Salve, da un pò di tempo che il mio computer si avvia lentamente, e vorrei sapere se è normale o la causa è qualche virus, vi metto i log thi hijackthis e di combofix:
GRAZIE PER L'AIUTO!ComboFix 10-04-07.04 - A 09/04/2010 15.58.03.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2815.2249 [GMT 2:00]
Eseguito da: i:\documents and settings\A\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000000-0000-0000-0000-000000000000}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Resident AV is active
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2010-03-09 al 2010-04-09 )))))))))))))))))))))))))))))))))))
.
Nessun nuovo file creato in questo arco di tempo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- i:\programmi\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- i:\programmi\mozilla firefox\plugins\ssldivx.dll
.
------- Sigcheck -------
[-] 2008-10-22 . E248A8391D7388A0A3679D1FB33E003D . 361600 . . [5.1.2600.5625] . . i:\windows\system32\drivers\tcpip.sys
[-] 2008-10-22 . E092AEB03D40F40854D4C3D90C9AFECC . 1571840 . . [5.1.2600.5512] . . i:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="i:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-22 16804864]
"GrooveMonitor"="i:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="i:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avgnt"="i:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="i:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="i:\programmi\QuickTime\qttask.exe" [2009-11-10 417792]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
"NvMediaCenter"="i:\windows\system32\NvMcTray.dll" [2010-01-11 110696]
"ZoneAlarm Client"="i:\programmi\Zone Labs\ZoneAlarm\zlclient.exe" [2009-12-04 1037192]
"ISW"="i:\programmi\CheckPoint\ZAForceField\ForceField.exe" [2009-10-27 730480]
"Malwarebytes' Anti-Malware"="i:\programmi\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-03-29 437584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="i:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
i:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Monitor Apache Servers.lnk - i:\programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe [2010-3-4 41051]
Windows Search.lnk - i:\programmi\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "i:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-10-22 06:35 57344 ----a-w- i:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 5600-6600 Series Fax Server]
2008-09-10 11:10 311976 ----a-w- i:\programmi\Lexmark 5600-6600 Series\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxduamon]
2008-09-10 11:11 16040 ----a-w- i:\programmi\Lexmark 5600-6600 Series\lxduamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdumon.exe]
2008-09-10 11:11 676520 ----a-w- i:\programmi\Lexmark 5600-6600 Series\lxdumon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2008-05-02 04:15 15872 ----a-w- i:\programmi\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"i:\\WINDOWS\\system32\\lxducoms.exe"=
"i:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"i:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"i:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"i:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"i:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"i:\\WINDOWS\\system32\\dpvsetup.exe"=
"i:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"i:\\Programmi\\uTorrent\\uTorrent.exe"=
"i:\\Programmi\\eMule\\emule.exe"=
"i:\\Programmi\\Skype\\Phone\\Skype.exe"=
"i:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:*:Disabled:vnc5900
"5800:TCP"= 5800:TCP:*:Disabled:vnc5800
R0 sptd;sptd;i:\windows\System32\Drivers\sptd.sys [2009-08-06 721904]
R2 lxduCATSCustConnectService;lxduCATSCustConnectService;i:\windows\System32\spool\DRIVERS\W32X86\3\\lxduserv.exe [2008-05-23 98984]
R3 epmntdrv;epmntdrv;i:\windows\system32\epmntdrv.sys [2009-04-22 8704]
R3 EuGdiDrv;EuGdiDrv;i:\windows\system32\EuGdiDrv.sys [2009-04-22 3072]
R3 isftrm;isftrm;i:\windows\system32\isftrm.sys [2009-10-26 4096]
R4 G Data Tuner Service;G Data Tuner Service;i:\programmi\G Data\TotalCare\AVKTuner\AVKTunerService.exe [x]
R4 TomTomHOMEService;TomTomHOMEService;i:\programmi\TomTom HOME\TomTomHOMEService.exe [2009-08-07 92008]
S2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;i:\programmi\File comuni\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S2 Apache2.2;Apache2.2;i:\programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe [2010-03-04 24645]
S2 ISWKL;ZoneAlarm Toolbar ISWKL;i:\programmi\CheckPoint\ZAForceField\ISWKL.sys [2009-10-27 25208]
S2 IswSvc;ZoneAlarm Toolbar IswSvc;i:\programmi\CheckPoint\ZAForceField\IswSvc.exe [2009-10-27 476528]
S2 lxdu_device;lxdu_device;i:\windows\system32\lxducoms.exe [2008-05-23 594600]
S2 MBAMService;MBAMService;i:\programmi\Malwarebytes' Anti-Malware\mbamservice.exe [2010-03-29 303952]
S3 MBAMProtector;MBAMProtector;i:\windows\system32\drivers\mbam.sys [2010-03-29 20824]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.com/webhp?client=aff-imeIE: E&sporta in Microsoft Excel - i:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Sothink SWF Catcher - i:\programmi\File comuni\SourceTec\SWF Catcher\InternetExplorer.htm
TCP: {05DEADC7-9034-417D-8B26-85AC9CC44F0A} = 208.67.222.222,208.67.220.220
FF - ProfilePath - i:\documents and settings\A\Dati applicazioni\Mozilla\Firefox\Profiles\36rlo6dp.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - i:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
i:\programmi\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
i:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
i:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
i:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
i:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
i:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
i:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
i:\programmi\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
i:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-Run-nwiz - nwiz.exe
**************************************************************************
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL]
"ImagePath"="\"i:\programmi\MySQL\MySQL Server 5.1\bin\mysqld\" --defaults-file=\"i:\programmi\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-484763869-776561741-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C92D66EE-3DE3-4E65-EA18-008825C22BDF}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hapipnephfhdajhf"=hex:67,61,63,6a,68,61,62,6e,64,62,6b,63,6c,6e,00,00
"hapipnepeekcfdaf"=hex:65,62,6e,68,63,6f,6b,6e,6a,68,65,70,63,66,6c,70,70,65,
70,64,63,64,62,6f,63,6d,6a,65,62,63,6d,6d,6a,6b,64,69,6a,6a,6a,62,6c,66,00,\
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(856)
i:\programmi\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'lsass.exe'(912)
i:\programmi\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Ora fine scansione: 2010-04-09 16:04:45
ComboFix-quarantined-files.txt 2010-04-09 14:04
Pre-Run: 128.029.102.080 byte disponibili
Post-Run: 128.069.603.328 byte disponibili
- - End Of File - - AC541DCBFE8E623920FE3EAC6D80AAC5
________________________________________________________Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16.23.51, on 09/04/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\nvsvc32.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\ZoneLabs\vsmon.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\system32\ctfmon.exe
I:\Programmi\CheckPoint\ZAForceField\IswSvc.exe
I:\WINDOWS\system32\spoolsv.exe
I:\Programmi\Avira\AntiVir Desktop\sched.exe
I:\Programmi\Avira\AntiVir Desktop\avguard.exe
I:\Programmi\CheckPoint\ZAForceField\ForceField.exe
I:\Programmi\File comuni\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
I:\Programmi\Java\jre6\bin\jqs.exe
I:\Programmi\File comuni\LightScribe\LSSrvc.exe
I:\WINDOWS\system32\lxducoms.exe
I:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
I:\Programmi\MySQL\MySQL Server 5.1\bin\mysqld.exe
I:\Programmi\File comuni\Nero\Nero BackItUp 4\NBService.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\SearchIndexer.exe
I:\WINDOWS\RTHDCPL.EXE
I:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
I:\Programmi\Avira\AntiVir Desktop\avgnt.exe
I:\Programmi\Java\jre6\bin\jusched.exe
I:\WINDOWS\system32\RUNDLL32.EXE
I:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
I:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe
I:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
I:\WINDOWS\system32\wbem\wmiapsrv.exe
I:\Programmi\Mozilla Firefox\firefox.exe
I:\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - I:\Programmi\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - I:\Programmi\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - I:\Programmi\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "I:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "I:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "I:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "I:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "I:\Programmi\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "I:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] I:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Monitor Apache Servers.lnk = I:\Programmi\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
O4 - Global Startup: Windows Search.lnk = I:\Programmi\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel -
res://I:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - I:\Programmi\File comuni\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - I:\Programmi\File comuni\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - I:\Programmi\File comuni\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/microso ... 0696163906O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microso ... 0696140015O17 - HKLM\System\CCS\Services\Tcpip\..\{05DEADC7-9034-417D-8B26-85AC9CC44F0A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{10B8F39F-89DE-4621-81DF-BCEEB0419561}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{05DEADC7-9034-417D-8B26-85AC9CC44F0A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS3\Services\Tcpip\..\{05DEADC7-9034-417D-8B26-85AC9CC44F0A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - I:\Programmi\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - I:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - I:\Programmi\File comuni\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - I:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - I:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apache2.2 - Apache Software Foundation - I:\Programmi\Apache Software Foundation\Apache2.2\bin\httpd.exe
O23 - Service: CiSvc - Unknown owner - I:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - I:\Programmi\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - I:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: lxduCATSCustConnectService - Lexmark International, Inc. - I:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxduserv.exe
O23 - Service: lxdu_device - - I:\WINDOWS\system32\lxducoms.exe
O23 - Service: MBAMService - Malwarebytes Corporation - I:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MySQL - Unknown owner - I:\Programmi\MySQL\MySQL.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - I:\Programmi\File comuni\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - I:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - I:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 8972 bytes