ho dei virus nel pc ho eseguito la scansione con malawarebytes e con combofix questi sono gli esiti:
combofix:
ComboFix 11-03-27.02 - nicola 28/03/2011 12.50.44.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.3068.1180 [GMT 2:00]
Eseguito da: c:\downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files\OfferBox
c:\program files\OfferBox\OfferBox.exe
c:\program files\OfferBox\OfferBoxBHO.dll
c:\program files\OfferBox\OfferBoxChromeExtension.crx
c:\program files\OfferBox\OfferBoxEngine.dll
c:\program files\OfferBox\offerboxffx@offerbox.com\chrome.manifest
c:\program files\OfferBox\offerboxffx@offerbox.com\chrome\content\events.js
c:\program files\OfferBox\offerboxffx@offerbox.com\chrome\content\overlay.xul
c:\program files\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.dll
c:\program files\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.xpt
c:\program files\OfferBox\offerboxffx@offerbox.com\install.rdf
c:\program files\OfferBox\OfferBoxLauncher.exe
c:\program files\OfferBox\res\Language.xml
c:\program files\OfferBox\res\loader.gif
c:\program files\pdfforge Toolbar\IE\4.3\pdFForgetoolbarie.dll
c:\users\nicola\AppData\Roaming\OfferBox
c:\users\nicola\AppData\Roaming\OfferBox\config.dat
c:\users\nicola\AppData\Roaming\OfferBox\config.xml
c:\users\Pc\AppData\Local\ttrhee.dat
c:\users\Pc\AppData\Local\ttrhee_nav.dat
c:\users\Pc\AppData\Local\ttrhee_navps.dat
c:\users\Pc\AppData\Roaming\OfferBox
c:\users\Pc\AppData\Roaming\OfferBox\config.dat
c:\users\Pc\AppData\Roaming\OfferBox\config.xml
.
.
((((((((((((((((((((((((( Files Creati Da 2011-02-28 al 2011-03-28 )))))))))))))))))))))))))))))))))))
.
.
2011-03-28 11:11 . 2011-03-28 11:11 -------- d-----w- c:\users\Pc\AppData\Local\temp
2011-03-28 11:11 . 2011-03-28 11:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-28 07:47 . 2011-03-28 07:47 -------- d-----w- c:\users\nicola\AppData\Local\{5438C5DD-C371-488F-9F9F-4E52D8CA71F2}
2011-03-27 19:56 . 2011-03-15 04:05 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F919D99C-CC4D-43B2-A5EF-9A1444341CD2}\mpengine.dll
2011-03-27 19:42 . 2011-03-27 19:42 -------- d-----w- c:\users\nicola\AppData\Local\{6C7D86DA-E531-484E-B18C-6C1D58F2DC83}
2011-03-23 15:15 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-23 15:15 . 2011-02-22 13:33 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-03-23 15:15 . 2011-02-22 13:33 797696 ----a-w- c:\windows\system32\FntCache.dll
2011-03-23 15:07 . 2011-03-23 15:08 -------- d-----w- c:\users\nicola\AppData\Local\{2E8A6983-098A-4B87-8A9A-BA029D36F85F}
2011-03-23 14:58 . 2011-03-23 14:58 -------- d-----w- c:\users\nicola\AppData\Local\{782C1FBE-D518-45F1-9BEE-51D05AF45B04}
2011-03-22 15:53 . 2011-03-22 15:53 -------- d-----w- c:\users\nicola\AppData\Local\{3EC00067-0CBD-49FC-B811-FC08978B360D}
2011-03-22 13:25 . 2011-03-22 13:25 -------- d-----w- c:\users\nicola\AppData\Local\{D268350A-42B7-419B-A6BD-C61CA07F7B0E}
2011-03-21 15:18 . 2011-03-21 15:19 -------- d-----w- c:\users\nicola\AppData\Local\{667D7C0F-F25D-4CE8-8B61-3A50C64BBD3A}
2011-03-19 19:42 . 2011-03-20 16:31 -------- d-----w- c:\users\nicola\AppData\Local\{418B8BC8-368C-4C12-8DE4-B86B6162220D}
2011-03-19 07:42 . 2011-03-19 07:42 -------- d-----w- c:\users\nicola\AppData\Local\{994F41A5-5A63-4E50-B7F4-73FB33C5AFA3}
2011-03-18 13:32 . 2011-03-18 13:33 -------- d-----w- c:\users\nicola\AppData\Local\{6CFCA5D0-F320-422F-99F9-AF543289D291}
2011-03-17 10:47 . 2011-03-17 10:47 -------- d-----w- c:\users\nicola\AppData\Local\{87950DE7-58F2-48F1-B662-21BDB33B75CB}
2011-03-17 09:52 . 2011-03-17 09:52 -------- dc----w- C:\Sounds
2011-03-17 09:45 . 2008-09-04 05:28 19968 ----a-w- c:\windows\system32\drivers\lgusbdiag.sys
2011-03-17 09:45 . 2008-09-04 05:27 24832 ----a-w- c:\windows\system32\drivers\lgusbmodem.sys
2011-03-17 09:45 . 2008-09-04 05:27 13056 ----a-w- c:\windows\system32\drivers\lgusbbus.sys
2011-03-17 09:45 . 2011-03-17 09:51 -------- d-----w- c:\program files\LG Electronics
2011-03-17 09:42 . 2007-11-08 15:26 1164728 ----a-w- c:\windows\system32\NMSDVDXU.dll
2011-03-17 09:42 . 2005-09-26 21:55 419240 ----a-w- c:\windows\system32\Vsflex7L.ocx
2011-03-17 09:42 . 2005-03-18 15:55 630784 ----a-w- c:\windows\system32\vsflex8u.ocx
2011-03-17 09:42 . 2000-05-21 23:00 244416 ----a-w- c:\windows\system32\Msflxgrd.ocx
2011-03-17 09:41 . 2011-03-21 16:55 -------- d-----w- c:\program files\LG PC Suite II
2011-03-17 09:41 . 2011-03-17 09:54 -------- d-----w- c:\users\nicola\AppData\Roaming\LG Electronics
2011-03-17 09:40 . 2011-03-17 09:40 -------- d-----w- c:\users\nicola\AppData\Roaming\InstallShield
2011-03-16 22:46 . 2011-03-16 22:46 -------- d-----w- c:\users\nicola\AppData\Local\{3E6FD6AA-D8A8-4EFB-B220-A9CE91E27DF5}
2011-03-16 10:46 . 2011-03-16 10:46 -------- d-----w- c:\users\nicola\AppData\Local\{D24447DA-52A1-4E99-93B6-280F47563374}
2011-03-15 19:19 . 2011-03-15 19:19 -------- d-----w- c:\program files\iPod
2011-03-15 18:40 . 2011-03-15 18:40 -------- d-----w- c:\users\nicola\AppData\Local\{F47658F2-AE42-4A7E-B001-7CB2F6F66829}
2011-03-15 13:18 . 2011-03-15 13:18 -------- d-----w- c:\users\nicola\AppData\Local\{F7235C4E-01E0-41D2-9E69-8DE408C24911}
2011-03-14 15:18 . 2011-03-14 15:18 -------- d-----w- c:\users\nicola\AppData\Local\{A018B5BC-BBC8-4C44-9799-0D468D8E88FE}
2011-03-14 13:06 . 2011-03-14 13:06 -------- d-----w- c:\users\nicola\AppData\Local\{8196C078-ACC9-4CAA-B3B8-093514181502}
2011-03-13 22:03 . 2011-03-13 22:03 -------- d-----w- c:\program files\Common Files\Java
2011-03-13 21:19 . 2011-03-13 21:21 -------- d-----w- c:\users\nicola\AppData\Local\{1A39F828-47DA-4264-9DA2-4C8DCF939C94}
2011-03-13 21:19 . 2011-03-13 21:19 -------- d-----w- c:\users\nicola\AppData\Local\{E54F588C-D829-4B2B-BD5E-D3AD2E032E22}
2011-03-13 09:18 . 2011-03-13 09:18 -------- d-----w- c:\users\nicola\AppData\Local\{FB1367A5-5628-4937-B434-7E3A85BF1AD3}
2011-03-12 13:22 . 2011-03-12 13:22 -------- d-----w- c:\users\nicola\AppData\Local\{526F06EB-071B-48F9-A283-AC78242CC0C4}
2011-03-11 20:13 . 2011-03-11 20:13 -------- d-----w- c:\users\nicola\AppData\Local\{0812F003-59CF-49BC-997B-A68AFDEAB1D5}
2011-03-11 08:11 . 2011-03-11 08:13 -------- d-----w- c:\users\nicola\AppData\Local\{AB2971FC-EE2F-4D03-8F18-89B9572B6E2E}
2011-03-10 08:34 . 2011-03-10 08:36 -------- d-----w- c:\users\nicola\AppData\Local\{3AC3FF0C-8007-4D81-8BFE-618282E53D60}
2011-03-09 20:12 . 2011-03-09 20:12 -------- d-----w- c:\users\nicola\AppData\Local\{D4B3E932-CC8F-4EDD-A15A-4367CDB2C7A5}
2011-03-09 11:06 . 2011-03-09 11:06 -------- d-----w- c:\users\nicola\AppData\Roaming\vlc
2011-03-09 08:58 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2011-03-09 08:58 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2011-03-09 08:58 . 2010-12-29 18:28 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-03-09 08:58 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-09 08:57 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-03-09 08:57 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-03-08 18:32 . 2011-03-08 18:32 -------- d-----w- c:\program files\Bonjour
2011-03-08 14:42 . 2011-03-09 08:11 -------- d-----w- c:\users\nicola\AppData\Local\{D0C605B3-EC4A-4CDB-ABE0-B69E5761D0F8}
2011-03-08 14:28 . 2011-03-08 14:28 -------- d-----w- c:\users\mattia
2011-03-08 13:11 . 2011-03-08 13:11 -------- d-----w- c:\users\nicola\AppData\Local\{6604FE75-82B2-4AF4-81AB-E24FBA8DE9CA}
2011-03-07 19:26 . 2011-03-07 19:26 -------- d-----w- c:\users\nicola\AppData\Local\{1C69DF44-3515-4A2A-A8DA-6A63ADDDDA08}
2011-03-07 19:26 . 2011-03-07 19:26 -------- d-----w- c:\users\nicola\AppData\Local\{CA6C1C96-9E1D-4EA4-937B-55D9EC051558}
2011-03-07 17:38 . 2011-03-07 17:38 -------- d-----w- c:\windows\it
2011-03-07 17:05 . 2010-09-22 23:21 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-03-07 16:34 . 2011-03-07 16:34 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-03-06 16:47 . 2011-03-06 16:47 -------- d-----w- c:\users\nicola\AppData\Local\{A323CB8B-DA8D-4CC9-B880-69F12E655714}
2011-03-06 14:42 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-03-06 14:42 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-03-06 14:42 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-03-06 14:40 . 2011-03-06 14:40 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\627e95551cbdc0c01\MeshBetaRemover.exe
2011-03-06 14:33 . 2011-03-06 14:33 -------- d-----w- c:\users\nicola\AppData\Local\Xara
2011-03-06 10:44 . 2011-03-06 10:44 -------- d-----w- c:\users\nicola\AppData\Roaming\Template
2011-03-05 10:19 . 2011-03-05 10:19 -------- d-----w- c:\program files\Application Updater
2011-03-05 10:19 . 2011-03-05 10:19 -------- d-----w- c:\program files\Common Files\Spigot
2011-03-03 20:43 . 2011-03-11 11:22 -------- d-----w- c:\users\nicola\AppData\Local\Windows Live
2011-03-03 16:37 . 2011-03-28 10:57 -------- d-----w- c:\users\nicola\AppData\Local\freetvradio Air
2011-03-03 16:17 . 2011-03-03 16:17 -------- d-----w- c:\users\nicola\AppData\Roaming\Leadertech
2011-03-02 22:59 . 2011-03-02 22:59 -------- d-----w- c:\users\TEMP
2011-03-02 19:52 . 2011-03-02 19:53 -------- d-----w- c:\program files\Microsoft ATS
2011-02-28 16:39 . 2011-02-28 16:39 -------- d-----w- c:\users\Pc\AppData\Roaming\DVDVideoSoftIEHelpers
2011-02-28 16:38 . 2011-02-28 16:39 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2011-02-28 16:38 . 2011-02-28 16:38 -------- d-----w- c:\program files\DVDVideoSoft
2011-02-28 15:25 . 2011-02-28 15:25 -------- d-----w- c:\program files\Common Files\Yahoo!
2011-02-28 15:25 . 2011-02-28 15:25 -------- d-----w- c:\program files\Pinnacle
2011-02-28 15:24 . 2011-02-28 16:21 -------- d-----w- c:\programdata\Pinnacle VideoSpin
2011-02-27 14:14 . 2011-02-23 14:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-15 18:40 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-23 15:04 . 2010-09-03 12:28 40648 ----a-w- c:\windows\avastSS.scr
2011-02-23 15:04 . 2010-09-03 12:28 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:56 . 2010-09-03 12:29 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2010-09-03 12:29 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2010-09-03 12:29 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:55 . 2010-09-03 12:29 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-02-23 14:54 . 2010-09-03 12:29 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-18 15:36 . 2011-02-18 15:36 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 15:36 . 2011-02-18 15:36 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-02 20:40 . 2010-04-18 08:04 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 16:11 . 2009-10-03 07:03 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-02-15 14:29 638336 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-15 14:29 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-15 14:29 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-15 14:29 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-15 14:29 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:08 . 2011-02-15 14:29 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:07 . 2011-02-15 14:29 37376 ----a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-15 14:29 258048 ----a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-15 14:29 586240 ----a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-15 14:29 2873344 ----a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-15 14:29 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-15 14:29 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-15 14:29 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-15 14:29 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-15 14:29 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-15 14:29 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-15 14:29 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-15 14:29 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-15 14:29 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-15 14:29 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-15 14:29 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14 . 2011-02-15 14:29 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12 . 2011-02-15 14:29 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-15 14:29 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-15 14:29 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-01-08 08:47 . 2011-02-15 14:20 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28 . 2011-02-15 14:20 292352 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:57 . 2011-02-15 14:29 2039808 ----a-w- c:\windows\system32\win32k.sys
2010-12-28 15:55 . 2011-02-15 14:29 413696 ----a-w- c:\windows\system32\odbc32.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}"= "c:\program files\MAX_IT_Atube\tbMAX_.dll" [2010-02-22 2353176]
.
[HKEY_CLASSES_ROOT\clsid\{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\MAX_IT_Atube\tbMAX_.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}]
2010-04-21 21:22 2349080 ----a-w- c:\program files\Search_USA\tbSea1.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C4AD71D-52E1-4402-9E5B-CBFC295EC9BA}]
2010-07-05 16:30 134816 ----a-w- c:\program files\freeTVRadio\spointer\extensions\freetvradio_air_ie.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4edd5c14-2d22-4d7a-9748-c975a7fd933b}]
2010-04-21 21:24 2349080 ----a-w- c:\program files\Softonic_Italia\tbSof0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2010-04-27 09:08 2393184 ----a-w- c:\program files\DVDVideoSoftTB\tbDVDV.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8c2f6d41-2583-424f-a88b-46d5401b5a96}]
2010-05-14 11:47 2515552 ----a-w- c:\program files\P2P_MAX_IT_Atube\tbP2P0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{dbbe01d1-5a24-48db-ae99-bd025b80b9e7}]
2010-05-14 11:47 2515552 ----a-w- c:\program files\AresTube2\tbAre1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4edd5c14-2d22-4d7a-9748-c975a7fd933b}"= "c:\program files\Softonic_Italia\tbSof0.dll" [2010-04-21 2349080]
"{48405d3d-2674-4cd8-b1ef-9a719443bd3f}"= "c:\program files\Search_USA\tbSea1.dll" [2010-04-21 2349080]
"{8c2f6d41-2583-424f-a88b-46d5401b5a96}"= "c:\program files\P2P_MAX_IT_Atube\tbP2P0.dll" [2010-05-14 2515552]
"{dbbe01d1-5a24-48db-ae99-bd025b80b9e7}"= "c:\program files\AresTube2\tbAre1.dll" [2010-05-14 2515552]
"{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}"= "c:\program files\MAX_IT_Atube\tbMAX_.dll" [2010-02-22 2353176]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVDV.dll" [2010-04-27 2393184]
.
[HKEY_CLASSES_ROOT\clsid\{4edd5c14-2d22-4d7a-9748-c975a7fd933b}]
.
[HKEY_CLASSES_ROOT\clsid\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}]
.
[HKEY_CLASSES_ROOT\clsid\{8c2f6d41-2583-424f-a88b-46d5401b5a96}]
.
[HKEY_CLASSES_ROOT\clsid\{dbbe01d1-5a24-48db-ae99-bd025b80b9e7}]
.
[HKEY_CLASSES_ROOT\clsid\{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{48405D3D-2674-4CD8-B1EF-9A719443BD3F}"= "c:\program files\Search_USA\tbSea1.dll" [2010-04-21 2349080]
"{4EDD5C14-2D22-4D7A-9748-C975A7FD933B}"= "c:\program files\Softonic_Italia\tbSof0.dll" [2010-04-21 2349080]
"{8C2F6D41-2583-424F-A88B-46D5401B5A96}"= "c:\program files\P2P_MAX_IT_Atube\tbP2P0.dll" [2010-05-14 2515552]
"{0E9C9453-038B-4C2D-999D-21E0D2AA7CE5}"= "c:\program files\MAX_IT_Atube\tbMAX_.dll" [2010-02-22 2353176]
"{DBBE01D1-5A24-48DB-AE99-BD025B80B9E7}"= "c:\program files\AresTube2\tbAre1.dll" [2010-05-14 2515552]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\tbDVDV.dll" [2010-04-27 2393184]
.
[HKEY_CLASSES_ROOT\clsid\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}]
.
[HKEY_CLASSES_ROOT\clsid\{4edd5c14-2d22-4d7a-9748-c975a7fd933b}]
.
[HKEY_CLASSES_ROOT\clsid\{8c2f6d41-2583-424f-a88b-46d5401b5a96}]
.
[HKEY_CLASSES_ROOT\clsid\{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}]
.
[HKEY_CLASSES_ROOT\clsid\{dbbe01d1-5a24-48db-ae99-bd025b80b9e7}]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-11-13 972080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-02 39408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Google Update"="c:\users\nicola\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-18 136176]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2009-03-02 3399727]
"Mobile Partner"="c:\program files\MD-@ HSUPA\MD-@ HSUPA.exe" [2010-01-27 110592]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2008-04-30 22058792]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-04 1410344]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-11-28 1148200]
"TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-01-21 210216]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2008-11-14 218408]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-11-26 210216]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-10-30 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-06-03 450652]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-01-28 526336]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2010-09-22 884584]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 727592]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kaspersky Security Scan.lnk]
backup=c:\windows\pss\Kaspersky Security Scan.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kaspersky Security Scan.lnk
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-22 14:09 63712 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer for HP TouchSmart]
2008-12-25 11:41 189736 ------w- c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 14:33 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-08-29 15:11 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TSMAgent]
2008-12-25 11:41 1316136 ------w- c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 E2ECAP;CamDirector - WDM Video Capture;c:\windows\system32\DRIVERS\e2ecap.sys [2008-08-05 156160]
R2 gupdate;Servizio di Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-12-05 109408]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [2010-04-19 18432]
R3 u9usbser;MYWAVEU9 USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\u9usbser.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/04/03 03:54];c:\program files\Hewlett-Packard\Media\DVD\000.fcl [2008-11-28 16:04 87536]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\aestsrv.exe [2009-03-02 81920]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2011-01-28 387072]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-11-16 50704]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-12-17 365952]
S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2008-11-26 296320]
S2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2008-11-26 116096]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-11-19 222512]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-09-04 54784]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2008-05-28 22072]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 12:49]
.
2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 12:49]
.
2011-03-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4253506766-320108052-3283501201-1001Core.job
- c:\users\nicola\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-09 06:59]
.
2011-03-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4253506766-320108052-3283501201-1001UA.job
- c:\users\nicola\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-09 06:59]
.
2011-03-22 c:\windows\Tasks\HPCeeScheduleFornicola.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-02-22 10:34]
.
2011-03-28 c:\windows\Tasks\HPCeeScheduleForPc.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-02-22 10:34]
.
2011-02-15 c:\windows\Tasks\User_Feed_Synchronization-{9388F270-E3D0-42E5-9B78-118C77434907}.job
- c:\windows\system32\msfeedssync.exe [2011-02-15 04:47]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.plusnetwork.comIE: &AOL Toolbar Cerca - c:\programdata\AOL\ieToolbar\resources\it-IT\local\search.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Invia immagine alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Invia pagina alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Scarica con Free Download Manager -
file://c:\program files\Free Download Manager\dllink.htm
IE: Scarica i video con Free Download Manager -
file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Scarica selezionati con Free Download Manager -
file://c:\program files\Free Download Manager\dlselected.htm
IE: Scarica tutto con Free Download Manager -
file://c:\program files\Free Download Manager\dlall.htm
TCP: {7224FACA-8E03-4804-9651-1C2BD670DE06} = 62.13.169.92 62.13.169.93
FF - ProfilePath - c:\users\nicola\AppData\Roaming\Mozilla\Firefox\Profiles\qfogohfv.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage -
hxxp://www.facebook.com/home.php?#!/FF - prefs.js: keyword.URL -
hxxp://it.search.yahoo.com/search?fr=gr ... =302398&p=FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programdata\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Interest Recognizer for Freetvradio:
freetvradio@spointer.com - c:\program files\freeTVRadio\spointer\extensions\freetvradio@spointer.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
URLSearchHooks-{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-SmartMenu - %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
HKLM-Run-NWEReboot - (no file)
AddRemove-Facebook Plug-In - c:\users\nicola\AppData\Roaming\Facebook\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-03-28 13:12
Windows 6.0.6002 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
.
c:\users\nicola\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
Scansione completata con successo
Files nascosti: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2011-03-28 13:20:18
ComboFix-quarantined-files.txt 2011-03-28 11:20
.
Pre-Run: 277.242.462.208 byte disponibili
Post-Run: 278.095.335.424 byte disponibili
.
Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 8D5DAE7926827564B54607AB5D9A63E6
____________________________________________________________
esito malawarebytes:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.orgVersione database: 6203
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019
29/03/2011 18.24.06
mbam-log-2011-03-29 (18-24-06).txt
Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi esaminati: 66220
Tempo trascorso: 8 minuti, 13 secondi
Processi infetti in memoria: 0
Moduli di memoria infetti: 1
Chiavi di registro infette: 0
Valori di registro infetti: 1
Voci infette nei dati di registro: 0
Cartelle infette: 0
File infetti: 1
Processi infetti in memoria:
(Non sono stati rilevati elementi nocivi)
Moduli di memoria infetti:
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Delete on reboot.
Chiavi di registro infette:
(Non sono stati rilevati elementi nocivi)
Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully.
Voci infette nei dati di registro:
(Non sono stati rilevati elementi nocivi)
Cartelle infette:
(Non sono stati rilevati elementi nocivi)
File infetti:
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Delete on reboot.
_________________________________
ora che faccio?