ComboFix 11-09-24.04 - Luca 26/09/2011 9.28.55.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.39.1040.18.3070.1541 [GMT 2:00]
Eseguito da: c:\users\Luca\Downloads\ComboFix.exe
AV: McAfee Antivirus e Antispyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Antivirus e Antispyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Mozilla Firefox\extensions\{27E679CC-6AAB-4B2A-BB87-096FE4178464}
c:\program files\Mozilla Firefox\extensions\{27E679CC-6AAB-4B2A-BB87-096FE4178464}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{27E679CC-6AAB-4B2A-BB87-096FE4178464}\chrome\queryexplorer.jar
c:\program files\Mozilla Firefox\extensions\{27E679CC-6AAB-4B2A-BB87-096FE4178464}\defaults\preferences\prefs.js
c:\program files\Mozilla Firefox\extensions\{27E679CC-6AAB-4B2A-BB87-096FE4178464}\install.rdf
c:\program files\QueryExplorer
c:\program files\ShopperReports3
c:\program files\ShopperReports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\chrome.manifest
c:\program files\ShopperReports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\chrome\firefoxtoolbar.jar
c:\program files\ShopperReports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\components\BRNstFF.xpt
c:\program files\ShopperReports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\install.rdf
c:\program files\ShopperReports3\bin\3.0.497.0\LaunchHelp.dll
c:\program files\ShopperReports3\bin\3.0.497.0\link.ico
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\About Us.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\Customer Support.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\ShopperReports Uninstall Instructions.lnk
c:\programdata\QueryExplorer
c:\users\Luca\AppData\Roaming\.#
c:\users\Luca\AppData\Roaming\Local
c:\users\Luca\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
c:\users\Luca\AppData\Roaming\Local\Temp\DDM\Settings\1.ddi
c:\users\Luca\AppData\Roaming\Local\Temp\DDM\Settings\Inception_Trailer_592.divx.ddr
c:\users\Luca\AppData\Roaming\Local\Temp\DDM\Settings\promo.avi.ddr
c:\users\Luca\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
c:\users\Luca\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Inception_Trailer_592.divx
c:\users\Luca\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\promo.avi
c:\users\Luca\AppData\Roaming\OfferBox
c:\users\Luca\AppData\Roaming\OfferBox\config.xml
c:\users\Luca\AppData\Roaming\PriceGong
c:\users\Luca\AppData\Roaming\PriceGong\Data\1.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\a.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\b.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\c.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\d.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\e.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\f.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\g.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\h.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\i.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\j.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\k.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\l.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\m.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\mru.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\n.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\o.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\p.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\q.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\r.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\s.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\t.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\u.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\v.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\w.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\x.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\y.xml
c:\users\Luca\AppData\Roaming\PriceGong\Data\z.xml
c:\users\Luca\AppData\Roaming\ShopperReports3
c:\users\Luca\AppData\Roaming\ShopperReports3\IE\cs\Config.xml
c:\users\Luca\AppData\Roaming\ShopperReports3\IE\cs\report\aggr_storage.xml
c:\users\Luca\AppData\Roaming\ShopperReports3\IE\cs\report\send_storage.xml
c:\windows\system32\MailBee.dll
F:\autorun.inf
.
.
((((((((((((((((((((((((( Files Creati Da 2011-08-26 al 2011-09-26 )))))))))))))))))))))))))))))))))))
.
.
2011-09-26 08:23 . 2011-09-26 08:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-26 07:22 . 2011-09-26 07:22 54016 ----a-w- c:\windows\system32\drivers\pkdrrixq.sys
2011-09-25 08:44 . 2011-09-25 08:44 -------- d-----w- c:\users\Luca\AppData\Roaming\Malwarebytes
2011-09-25 08:42 . 2011-09-25 08:42 -------- d-----w- c:\programdata\Malwarebytes
2011-09-25 08:42 . 2011-08-31 15:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-25 08:42 . 2011-09-25 08:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-09-24 11:38 . 2011-09-24 11:38 71880 ----a-w- c:\windows\system32\PxSecure.dll
2011-09-24 11:38 . 2011-09-24 11:38 76696 ----a-w- c:\windows\system32\drivers\pxrts.sys
2011-09-24 11:38 . 2011-09-24 11:38 32008 ----a-w- c:\windows\system32\drivers\pxscan.sys
2011-09-24 11:38 . 2011-09-24 11:38 26096 ----a-w- c:\windows\system32\drivers\pxkbf.sys
2011-09-24 11:38 . 2011-09-24 11:38 -------- d-----w- c:\program files\Prevx
2011-09-24 11:37 . 2011-09-25 11:28 -------- d-----w- c:\programdata\PrevxCSI
2011-09-23 09:15 . 2011-09-23 09:15 -------- d-----w- c:\users\Luca\AppData\Roaming\QuickScan
2011-09-23 09:03 . 2011-09-23 09:03 388096 ----a-r- c:\users\Luca\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-23 08:46 . 2011-09-23 08:46 -------- dc-h--w- c:\programdata\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-09-22 08:09 . 2011-09-25 08:38 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-09-22 08:09 . 2011-09-22 08:18 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-09-21 17:02 . 2011-09-21 17:03 -------- d-----w- c:\program files\CCleaner
2011-09-21 16:33 . 2011-09-22 07:43 -------- d-----w- c:\program files\Trend Micro
2011-09-17 10:05 . 2011-08-19 13:56 28504 ----a-w- c:\program files\Mozilla Firefox\ScriptFF.dll
2011-09-15 18:34 . 2011-08-10 12:14 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-28 10:47 . 2011-08-28 10:47 -------- d-----w- c:\program files\SWFMenu
2011-08-27 09:32 . 2011-08-27 09:32 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-15 08:00 . 2010-05-14 08:40 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-08-15 08:00 . 2010-05-14 08:40 87808 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2011-08-15 08:00 . 2010-05-14 08:40 64712 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2011-08-15 08:00 . 2010-05-14 08:40 59288 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2011-08-15 08:00 . 2010-05-14 08:40 57432 ----a-w- c:\windows\system32\drivers\cfwids.sys
2011-08-15 08:00 . 2010-05-14 08:40 338040 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2011-08-15 08:00 . 2010-05-14 08:40 180072 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-08-15 08:00 . 2010-05-14 08:40 164776 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2011-08-15 08:00 . 2010-01-05 16:04 119808 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-08-15 08:00 . 2009-01-10 22:58 461864 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2011-07-26 07:06 . 2011-05-18 16:43 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-22 02:54 . 2011-08-11 07:40 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-22 02:48 . 2011-08-11 07:40 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-07-22 02:44 . 2011-08-11 07:40 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-11 13:25 . 2011-08-24 08:44 2048 ----a-w- c:\windows\system32\tzres.dll
2011-07-06 15:31 . 2011-08-10 15:18 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-11-23 14:21 . 2010-11-23 14:21 774144 ----a-w- c:\program files\RngInterstitial.dll
2011-06-29 17:40 . 2011-05-07 09:48 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-08-21 20:19 . 2009-12-01 12:35 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2011-04-14 12:01 . 2010-05-14 08:41 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}]
2011-01-17 14:54 175912 ----a-w- c:\program files\Search_USA\prxtbSea2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{48405d3d-2674-4cd8-b1ef-9a719443bd3f}"= "c:\program files\Search_USA\prxtbSea2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{48405D3D-2674-4CD8-B1EF-9A719443BD3F}"= "c:\program files\Search_USA\prxtbSea2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 16:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]
"AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe" [2008-08-28 13145448]
"MyTomTomSA.exe"="c:\program files\MyTomTom 3\MyTomTomSA.exe" [2011-06-30 399320]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"UniblueRegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2011-08-18 67456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-20 6144000]
"Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-08-19 319488]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-21 30192]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-07-29 526896]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-05-20 204908]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-09 13584928]
"Setresolution"="c:\acer\config\1440x900.cmd" [2008-02-26 240]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-23 198160]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-07-13 1312384]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-01-10 1230704]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"removeSearchqudatamngr"="RD" [X]
"removeSearchqutoolbar"="RD" [X]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2010-4-5 494920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\WI371A~1\Datamngr\datamngr.dll c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DeviceManager;DeviceManager;c:\program files\Common Files\DeviceHelper\DeviceManager.exe [2008-11-21 40960]
R2 gupdate1ca5407edc8772d;Servizio di Google Update (gupdate1ca5407edc8772d);c:\program files\Google\Update\GoogleUpdate.exe [2009-10-23 133104]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-21 30192]
R3 gupdatem;Servizio Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-10-23 133104]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-08-15 87808]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
R3 qcusbser;Modem Interface USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\qcusbser.sys [2008-10-22 103552]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2011-09-24 32008]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-08-15 64712]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-08-15 164776]
S1 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2011-09-24 76696]
S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2011-09-24 6416120]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-08-19 160344]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2011-08-19 148520]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-08-15 57432]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-08-15 338040]
S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2011-09-24 26096]
.
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - MBAMPROTECTOR
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-09-25 c:\windows\Tasks\Epson Printer Software Downloader.job
- c:\program files\EPSON\EPAPDL\E_SAPDL2.EXE [2009-05-26 09:43]
.
2011-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-23 17:40]
.
2011-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-23 17:40]
.
2011-09-25 c:\windows\Tasks\Norton Security Scan for Luca.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-05-22 00:27]
.
2011-09-25 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2011-09-23 09:48]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.searchqu.com/406mStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACA ... pire_m1201IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Luca\AppData\Roaming\Mozilla\Firefox\Profiles\y2y0gtdx.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage -
hxxp://www.searchqu.com/406FF - prefs.js: keyword.URL -
hxxp://dts.search-results.com/sr?src=ff ... mid=406&q=FF - prefs.js: network.proxy.http - 216.157.222.82
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.type - 0
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Toolbar-10 - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-09-26 10:24
Windows 6.0.6002 Service Pack 2 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2011-09-26 10:39:56
ComboFix-quarantined-files.txt 2011-09-26 08:39
.
Pre-Run: 40.481.292.288 byte disponibili
Post-Run: 42.016.198.656 byte disponibili
.
- - End Of File - - 9C3B7AA8A056B38FF5C2B9E229C8E623