ComboFix 10-05-20.A1 - Klod 21/05/2010 15.14.54.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.1919.1016 [GMT 2:00]
Eseguito da: c:\users\Klod\Desktop\ComboFix.exe
SP: Avira AntiVir PersonalEdition *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((( Files Creati Da 2010-04-21 al 2010-05-21 )))))))))))))))))))))))))))))))))))
.
2010-05-21 13:28 . 2010-05-21 13:29 -------- d-----w- c:\users\Klod\AppData\Local\temp
2010-05-21 13:28 . 2010-05-21 13:28 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-05-21 13:28 . 2010-05-21 13:28 -------- d-----w- c:\users\Ospiti\AppData\Local\temp
2010-05-21 13:28 . 2010-05-21 13:28 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-05-21 13:28 . 2010-05-21 13:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-21 08:39 . 2010-05-21 08:40 284915 ----a-w- c:\users\Klod\gmer.zip
2010-05-21 08:36 . 2010-05-21 08:36 277 ----a-w- c:\programdata\SecTaskMan\icn_3D8CB5F014732454FA001502A2F93D75.dll
2010-05-20 13:55 . 2010-05-21 13:11 -------- d-----w- C:\VEXPLite
2010-05-20 13:55 . 2010-05-21 13:09 -------- dc-h--w- c:\users\Klod\AppData\Local\~0
2010-05-17 12:23 . 2010-05-17 12:23 -------- d-----w- c:\users\Klod\AppData\Roaming\dvdcss
2010-05-15 17:05 . 2010-05-17 12:08 -------- d-----w- c:\programdata\PrevxCSI
2010-05-15 13:56 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\10526002.sys
2010-05-15 13:56 . 2009-10-09 21:31 311312 ----a-w- c:\windows\system32\drivers\1052600.sys
2010-05-15 13:56 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\10526001.sys
2010-05-13 15:34 . 2010-05-13 15:34 -------- d-----w- c:\users\Klod\AppData\Roaming\Avira
2010-05-13 14:55 . 2010-05-13 14:53 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-05-13 14:55 . 2010-05-13 14:53 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-05-13 14:55 . 2010-05-13 14:53 97608 ----a-w- c:\windows\system32\drivers\avfwot.sys
2010-05-13 14:55 . 2010-05-13 14:53 69632 ----a-w- c:\windows\system32\drivers\avfwim.sys
2010-05-13 14:55 . 2010-05-13 14:55 -------- d-----w- c:\programdata\Avira
2010-05-13 14:55 . 2010-05-13 14:55 -------- d-----w- c:\program files\Avira
2010-05-12 14:52 . 2010-05-19 13:59 -------- d-----w- c:\program files\VS Revo Group
2010-05-12 14:33 . 2010-05-12 14:33 -------- d-----w- c:\users\Klod\AppData\Local\VS Revo Group
2010-05-12 11:16 . 2010-05-12 14:48 -------- d-----w- c:\program files\Yahoo!
2010-05-12 04:34 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-11 18:36 . 2010-05-11 18:36 -------- d-----w- c:\users\Ospiti\AppData\Local\Adobe
2010-05-11 15:42 . 2010-05-14 15:04 61440 ----a-w- c:\windows\system32\PxSecure.dll
2010-05-07 12:40 . 2010-05-07 12:40 -------- d-----w- c:\users\Klod\AppData\Local\JollyBear
2010-05-07 12:40 . 2010-05-07 12:40 -------- d-----w- c:\programdata\JollyBear
2010-05-07 12:39 . 2010-05-07 12:40 -------- d-----w- c:\users\Klod\AppData\Roaming\Zylom
2010-05-07 12:39 . 2009-10-26 13:45 102400 ----a-w- c:\users\Klod\AppData\Roaming\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2010-05-07 12:39 . 2006-09-26 10:03 161976 ----a-w- c:\users\Klod\AppData\Roaming\Zylom\ZylomGamesPlayer\zylomgamesplayer.dll
2010-05-07 12:39 . 2010-05-07 13:47 -------- d-----w- c:\users\Klod\AppData\Local\Zylom Games
2010-05-06 16:24 . 2010-05-06 16:24 -------- d-----w- c:\users\Klod\AppData\Local\Shareaza
2010-05-04 18:30 . 2010-05-04 18:30 -------- d-----w- c:\users\Ospiti\AppData\Local\ArcSoft
2010-04-30 01:30 . 2010-04-30 01:30 -------- d-----w- c:\program files\Windows Portable Devices
2010-04-30 01:10 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2010-04-30 01:10 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-04-30 01:09 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2010-04-30 01:08 . 2009-09-25 01:33 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2010-04-30 01:08 . 2009-09-24 22:54 258048 ----a-w- c:\windows\system32\winspool.drv
2010-04-30 01:08 . 2009-09-25 01:27 37888 ----a-w- c:\windows\system32\cdd.dll
2010-04-30 01:08 . 2009-09-25 01:27 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-04-30 01:06 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-04-30 01:06 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2010-04-30 01:06 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2010-04-30 01:06 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2010-04-30 01:05 . 2009-10-01 01:01 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2010-04-30 01:05 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2010-04-30 01:05 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2010-04-30 01:05 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2010-04-30 01:05 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2010-04-30 01:05 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2010-04-30 01:05 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2010-04-30 01:05 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2010-04-30 01:05 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2010-04-30 01:02 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-04-30 01:02 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-04-30 01:02 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-04-30 00:28 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-04-30 00:27 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-04-30 00:27 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-04-29 20:31 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\73996562.sys
2010-04-29 20:31 . 2009-10-09 21:31 311312 ----a-w- c:\windows\system32\drivers\7399656.sys
2010-04-29 20:31 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\73996561.sys
2010-04-29 19:25 . 2010-04-29 19:27 -------- d-----w- c:\windows\system32\ca-ES
2010-04-29 19:25 . 2010-04-29 19:26 -------- d-----w- c:\windows\system32\eu-ES
2010-04-29 19:25 . 2010-04-29 19:26 -------- d-----w- c:\windows\system32\vi-VN
2010-04-29 19:15 . 2010-04-29 19:15 -------- d-----w- c:\windows\system32\SPReview
2010-04-29 18:35 . 2009-04-10 21:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2010-04-29 18:34 . 2009-04-10 21:27 57856 ----a-w- c:\windows\system32\compcln.exe
2010-04-29 18:01 . 2009-04-10 21:28 483328 ----a-w- c:\windows\system32\samsrv.dll
2010-04-29 17:59 . 2009-04-10 21:28 171008 ----a-w- c:\windows\system32\apphelp.dll
2010-04-29 17:58 . 2009-04-10 21:28 3174400 ----a-w- c:\windows\system32\netshell.dll
2010-04-29 17:57 . 2009-04-10 19:38 149504 ----a-w- c:\windows\system32\drivers\ks.sys
2010-04-29 17:56 . 2009-04-10 21:28 117248 ----a-w- c:\windows\system32\wbem\WMIADAP.exe
2010-04-29 17:55 . 2009-04-10 21:28 1576960 ----a-w- c:\windows\system32\tquery.dll
2010-04-29 17:55 . 2009-04-10 21:28 170496 ----a-w- c:\windows\system32\tcpipcfg.dll
2010-04-29 17:55 . 2009-04-10 21:28 135168 ----a-w- c:\windows\system32\tcpmon.dll
2010-04-29 17:55 . 2009-04-10 21:28 242688 ----a-w- c:\windows\system32\tapisrv.dll
2010-04-29 17:55 . 2009-04-10 21:28 270336 ----a-w- c:\windows\system32\taskcomp.dll
2010-04-29 17:55 . 2009-04-10 21:28 169984 ----a-w- c:\windows\system32\taskeng.exe
2010-04-29 17:55 . 2009-04-10 21:28 449024 ----a-w- c:\windows\system32\termsrv.dll
2010-04-29 17:55 . 2009-04-10 21:28 313344 ----a-w- c:\windows\system32\thawbrkr.dll
2010-04-29 17:55 . 2009-04-10 21:28 615424 ----a-w- c:\windows\system32\themeui.dll
2010-04-29 17:55 . 2009-04-10 21:28 1152000 ----a-w- c:\windows\system32\themecpl.dll
2010-04-29 17:55 . 2009-04-10 19:45 72192 ----a-w- c:\windows\system32\drivers\tdx.sys
2010-04-29 17:55 . 2009-04-10 21:32 53224 ----a-w- c:\windows\system32\drivers\termdd.sys
2010-04-29 13:35 . 2010-05-14 15:04 57248 ----a-w- c:\windows\system32\drivers\pxrts.sys
2010-04-29 13:35 . 2010-05-14 15:04 30320 ----a-w- c:\windows\system32\drivers\pxscan.sys
2010-04-29 13:35 . 2010-05-14 15:04 24400 ----a-w- c:\windows\system32\drivers\pxkbf.sys
2010-04-28 07:28 . 2010-05-04 17:28 -------- d-----w- c:\users\Klod\DoctorWeb
2010-04-27 14:42 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\14653202.sys
2010-04-27 14:42 . 2009-10-09 21:31 311312 ----a-w- c:\windows\system32\drivers\1465320.sys
2010-04-27 14:42 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\14653201.sys
2010-04-27 07:40 . 2010-05-15 13:57 -------- d-----w- c:\programdata\Kaspersky Lab
2010-04-23 13:32 . 2010-04-23 13:32 -------- d-----w- c:\users\Klod\AppData\Roaming\Malwarebytes
2010-04-23 13:32 . 2010-04-23 13:32 -------- d-----w- c:\programdata\Malwarebytes
2010-04-22 18:07 . 2010-04-22 18:07 -------- d-----w- c:\program files\Trend Micro
2010-04-22 15:49 . 2010-04-22 15:49 -------- d-----w- c:\users\Klod\AppData\Local\PackageAware
2010-04-22 13:05 . 2010-04-22 13:05 -------- d-----w- c:\windows\CheckSur
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-21 12:20 . 2007-09-11 14:23 12978 ----a-w- c:\users\Klod\AppData\Roaming\nvModes.dat
2010-05-21 08:37 . 2010-04-22 16:15 -------- d-----w- c:\programdata\SecTaskMan
2010-05-20 16:50 . 2010-05-20 16:50 906352 ----a-w- c:\windows\WINDOWSUPDATE.LOG.TMP
2010-05-20 16:50 . 2010-05-20 16:50 32524 ----a-w- c:\windows\Tasks\SCHEDLGU.TXT.TMP.TMP
2010-05-20 16:50 . 2010-04-25 07:36 32524 ----a-w- c:\windows\Tasks\SCHEDLGU.TXT.TMP
2010-05-20 16:50 . 2010-04-25 07:36 3168 ----a-w- c:\windows\system32\7B296FB0-376B-497E-B012-9C450E1B7327-2P-1.C7483456-A289-439D-8115-601632D005A0.TMP
2010-05-20 16:50 . 2010-04-25 07:36 3168 ----a-w- c:\windows\system32\7B296FB0-376B-497E-B012-9C450E1B7327-2P-0.C7483456-A289-439D-8115-601632D005A0.TMP
2010-05-20 09:23 . 2008-01-27 21:58 13072 ----a-w- c:\users\Ospiti\AppData\Roaming\nvModes.dat
2010-05-17 12:32 . 2007-09-11 15:46 -------- d-----w- c:\users\Klod\AppData\Roaming\vlc
2010-05-13 14:36 . 2010-04-08 12:43 -------- d-----w- c:\program files\F-Secure
2010-05-13 14:35 . 2010-04-08 12:44 -------- d-----w- c:\programdata\F-Secure
2010-05-12 14:28 . 2007-03-12 16:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-12 14:27 . 2008-12-26 10:33 -------- d-----w- c:\program files\QuickTime
2010-05-12 14:25 . 2009-09-29 13:20 -------- d-----w- c:\program files\Common Files\Nero
2010-05-12 14:24 . 2009-09-29 13:20 -------- d-----w- c:\programdata\Nero
2010-05-12 14:11 . 2007-03-12 16:30 -------- d-----w- c:\program files\HDReg
2010-05-12 12:33 . 2007-03-12 16:31 -------- d-----w- c:\program files\Google
2010-05-12 12:04 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-12 09:21 . 2009-10-03 13:03 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-11 09:08 . 2007-12-15 15:13 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-05-11 09:05 . 2009-04-18 10:03 -------- d-----w- c:\program files\Startup Inspector for Windows
2010-05-11 09:04 . 2007-03-12 16:30 -------- d-----w- c:\program files\Packard Bell
2010-05-11 08:20 . 2007-03-13 01:04 669974 ----a-w- c:\windows\system32\perfh010.dat
2010-05-11 08:20 . 2007-03-13 01:04 123570 ----a-w- c:\windows\system32\perfc010.dat
2010-05-04 18:30 . 2008-01-24 13:52 79008 ----a-w- c:\users\Ospiti\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-30 01:29 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-04-30 01:29 . 2010-04-30 01:29 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-04-30 01:28 . 2010-04-30 01:28 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-04-29 19:28 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-04-29 19:28 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-04-29 19:27 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-04-29 19:27 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-04-29 19:27 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-04-29 19:27 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-04-22 15:19 . 2007-09-11 12:57 79008 ----a-w- c:\users\Klod\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-21 14:32 . 2008-01-04 16:21 -------- d-----w- c:\program files\IncrediMail
2010-04-19 10:16 . 2010-04-19 10:16 12 ----a-w- c:\users\Klod\AppData\Roaming\kcmdte.dat
2010-04-13 08:55 . 2010-04-13 08:55 -------- d-----w- c:\users\Klod\AppData\Roaming\HPAppData
2010-04-08 20:46 . 2010-04-08 12:47 33920 ----a-w- c:\windows\system32\drivers\fsbts.sys
2010-04-08 12:44 . 2010-04-08 12:44 -------- d-----w- c:\programdata\fssg
2010-04-08 12:39 . 2007-11-06 18:22 -------- d-----w- c:\programdata\Lavasoft
2010-04-08 12:38 . 2009-04-06 13:35 -------- d-----w- c:\program files\Lavasoft
2010-04-08 11:15 . 2010-04-08 11:15 -------- d-----w- c:\users\Ospiti\AppData\Roaming\HPAppData
2010-03-24 13:35 . 2009-05-28 13:51 2485883 ----a-w- c:\programdata\ArcSoft\Global Deploy\CheckUpdate\ArcConnect.exe
2010-03-23 09:48 . 2010-03-23 09:45 23163 ----a-w- c:\windows\hpqins15.dat
2010-03-23 09:41 . 2009-01-11 08:59 -------- d-----w- c:\programdata\HP
2010-03-05 14:01 . 2010-04-14 10:28 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-01 14:26 . 2009-10-28 18:39 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-01 14:12 . 2009-10-01 12:35 801 ----a-w- c:\users\Klod\AppData\Roaming\Mp3 Editor for Free\mef.dll
2010-03-01 13:36 . 2010-03-01 13:37 509552 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbCD45.tmp.exe
2010-02-23 11:10 . 2010-04-14 10:28 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-23 11:10 . 2010-04-14 10:28 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-02-23 11:10 . 2010-04-14 10:28 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 06:39 . 2010-03-31 12:57 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 12:57 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33 . 2010-03-31 12:57 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55 . 2010-03-31 12:57 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-12 09:17 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-12 09:16 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-12 09:16 411648 ----a-w- c:\windows\system32\drivers\http.sys
2007-03-13 01:07 . 2007-03-13 01:07 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 815104]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-20 4018176]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-19 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-19 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-19 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"UacDisableNotify"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):28,bc,db,d6,d3,e7,ca,01
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [x]
R3 esihdrv;esihdrv;c:\users\Klod\AppData\Local\Temp\esihdrv.sys [x]
R3 NDISKIO;NDISKIO;c:\users\Klod\AppData\Local\Temp\00001681.nmc\nse\bin\ndiskio.sys [x]
S0 10526002;10526002 Boot Guard Driver;c:\windows\system32\DRIVERS\10526002.sys [2009-10-22 37392]
S0 14653202;14653202 Boot Guard Driver;c:\windows\system32\DRIVERS\14653202.sys [2009-10-22 37392]
S0 73996562;73996562 Boot Guard Driver;c:\windows\system32\DRIVERS\73996562.sys [2009-10-22 37392]
S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2010-05-14 30320]
S1 10526001;10526001;c:\windows\system32\DRIVERS\10526001.sys [2009-09-25 128016]
S1 14653201;14653201;c:\windows\system32\DRIVERS\14653201.sys [2009-09-25 128016]
S1 73996561;73996561;c:\windows\system32\DRIVERS\73996561.sys [2009-09-25 128016]
S1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys [2010-05-13 97608]
S1 setup_9.0.0.722_27.04.2010_17-19drv;setup_9.0.0.722_27.04.2010_17-19drv;c:\windows\system32\DRIVERS\1465320.sys [2009-10-09 311312]
S1 setup_9.0.0.722_29.04.2010_23-20drv;setup_9.0.0.722_29.04.2010_23-20drv;c:\windows\system32\DRIVERS\7399656.sys [2009-10-09 311312]
S2 AntiVirFirewallService;Avira Firewall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [2010-05-13 388865]
S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [2010-05-13 194817]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-05-13 108289]
S2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-05-13 434945]
S2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2010-05-14 57248]
S2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:\windows\System32\StkSrv.exe [2006-09-07 24576]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys [2010-05-13 69632]
S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2010-05-14 24400]
S3 StkCMini;Syntek AVStream USB2.0 VGA WebCam;c:\windows\system32\DRIVERS\StkCMini.sys [2006-11-10 669568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenuto della cartella 'Scheduled Tasks'
2010-05-21 c:\windows\Tasks\User_Feed_Synchronization-{AD3A756D-CAE6-441A-9B5A-77925B071565}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.it/IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: {3985110E-F263-40FD-820F-B86CB0E23E8E} = 208.67.222.222,208.67.220.220
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
AddRemove-{0F5BC8D3-3741-4542-AF00-51202A9FD357} - c:\users\Klod\AppData\Local\{968F9FBF-0523-4FFE-95F9-512F1E2811A3}\vnlt6639.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-21 15:29
Windows 6.0.6002 Service Pack 2 NTFS
scansione processi nascosti ...
[0] 0x00000005
scansione entrate autostart nascoste ...
Scansione files nascosti ...
c:\windows\TEMP\TMP0000007407E9FB7723392FF7 524288 bytes executable
Scansione completata con successo
Files nascosti: 1
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2010-05-21 15:38:07
ComboFix-quarantined-files.txt 2010-05-21 13:38
Pre-Run: 41.369.305.088 byte disponibili
Post-Run: 41.373.200.384 byte disponibili
- - End Of File - - 1ACCF38247A5857C8A1390E81C7554D0