\coykfbcl.sys
2013-12-30 12:51:13 . 2013-12-30 12:51:13 79824 ----a-w- C:\Windows\system32\drivers\201ffaf37a80d188.sys
2013-12-30 12:50:15 . 2014-01-08 20:54:27 -------- d-----w- C:\ProgramData\Local Settings
2013-12-19 09:14:12 . 2013-12-30 12:59:01 -------- d-----w- C:\Users\Utente\AppData\Roaming\VSStore
2013-12-14 12:56:48 . 2013-12-14 12:56:49 -------- d-----w- C:\Users\Utente\.android
2013-12-14 12:56:45 . 2013-12-14 12:56:45 -------- d-----w- C:\Users\Utente\AppData\Local\cache
2013-12-14 12:56:44 . 2013-12-14 12:56:44 -------- d-----w- C:\Users\Utente\AppData\Local\genienext
2013-12-14 12:56:43 . 2013-12-14 12:57:46 -------- d-----w- C:\Users\Utente\AppData\Local\Mobogenie
2013-12-14 12:56:26 . 2013-12-14 12:57:46 -------- d-----w- C:\Program Files (x86)\Mobogenie
2013-12-14 12:55:42 . 2013-12-30 12:59:02 -------- d-----w- C:\Users\Utente\AppData\Roaming\Iminent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
2013-12-11 18:37:21 . 2013-03-07 18:45:59 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-12-11 18:37:21 . 2012-01-11 15:56:29 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-04 16:35:46 . 2013-10-27 18:26:42 48648 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2013-11-04 16:35:42 . 2013-11-04 16:35:42 375632 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2013-10-27 18:26:38 . 2013-10-27 18:26:38 375632 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
[-] 2009-07-14 01:52:21 . !HASH: COULD NOT OPEN FILE !!!!! . 24128 . . [------] .. C:\Windows\system32\drivers\atapi.sys
[-] 2009-07-14 00:10:13 . !HASH: COULD NOT OPEN FILE !!!!! . 23040 . . [------] .. C:\Windows\system32\drivers\asyncmac.sys
[-] 2009-07-14 01:48:04 . !HASH: COULD NOT OPEN FILE !!!!! . 50768 . . [------] .. C:\Windows\system32\drivers\kbdclass.sys
[-] 2012-08-22 18:12:40 . !HASH: COULD NOT OPEN FILE !!!!! . 950128 . . [------] .. C:\Windows\system32\drivers\ndis.sys
[-] 2011-08-22 08:11:13 . !HASH: COULD NOT OPEN FILE !!!!! . 1659776 . . [------] .. C:\Windows\system32\drivers\ntfs.sys
[-] 2009-07-13 23:19:38 . !HASH: COULD NOT OPEN FILE !!!!! . 6144 . . [------] .. C:\Windows\system32\drivers\null.sys
[-] 2012-08-22 18:12:50 . !HASH: COULD NOT OPEN FILE !!!!! . 1913200 . . [------] .. C:\Windows\system32\drivers\tcpip.sys
[-] 2010-11-21 03:24:32 . !HASH: COULD NOT OPEN FILE !!!!! . 119296 . . [------] .. C:\Windows\system32\drivers\tdx.sys
[7] 2012-05-04 10:03:53 . A37A39568C8EC9A17D1B7471445B81A8 . 3916656 . . [6.1.7601.21987 (win7sp1_ldr.120503-2030)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21987_none_6e78bf732bb8d24e\ntoskrnl.exe
[7] 2012-05-04 10:03:50 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835 (win7sp1_gdr.120503-2030)] .. C:\Windows\erdnt\cache86\ntoskrnl.exe
[7] 2012-05-04 10:03:50 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835 (win7sp1_gdr.120503-2030)] .. C:\Windows\SysWOW64\ntoskrnl.exe
[7] 2012-05-04 10:03:50 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835 (win7sp1_gdr.120503-2030)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17835_none_6e2331b012747421\ntoskrnl.exe
[7] 2012-03-31 04:39:37 . 28F44480E411C3DDF04B63F6560E6EF4 . 3913072 . . [6.1.7601.17803 (win7sp1_gdr.120330-1504)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17803_none_6e41a0e0125deda0\ntoskrnl.exe
[7] 2012-03-31 04:37:33 . 2E02A17E8965AD671E4987E503AD38B1 . 3916656 . . [6.1.7601.21955 (win7sp1_ldr.120330-1503)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21955_none_6e972ea32ba24bcd\ntoskrnl.exe
[7] 2012-03-06 05:59:41 . 53B4BDEA12A032EEC71E60B6BFF42F37 . 3913072 . . [6.1.7601.17790 (win7sp1_gdr.120305-1505)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17790_none_6ddd4ed012a99fed\ntoskrnl.exe
[7] 2012-03-06 05:41:34 . 57B7DE30C4E65AD19CA13AC3065EE60B . 3916656 . . [6.1.7601.21936 (win7sp1_ldr.120305-1505)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21936_none_6eadcec52b912d42\ntoskrnl.exe
[7] 2011-08-23 12:05:04 . FB58ABD5E1F75A2CF713C9DFF0EC0804 . 3912576 . . [6.1.7601.17640 (win7sp1_gdr.110622-1506)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17640_none_6e135c8612811711\ntoskrnl.exe
[7] 2011-08-23 12:05:04 . 90EFDB506F6140EEA9DEE398D9449D86 . 3912576 . . [6.1.7601.21755 (win7sp1_ldr.110622-1503)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21755_none_6e972ad72ba2517f\ntoskrnl.exe
[7] 2011-08-22 08:15:23 . 5D21C487F79F8245E799071589E035BF . 3912576 . . [6.1.7601.17592 (win7sp1_gdr.110408-1631)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17592_none_6ddf4b9812a7d84d\ntoskrnl.exe
[7] 2011-08-22 08:15:23 . D385343510B75545EC5DB3A64C2D2492 . 3912576 . . [6.1.7601.21701 (win7sp1_ldr.110408-1634)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21701_none_6ec9394b2b7d606e\ntoskrnl.exe
[7] 2010-11-21 03:23:51 . 2088D9994332583EDB3C561DE31EA5AD . 3911040 . . [6.1.7601.17514 (win7sp1_rtm.101119-1850)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73\ntoskrnl.exe
[-] 2012-05-04 11:06:22 . !HASH: COULD NOT OPEN FILE !!!!! . 5559664 . . [------] .. C:\Windows\system32\ntoskrnl.exe
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-12-30 17:54:47 3333144 ----a-w- C:\Program Files (x86)\AVG Secure Search\17.2.0.38\AVG Secure Search_toolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "C:\Program Files (x86)\AVG Secure Search\17.2.0.38\AVG Secure Search_toolbar.dll" [2013-12-30 17:54:47 3333144]
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 16:36:46 30040]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 12:02:04 254696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
R1 Avgdiska;AVG Disk Driver;C:\Windows\system32\DRIVERS\avgdiska.sys;C:\Windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys;C:\Windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [x]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R2 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe;C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe [x]
R2 vToolbarUpdater17.2.0;vToolbarUpdater17.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [x]
R3 A38CCID;CCID USB Smart Card Reader;C:\Windows\system32\DRIVERS\a38ccid.sys;C:\Windows\SYSNATIVE\DRIVERS\a38ccid.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\system32\DRIVERS\ssudbus.sys;C:\Windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 LVUVC64;Logitech Webcam 120(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys;C:\Windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;C:\Windows\system32\drivers\TsUsbGD.sys;C:\Windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\system32\drivers\viahduaa.sys;C:\Windows\SYSNATIVE\drivers\viahduaa.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;C:\Windows\system32\Wat\WatAdminSvc.exe;C:\Windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys;C:\Windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;C:\Windows\system32\DRIVERS\avgloga.sys;C:\Windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys;C:\Windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 avgtp;avgtp;C:\Windows\system32\drivers\avgtpx64.sys;C:\Windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys;C:\Windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - 201ffaf37a80d188
Contenuto della cartella 'Scheduled Tasks'
2014-01-08 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-15 19:04:33 . 2013-12-11 18:37:21]
--------- X64 Entries -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-18 11:17:34 8067616]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2009-09-23 17:30:44 165912]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2009-09-23 17:30:44 385560]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2009-09-23 17:30:44 363544]
------- Scansione supplementare -------
uLocal Page = C:\Windows\system32\blank.htm
uStart Page = hxxp://www.google.it/
mStart Page = hxxp://nmd.msn.com
mLocal Page = C:\Windows\system32\blank.htm
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.2.0\ViProtocol.dll
- - - - CHIAVI ORFANE RIMOSSE - - - -
Toolbar-Locked - (no file)
Toolbar-{9E131A93-EED7-4BEB-B015-A0ADB30B5646} - (no file)
Wow6432Node-HKLM-Explorer_Run-3744 - C:\PROGRA~3\LOCALS~1\Temp\mshrswr.bat
Toolbar-Locked - (no file)
AddRemove-UnityWebPlayer - C:\Users\Utente\AppData\Local\Unity\WebPlayer\Uninstall.exe
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\201ffaf37a80d188]
"ImagePath"="\SystemRoot\System32\Drivers\201ffaf37a80d188.sys"
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-3393571389-480633730-1725549892-1000\Software\Microsoft\Internet Explorer\Approved Extensions]
@DACL=(02 0000)
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,3b,1b,71,2c,94,
62,f1,66,4a,01,a8,fa,40,fc,19,73,e6,64
"{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}"=hex:51,66,7a,6c,4c,1d,3b,1b,ff,33,22,
21,ab,9d,e7,09,b0,e8,98,4e,9e,2d,f3,a0
"{4D2D3B0F-69BE-477A-90F5-FDDB05357975}"=hex:51,66,7a,6c,4c,1d,3b,1b,1f,26,3c,
5d,8a,3f,12,0b,8f,f6,b6,9b,01,7e,3c,6f
"{9E131A93-EED7-4BEB-B015-A0ADB30B5646}"=hex:51,66,7a,6c,4c,1d,3b,1b,83,07,02,
8e,e3,b8,83,07,af,16,eb,ed,b7,40,13,5c
"{000F18F2-09EB-4A59-82B2-5AE4184C39C3}"=hex:51,66,7a,6c,4c,1d,3b,1b,e2,05,1e,
10,df,5f,31,06,9d,b1,11,a4,1c,07,7c,d9
"{1FAFD711-ABF9-4F6A-8130-5166C7371427}"=hex:51,66,7a,6c,4c,1d,3b,1b,01,ca,be,
0f,cd,fd,02,03,9e,33,1a,26,c3,7c,51,3d
"{112BA211-334C-4A90-90EC-2AD1CDAB287C}"=hex:51,66,7a,6c,4c,1d,3b,1b,01,bf,3a,
01,78,65,f8,06,8f,ef,61,91,c9,e0,6d,66
[HKEY_USERS\S-1-5-21-3393571389-480633730-1725549892-1000_Classes\CLSID\{57A50FF4-D894-A049-85B7-1ED6854B694C}]
@Denied: (A 4) (Everyone)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@C:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="C:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Ora fine scansione: 2014-01-08 21:57:18
ComboFix-quarantined-files.txt 2014-01-08 20:57:18
Pre-Run: 87.858.012.160 byte disponibili
Post-Run: 87.621.619.712 byte disponibili
- - End Of File - - 135731F2CDEF95A70B648ACF56CC2AF0
A36C5E4F47E84449FF07ED3517B43A31
Eseguito da: C:\Users\Utente\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
* Resident AV is active
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\@
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\L\00000004.@
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\L\76603ac3
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\U\00000004.@
C:\Program Files (x86)\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\9519~1\A535~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\U\00000008.@
C:\Program Files (x86)\WinRAR\Leggimi.Txt
C:\Program Files (x86)\WinRAR\Leggimi_1a.Txt
C:\Program Files (x86)\WinRAR\Licenza.Txt
C:\Program Files (x86)\WinRAR\NoteTecniche.Txt
C:\Program Files (x86)\WinRAR\Ordin.htm
C:\Program Files (x86)\WinRAR\Ordina.htm
C:\Program Files (x86)\WinRAR\SorgUnRAR.Txt
C:\ProgramData\Local Settings\Temp
C:\Users\Utente\AppData\Local\cygwin1.dll
C:\Users\Utente\AppData\Local\Google\Desktop\Install
C:\Users\Utente\AppData\Local\Google\Desktop\Install\{8be8d218-b518-3efe-d751-86471f1c36fa}\2E2F~1\28F0~1\E628~1\{8be8d218-b518-3efe-d751-86471f1c36fa}\@
C:\Users\Utente\AppData\Local\wuauclt.exe
C:\Users\Utente\AppData\Roaming\7go.ico
((((((((((((((((((((((((( Files Creati Da 2013-12-08 al 2014-01-08 )))))))))))))))))))))))))))))))))))
2014-01-08 20:54:48 . 2014-01-08 20:54:48 -------- d-----w- C:\Users\Default\AppData\Local\temp
2014-01-07 21:09:05 . 2014-01-07 21:09:05 422216 ----a-w- C:\Windows\system32\drivers\xinwaihy.sys
2014-01-07 21:09:04 . 2014-01-07 21:09:04 -------- d-----w- C:\ProgramData\AVAST Software
2013-12-30 20:38:46 . 2013-12-30 20:38:47 -------- d-----w- C:\Windows\7zS6637.tmp
2013-12-30 19:34:47 . 2013-12-30 19:34:47 422216 ----a-w- C:\Windows\system32\drivers\fefnpaue.sys
2013-12-30 18:32:51 . 2013-12-30 18:32:51 422216 ----a-w- C:\Windows\system32\drivers\llrowzja.sys
2013-12-30 17:54:53 . 2013-12-30 17:54:53 -------- d-----w- C:\Program Files (x86)\AVG Secure Search
2013-12-30 17:21:29 . 2013-12-30 17:21:29 422216 ----a-w- C:\Windows\system32\drivers\mwxpjilt.sys
2013-12-30 14:47:50 . 2013-12-30 14:47:50 422216 ----a-w- C:\Windows\system32\drivers\zhfvymlc.sys
2013-12-30 14:42:54 . 2013-12-30 14:42:54 422216 ----a-w- C:\Windows\system32\drivers\mbufbarj.sys
2013-12-30 14:38:24 . 2013-12-30 14:38:24 422216 ----a-w- C:\Windows\system32\drivers\avwqopgy.sys
2013-12-30 14:37:25 . 2013-12-30 14:37:25 422216 ----a-w- C:\Windows\system32\drivers\coykfbcl.sys
2013-12-30 12:51:13 . 2013-12-30 12:51:13 79824 ----a-w- C:\Windows\system32\drivers\201ffaf37a80d188.sys
2013-12-30 12:50:15 . 2014-01-08 20:54:27 -------- d-----w- C:\ProgramData\Local Settings
2013-12-19 09:14:12 . 2013-12-30 12:59:01 -------- d-----w- C:\Users\Utente\AppData\Roaming\VSStore
2013-12-14 12:56:48 . 2013-12-14 12:56:49 -------- d-----w- C:\Users\Utente\.android
2013-12-14 12:56:45 . 2013-12-14 12:56:45 -------- d-----w- C:\Users\Utente\AppData\Local\cache
2013-12-14 12:56:44 . 2013-12-14 12:56:44 -------- d-----w- C:\Users\Utente\AppData\Local\genienext
2013-12-14 12:56:43 . 2013-12-14 12:57:46 -------- d-----w- C:\Users\Utente\AppData\Local\Mobogenie
2013-12-14 12:56:26 . 2013-12-14 12:57:46 -------- d-----w- C:\Program Files (x86)\Mobogenie
2013-12-14 12:55:42 . 2013-12-30 12:59:02 -------- d-----w- C:\Users\Utente\AppData\Roaming\Iminent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
2013-12-11 18:37:21 . 2013-03-07 18:45:59 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-12-11 18:37:21 . 2012-01-11 15:56:29 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-04 16:35:46 . 2013-10-27 18:26:42 48648 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2013-11-04 16:35:42 . 2013-11-04 16:35:42 375632 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2013-10-27 18:26:38 . 2013-10-27 18:26:38 375632 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
[-] 2009-07-14 01:52:21 . !HASH: COULD NOT OPEN FILE !!!!! . 24128 . . [------] .. C:\Windows\system32\drivers\atapi.sys
[-] 2009-07-14 00:10:13 . !HASH: COULD NOT OPEN FILE !!!!! . 23040 . . [------] .. C:\Windows\system32\drivers\asyncmac.sys
[-] 2009-07-14 01:48:04 . !HASH: COULD NOT OPEN FILE !!!!! . 50768 . . [------] .. C:\Windows\system32\drivers\kbdclass.sys
[-] 2012-08-22 18:12:40 . !HASH: COULD NOT OPEN FILE !!!!! . 950128 . . [------] .. C:\Windows\system32\drivers\ndis.sys
[-] 2011-08-22 08:11:13 . !HASH: COULD NOT OPEN FILE !!!!! . 1659776 . . [------] .. C:\Windows\system32\drivers\ntfs.sys
[-] 2009-07-13 23:19:38 . !HASH: COULD NOT OPEN FILE !!!!! . 6144 . . [------] .. C:\Windows\system32\drivers\null.sys
[-] 2012-08-22 18:12:50 . !HASH: COULD NOT OPEN FILE !!!!! . 1913200 . . [------] .. C:\Windows\system32\drivers\tcpip.sys
[-] 2010-11-21 03:24:32 . !HASH: COULD NOT OPEN FILE !!!!! . 119296 . . [------] .. C:\Windows\system32\drivers\tdx.sys
[7] 2012-05-04 10:03:53 . A37A39568C8EC9A17D1B7471445B81A8 . 3916656 . . [6.1.7601.21987 (win7sp1_ldr.120503-2030)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21987_none_6e78bf732bb8d24e\ntoskrnl.exe
[7] 2012-05-04 10:03:50 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835 (win7sp1_gdr.120503-2030)] .. C:\Windows\erdnt\cache86\ntoskrnl.exe
[7] 2012-05-04 10:03:50 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835 (win7sp1_gdr.120503-2030)] .. C:\Windows\SysWOW64\ntoskrnl.exe
[7] 2012-05-04 10:03:50 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835 (win7sp1_gdr.120503-2030)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17835_none_6e2331b012747421\ntoskrnl.exe
[7] 2012-03-31 04:39:37 . 28F44480E411C3DDF04B63F6560E6EF4 . 3913072 . . [6.1.7601.17803 (win7sp1_gdr.120330-1504)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17803_none_6e41a0e0125deda0\ntoskrnl.exe
[7] 2012-03-31 04:37:33 . 2E02A17E8965AD671E4987E503AD38B1 . 3916656 . . [6.1.7601.21955 (win7sp1_ldr.120330-1503)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21955_none_6e972ea32ba24bcd\ntoskrnl.exe
[7] 2012-03-06 05:59:41 . 53B4BDEA12A032EEC71E60B6BFF42F37 . 3913072 . . [6.1.7601.17790 (win7sp1_gdr.120305-1505)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17790_none_6ddd4ed012a99fed\ntoskrnl.exe
[7] 2012-03-06 05:41:34 . 57B7DE30C4E65AD19CA13AC3065EE60B . 3916656 . . [6.1.7601.21936 (win7sp1_ldr.120305-1505)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21936_none_6eadcec52b912d42\ntoskrnl.exe
[7] 2011-08-23 12:05:04 . FB58ABD5E1F75A2CF713C9DFF0EC0804 . 3912576 . . [6.1.7601.17640 (win7sp1_gdr.110622-1506)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17640_none_6e135c8612811711\ntoskrnl.exe
[7] 2011-08-23 12:05:04 . 90EFDB506F6140EEA9DEE398D9449D86 . 3912576 . . [6.1.7601.21755 (win7sp1_ldr.110622-1503)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21755_none_6e972ad72ba2517f\ntoskrnl.exe
[7] 2011-08-22 08:15:23 . 5D21C487F79F8245E799071589E035BF . 3912576 . . [6.1.7601.17592 (win7sp1_gdr.110408-1631)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17592_none_6ddf4b9812a7d84d\ntoskrnl.exe
[7] 2011-08-22 08:15:23 . D385343510B75545EC5DB3A64C2D2492 . 3912576 . . [6.1.7601.21701 (win7sp1_ldr.110408-1634)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21701_none_6ec9394b2b7d606e\ntoskrnl.exe
[7] 2010-11-21 03:23:51 . 2088D9994332583EDB3C561DE31EA5AD . 3911040 . . [6.1.7601.17514 (win7sp1_rtm.101119-1850)] .. C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73\ntoskrnl.exe
[-] 2012-05-04 11:06:22 . !HASH: COULD NOT OPEN FILE !!!!! . 5559664 . . [------] .. C:\Windows\system32\ntoskrnl.exe
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-12-30 17:54:47 3333144 ----a-w- C:\Program Files (x86)\AVG Secure Search\17.2.0.38\AVG Secure Search_toolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "C:\Program Files (x86)\AVG Secure Search\17.2.0.38\AVG Secure Search_toolbar.dll" [2013-12-30 17:54:47 3333144]
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 16:36:46 30040]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 12:02:04 254696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
R1 Avgdiska;AVG Disk Driver;C:\Windows\system32\DRIVERS\avgdiska.sys;C:\Windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys;C:\Windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [x]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R2 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe;C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe [x]
R2 vToolbarUpdater17.2.0;vToolbarUpdater17.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [x]
R3 A38CCID;CCID USB Smart Card Reader;C:\Windows\system32\DRIVERS\a38ccid.sys;C:\Windows\SYSNATIVE\DRIVERS\a38ccid.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\system32\DRIVERS\ssudbus.sys;C:\Windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 LVUVC64;Logitech Webcam 120(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys;C:\Windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;C:\Windows\system32\drivers\TsUsbGD.sys;C:\Windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\system32\drivers\viahduaa.sys;C:\Windows\SYSNATIVE\drivers\viahduaa.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;C:\Windows\system32\Wat\WatAdminSvc.exe;C:\Windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys;C:\Windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;C:\Windows\system32\DRIVERS\avgloga.sys;C:\Windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys;C:\Windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys;C:\Windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 avgtp;avgtp;C:\Windows\system32\drivers\avgtpx64.sys;C:\Windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys;C:\Windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - 201ffaf37a80d188
Contenuto della cartella 'Scheduled Tasks'
2014-01-08 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-15 19:04:33 . 2013-12-11 18:37:21]
--------- X64 Entries -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-18 11:17:34 8067616]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2009-09-23 17:30:44 165912]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2009-09-23 17:30:44 385560]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2009-09-23 17:30:44 363544]
------- Scansione supplementare -------
uLocal Page = C:\Windows\system32\blank.htm
uStart Page = hxxp://www.google.it/
mStart Page = hxxp://nmd.msn.com
mLocal Page = C:\Windows\system32\blank.htm
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.2.0\ViProtocol.dll
- - - - CHIAVI ORFANE RIMOSSE - - - -
Toolbar-Locked - (no file)
Toolbar-{9E131A93-EED7-4BEB-B015-A0ADB30B5646} - (no file)
Wow6432Node-HKLM-Explorer_Run-3744 - C:\PROGRA~3\LOCALS~1\Temp\mshrswr.bat
Toolbar-Locked - (no file)
AddRemove-UnityWebPlayer - C:\Users\Utente\AppData\Local\Unity\WebPlayer\Uninstall.exe
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\201ffaf37a80d188]
"ImagePath"="\SystemRoot\System32\Drivers\201ffaf37a80d188.sys"
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-3393571389-480633730-1725549892-1000\Software\Microsoft\Internet Explorer\Approved Extensions]
@DACL=(02 0000)
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,3b,1b,71,2c,94,
62,f1,66,4a,01,a8,fa,40,fc,19,73,e6,64
"{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}"=hex:51,66,7a,6c,4c,1d,3b,1b,ff,33,22,
21,ab,9d,e7,09,b0,e8,98,4e,9e,2d,f3,a0
"{4D2D3B0F-69BE-477A-90F5-FDDB05357975}"=hex:51,66,7a,6c,4c,1d,3b,1b,1f,26,3c,
5d,8a,3f,12,0b,8f,f6,b6,9b,01,7e,3c,6f
"{9E131A93-EED7-4BEB-B015-A0ADB30B5646}"=hex:51,66,7a,6c,4c,1d,3b,1b,83,07,02,
8e,e3,b8,83,07,af,16,eb,ed,b7,40,13,5c
"{000F18F2-09EB-4A59-82B2-5AE4184C39C3}"=hex:51,66,7a,6c,4c,1d,3b,1b,e2,05,1e,
10,df,5f,31,06,9d,b1,11,a4,1c,07,7c,d9
"{1FAFD711-ABF9-4F6A-8130-5166C7371427}"=hex:51,66,7a,6c,4c,1d,3b,1b,01,ca,be,
0f,cd,fd,02,03,9e,33,1a,26,c3,7c,51,3d
"{112BA211-334C-4A90-90EC-2AD1CDAB287C}"=hex:51,66,7a,6c,4c,1d,3b,1b,01,bf,3a,
01,78,65,f8,06,8f,ef,61,91,c9,e0,6d,66
[HKEY_USERS\S-1-5-21-3393571389-480633730-1725549892-1000_Classes\CLSID\{57A50FF4-D894-A049-85B7-1ED6854B694C}]
@Denied: (A 4) (Everyone)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@C:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="C:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="C:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Ora fine scansione: 2014-01-08 21:57:18
ComboFix-quarantined-files.txt 2014-01-08 20:57:18
Pre-Run: 87.858.012.160 byte disponibili
Post-Run: 87.621.619.712 byte disponibili
- - End Of File - - 135731F2CDEF95A70B648ACF56CC2AF0
A36C5E4F47E84449FF07ED3517B43A31