ComboFix 12-03-03.02 - Mark 04/03/2012 12.41.46.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1983.1360 [GMT 1:00]
Eseguito da: c:\documents and settings\Mark\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\Mark\Dati applicazioni\OfferBox
c:\documents and settings\Mark\Dati applicazioni\OfferBox\config.dat
c:\documents and settings\Mark\Dati applicazioni\OfferBox\config.xml
c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\wfpfp.dat
c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\wfpfp_nav.dat
c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\wfpfp_navps.dat
c:\programmi\Internet Explorer\SETAB7.tmp
c:\programmi\Internet Explorer\SETAB8.tmp
c:\programmi\OfferBox
c:\programmi\OfferBox\OfferBoxBHO.dll
c:\programmi\Windows Searchqu Toolbar
c:\windows\_000009_.tmp.dll
c:\windows\_000016_.tmp.dll
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\_000011_.tmp.dll
c:\windows\system32\_000012_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\_000014_.tmp.dll
c:\windows\system32\_000015_.tmp.dll
c:\windows\system32\_000016_.tmp.dll
c:\windows\system32\_000017_.tmp.dll
c:\windows\system32\_000018_.tmp.dll
c:\windows\system32\_000019_.tmp.dll
c:\windows\system32\_000020_.tmp.dll
c:\windows\system32\_000021_.tmp.dll
c:\windows\system32\_000022_.tmp.dll
c:\windows\system32\PowerToyReadme.htm
c:\windows\system32\SET1185.tmp
c:\windows\system32\SET118A.tmp
c:\windows\system32\SET1192.tmp
c:\windows\system32\SET1193.tmp
c:\windows\system32\SET1194.tmp
c:\windows\system32\SET1199.tmp
c:\windows\system32\SET1BC.tmp
c:\windows\system32\SET1C5.tmp
c:\windows\system32\SET1CC.tmp
c:\windows\system32\SET1D2.tmp
c:\windows\system32\SET229.tmp
c:\windows\system32\SET2A6.tmp
c:\windows\system32\SET2A7.tmp
c:\windows\system32\SET2C8.tmp
c:\windows\system32\SET359.tmp
c:\windows\system32\SET3CD.tmp
c:\windows\system32\SET3CE.tmp
c:\windows\system32\SET3CF.tmp
c:\windows\system32\SET5F0.tmp
c:\windows\system32\SET5FD.tmp
c:\windows\system32\SET69D.tmp
c:\windows\system32\SET69E.tmp
c:\windows\system32\SET6A4.tmp
c:\windows\system32\SET6AD.tmp
c:\windows\system32\SET710.tmp
c:\windows\system32\SET718.tmp
c:\windows\system32\SET748.tmp
c:\windows\system32\SET77B.tmp
c:\windows\system32\SET77F.tmp
c:\windows\system32\SET8EB.tmp
c:\windows\system32\SET95.tmp
c:\windows\system32\SET96.tmp
c:\windows\system32\SET97.tmp
c:\windows\system32\SETAA6.tmp
c:\windows\system32\SETAA7.tmp
c:\windows\system32\SETAA8.tmp
c:\windows\system32\SETAAC.tmp
c:\windows\system32\SETAAD.tmp
c:\windows\system32\SETAAE.tmp
c:\windows\system32\SETAB2.tmp
c:\windows\system32\SETAB3.tmp
c:\windows\system32\SETAB4.tmp
c:\windows\system32\SETB51.tmp
c:\windows\system32\SETB97.tmp
c:\windows\system32\SETB9C.tmp
c:\windows\system32\SETB9D.tmp
c:\windows\system32\SETB9F.tmp
c:\windows\system32\SETBC2.tmp
c:\windows\system32\SETCD7.tmp
c:\windows\system32\SETCE0.tmp
c:\windows\system32\SETCE1.tmp
c:\windows\system32\SETCEB.tmp
c:\windows\system32\SETCFD.tmp
c:\windows\system32\SETD05.tmp
c:\windows\system32\SETD06.tmp
c:\windows\system32\SETEFA.tmp
c:\windows\system32\SETF07.tmp
c:\windows\system32\SETF13.tmp
c:\windows\system32\SETF48.tmp
c:\windows\system32\SETF49.tmp
c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.exe
D:\install.exe
.
.
((((((((((((((((((((((((( Files Creati Da 2012-02-04 al 2012-03-04 )))))))))))))))))))))))))))))))))))
.
.
2012-03-04 09:18 . 2010-05-07 10:37 109240 ----a-w- c:\programmi\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
2012-03-03 09:34 . 2012-03-04 09:00 -------- d-----w- c:\programmi\Spybot - Search & Destroy
2012-03-03 09:34 . 2012-03-03 11:44 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2012-02-19 09:41 . 2012-02-19 09:42 -------- d-----w- c:\programmi\Nemo PDF To Word
2012-02-15 20:01 . 2012-02-15 20:01 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys
2012-02-15 20:01 . 2005-12-23 16:36 469216 ----a-w- c:\windows\system32\drivers\USRPCI.sys
2012-02-15 20:00 . 2012-02-15 20:00 1409 ----a-w- c:\windows\system32\tmp7630B.FOT
2012-02-15 20:00 . 2012-02-15 20:00 1409 ----a-w- c:\windows\system32\tmp3140B.FOT
2012-02-15 20:00 . 2012-02-15 20:00 1409 ----a-w- c:\windows\system32\tmp1740B.FOT
2012-02-06 11:13 . 2012-02-06 11:13 -------- d-----w- C:\s5ls
2012-02-06 11:12 . 2012-02-06 11:12 -------- d-----w- c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\libimobiledevice
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-20 09:39 . 2011-05-23 09:43 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-30 16:03 . 2011-11-27 11:53 21336 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2011-04-14 16:53 . 2011-06-05 11:11 142296 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\programmi\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-29 620376]
"Akamai NetSession Interface"="c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\Akamai\netsession_win.exe" [2012-02-02 3329824]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-05-07 344736]
"PosService"="c:\documents and settings\All Users\Documenti\AppData\PoApp\PLauncher.exe" [2011-12-03 218624]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
.
c:\documents and settings\Mark\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
USRobotics Wireless PCI Adapter.lnk - c:\programmi\USRobotics\Wireless PCI Manager\USR54G.exe [2006-4-14 667648]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Air Mouse.lnk]
backup=c:\windows\pss\Air Mouse.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mark^Menu Avvio^Programmi^Esecuzione automatica^Ritaglio schermata e avvio di OneNote 2007.lnk]
backup=c:\windows\pss\Ritaglio schermata e avvio di OneNote 2007.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 00:04 39792 ----a-w- c:\programmi\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 ----a-w- c:\programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
2012-02-02 01:44 3329824 ----a-w- c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\Akamai\netsession_win.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AliceRE_McciTrayApp]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-04-20 10:48 58656 ----a-w- c:\programmi\File comuni\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-11-01 22:25 59240 ----a-w- c:\programmi\File comuni\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GM4IE]
2006-07-23 08:32 61440 ----a-w- c:\programmi\SocialPlus\gm4ie.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-06-06 18:16 136176 ----atw- c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-12-08 00:36 421736 ----a-w- c:\programmi\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
2006-04-21 13:41 438359 ------w- c:\progra~1\ALICET~1\SMARTB~1\MotiveSB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 17:14 1695232 ------w- c:\programmi\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PosService]
2011-12-03 10:04 218624 ----a-w- c:\documents and settings\All Users\Documenti\AppData\PoApp\PLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 16:36 421888 ----a-w- c:\programmi\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 09:47 79192 ----a-w- c:\programmi\File comuni\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-08-26 11:35 39408 ----a-w- c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Nero BackItUp Scheduler 4.0"=2 (0x2)
"iPod Service"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"Bonjour Service"=2 (0x2)
"BBUpdate"=2 (0x2)
"BBSvc"=2 (0x2)
"AdvancedSystemCareService5"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Italian\\setup.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\eMule\\LinkCreator.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R?2 ServUpdater;Serv Updater;c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\ServUpdater\ServiceUpd.exe [27/11/2011 16.15.59 156160]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 17.29.38 36880]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [13/04/2008 18.14.22 14336]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [22/08/2009 12.27.16 8192]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 13.42.46 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/10/2009 18.39.44 19472]
R3 wlanndi5;wlanndi5 NDIS Protocol Driver;c:\windows\system32\wlanndi5.sys [21/04/2004 16.51.00 16384]
S1 kl2;Kl2;c:\windows\system32\drivers\kl2.sys [06/05/2010 23.19.06 132184]
S2 PowerOffer Service;Pos Service;c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\PosService\Pos.exe [27/11/2011 16.15.46 164864]
S3 CA500AI;GSmart Mini Still Image Capture;c:\windows\system32\drivers\BULK2NM.sys [19/03/2009 14.57.25 11117]
S3 CA500AV;GSmart Mini WDM Video Capture;c:\windows\system32\drivers\ca500av.SYS [19/03/2009 14.56.27 492619]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys

c:\windows\system32\drivers\nmwcdnsu.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys

c:\windows\system32\drivers\nmwcdnsuc.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 USRPCI;USRobotics Wireless PCI Adapter Service;c:\windows\system32\drivers\USRPCI.sys [15/02/2012 21.01.02 469216]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [13/04/2008 18.14.22 14336]
S4 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\programmi\IObit\Advanced SystemCare 5\ASCService.exe [27/11/2011 12.07.38 497496]
S4 BBSvc;Bing Bar Update Service;c:\programmi\Microsoft\BingBar\BBSvc.EXE [21/10/2011 15.23.42 196176]
S4 BBUpdate;BBUpdate;c:\programmi\Microsoft\BingBar\SeaPort.EXE [13/10/2011 17.21.52 249648]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
WINRM REG_MULTI_SZ WINRM
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-12-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:57]
.
2012-02-29 c:\windows\Tasks\ASC5_AutoUpdate.job
- c:\programmi\IObit\Advanced SystemCare 5\AutoUpdate.exe [2011-11-27 17:19]
.
2012-03-04 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-26 10:01]
.
2012-03-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-2025429265-1417001333-1004Core.job
- c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2011-07-04 18:16]
.
2012-03-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-2025429265-1417001333-1004UA.job
- c:\documents and settings\Mark\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2011-07-04 18:16]
.
2012-03-04 c:\windows\Tasks\User_Feed_Synchronization-{AE1684AE-7354-40AF-9642-0C6FDD22AFD1}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.igoogle.it/uInternet Settings,ProxyOverride = 127.0.0.1;*.local;127.0.0.1:9421
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Mark\Dati applicazioni\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: Interfaces\{936DD211-FA99-4B79-A849-16C6A91AD49B}: NameServer = 176.31.229.24,176.31.229.25
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Mark\Dati applicazioni\Mozilla\Firefox\Profiles\6gggeeg7.default\
FF - prefs.js: keyword.URL -
hxxp://www.searchqu.com/web?src=ffb&app ... 10&sr=0&q=FF - prefs.js: network.proxy.type - 0
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Toolbar-10 - (no file)
AddRemove-Artistic Effects by Lokas Software - c:\windows\AWuninstall.exe Software\Lokas Ltd\Artistic Effects
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-03-04 13:03
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="c:\programmi\file comuni\akamai/netsession_win_7de0ed9.dll"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-1214440339-2025429265-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B5920541-4255-F6FC-5EA7-34FDB5C823CF}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iacenagniaiejfebmi"=hex:6b,61,61,68,61,63,68,65,6a,6d,6d,6b,70,66,6a,67,67,65,
67,70,66,70,00,00
"hamdpbnnlpcfcpfb"=hex:6b,61,70,67,69,63,70,6d,6b,62,63,64,69,6d,62,63,62,66,
69,6e,63,6f,00,7e
"gadeefjbgaijjh"=hex:61,63,64,67,69,64,65,62,6f,67,65,61,6a,67,69,6c,6a,70,68,
6d,61,6e,67,62,6e,6a,69,67,6d,6f,69,61,66,65,67,66,67,63,6d,67,68,61,6e,6e,\
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(760)
c:\programmi\File comuni\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'explorer.exe'(3156)
c:\windows\system32\WININET.dll
c:\programmi\iTunes\iTunesMiniPlayer.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\it.lproj\iTunesMiniPlayerLocalized.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\acs.exe
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2012-03-04 13:07:00 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-03-04 12:06
.
Pre-Run: 39.263.191.040 byte disponibili
Post-Run: 39.541.997.568 byte disponibili
.
- - End Of File - - E7354A2A1BC44CAE24921DE87CF23C3B