ComboFix 13-09-22.01 - Matteo 22/09/2013 21:19:28.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.39.1040.18.4061.2427 [GMT 2:00]
Eseguito da: c:\users\Matteo\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\ASPG_icon.ico
c:\program files (x86)\Funmoods
c:\program files (x86)\Funmoods\1.5.23.22\bh\escort.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortApp.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortEng.dll
c:\program files (x86)\Funmoods\1.5.23.22\escorTlbr.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortShld.dll
c:\program files (x86)\Funmoods\1.5.23.22\FavIcon.ico
c:\program files (x86)\Funmoods\1.5.23.22\funmoodssrv.exe
c:\program files (x86)\Funmoods\1.5.23.22\Sqlite3.dll
c:\program files (x86)\Funmoods\1.5.23.22\uninst.dat
c:\program files (x86)\Funmoods\1.5.23.22\uninstall.exe
c:\program files (x86)\StartNow Toolbar
c:\program files (x86)\StartNow Toolbar\genfix.exe
c:\program files (x86)\StartNow Toolbar\Reactivate.exe
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_images.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_maps.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_news.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_videos.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_web.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_amazon.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_ebay.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_facebook.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_games.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_msn.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_shopping.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_travel.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_twitter.png
c:\program files (x86)\StartNow Toolbar\Resources\images\startnow_logo.png
c:\program files (x86)\StartNow Toolbar\Resources\installer.xml
c:\program files (x86)\StartNow Toolbar\Resources\skin\chevron_button.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\searchbox_button_hover.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\searchbox_button_normal.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\searchbox_dropdown_button_normal.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\searchbox_input_background.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\searchbox_input_left.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\searchbox_input_middle.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\separator.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\splitter.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\toolbarbutton_ff_hover_c.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_c.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_l.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_r.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_c.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_l.png
c:\program files (x86)\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_r.png
c:\program files (x86)\StartNow Toolbar\Resources\toolbar.xml
c:\program files (x86)\StartNow Toolbar\Resources\update.xml
c:\program files (x86)\StartNow Toolbar\StartNowToolbarUninstall.exe
c:\program files (x86)\StartNow Toolbar\Toolbar32.dll
c:\program files (x86)\StartNow Toolbar\ToolbarBroker.exe
c:\program files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe
c:\program files (x86)\StartNow Toolbar\uninstall.dat
c:\program files (x86)\StartNow Toolbar\XBrowser.dll
c:\programdata\BBrroWse2seaveo
c:\programdata\BBrroWse2seaveo\51374945e86bc.dll
c:\programdata\BBrroWse2seaveo\51374945e86bc.tlb
c:\programdata\BBrroWse2seaveo\settings.ini
c:\programdata\BBrroWse2seaveo\uninstall.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\BBrroWse2seaveo
c:\programdata\Microsoft\Windows\Start Menu\Programs\BBrroWse2seaveo\BBrroWse2seaveo.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\BBrroWse2seaveo\Uninstall.lnk
c:\users\Babbo\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Babbo\AppData\Roaming\Kywi
c:\users\Babbo\AppData\Roaming\Kywi\inuf.exe
c:\users\Babbo\AppData\Roaming\OfferBox
c:\users\Babbo\AppData\Roaming\OfferBox\config.dat
c:\users\Babbo\AppData\Roaming\OfferBox\config.xml
c:\users\Guest\AppData\Roaming\cacaoweb
c:\users\Guest\AppData\Roaming\cacaoweb\cacaoweb.exe
c:\users\Guest\AppData\Roaming\cacaoweb\npdfile.dat
c:\users\Guest\AppData\Roaming\cacaoweb\storage.db
c:\users\Guest\cacaoweb.exe
c:\users\Guest\Google_Chrome_Setup.exe
c:\users\Matteo\AppData\Local\DProtect
c:\users\Matteo\AppData\Local\DProtect\config.dat
c:\users\Matteo\AppData\Local\DProtect\DProtectSvc.exe
c:\users\Matteo\AppData\Local\DProtect\DPUninstall.exe
c:\users\Matteo\AppData\Local\DProtect\eBP.dll
c:\users\Matteo\AppData\Local\DProtect\eBPSD.dll
c:\users\Matteo\AppData\Local\DProtect\eDelayinfo.edb
c:\users\Matteo\AppData\Local\DProtect\eGdpSvc.exe
c:\users\Matteo\AppData\Local\DProtect\log\DProtectSvc.LOG
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgpbfmgacllblmgflefneokbpiaidcc
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgpbfmgacllblmgflefneokbpiaidcc\1\51374945e84708.94342796.js
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgpbfmgacllblmgflefneokbpiaidcc\1\background.html
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgpbfmgacllblmgflefneokbpiaidcc\1\content.js
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgpbfmgacllblmgflefneokbpiaidcc\1\lsdb.js
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgpbfmgacllblmgflefneokbpiaidcc\1\manifest.json
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgpbfmgacllblmgflefneokbpiaidcc\1\sqlite.js
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_odgpbfmgacllblmgflefneokbpiaidcc_0.localstorage-journal
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_odgpbfmgacllblmgflefneokbpiaidcc_0.localstorage
c:\users\Matteo\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Matteo\AppData\Local\lollipop
c:\users\Matteo\AppData\Local\lollipop\logo.ico
c:\users\Matteo\AppData\Local\lollipop\lollipop_08262026.bat
c:\users\Matteo\AppData\Local\lollipop\lollipop_08262026.exe
c:\users\Matteo\AppData\Local\lollipop\lollipop_08262026.lpd
c:\users\Matteo\AppData\Local\lollipop\lollipop_08262026_cfg.lpd
c:\users\Matteo\AppData\Local\lollipop\lollipop_08262026_ps.lpd
c:\users\Matteo\AppData\Roaming\BabMaint.exe
c:\users\Matteo\AppData\Roaming\cacaoweb
c:\users\Matteo\AppData\Roaming\cacaoweb\cacaoweb.crx
c:\users\Matteo\AppData\Roaming\cacaoweb\cacaoweb.exe
c:\users\Matteo\AppData\Roaming\cacaoweb\npdfile.dat
c:\users\Matteo\AppData\Roaming\cacaoweb\replicating8C8B1C793B0A50D9951BC2BBFFDE03BE.cacao
c:\users\Matteo\AppData\Roaming\cacaoweb\storage.db
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\chrome.manifest
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\funmoods.css
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\funmoods.xul
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\images\pref.jpg
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\arwDwn.gif
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ae.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\bg.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ch.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cn.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cz.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\de.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\eg.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\en.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\es.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\fr.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\gr.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\he.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\il.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\it.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ja.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\jp.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\nl.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\no.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pl.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pt.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ro.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ru.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sa.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\se.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sv.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\tr.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ua.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\us.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\help_16.gif
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\home.gif
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\logo.png
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\privecy_16_hot.gif
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\imgs\tellafriend.gif
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\loader.xul
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\mtstart.js
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\preferences.xul
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\content\tmplt.js
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\install.rdf
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@funmoods.com\META-INF\manifest.mf
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\psydmu-aq@ayia-ywvip.com
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\psydmu-aq@ayia-ywvip.com\bootstrap.js
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\psydmu-aq@ayia-ywvip.com\chrome.manifest
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\psydmu-aq@ayia-ywvip.com\content\bg.js
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\psydmu-aq@ayia-ywvip.com\content\zy.xul
c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\psydmu-aq@ayia-ywvip.com\install.rdf
c:\users\Public\sdelevURL.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_DPService
-------\Service_Updater Service for StartNow Toolbar
-------\Service_DPService
-------\Service_Updater Service for StartNow Toolbar
.
.
((((((((((((((((((((((((( Files Creati Da 2013-08-22 al 2013-09-22 )))))))))))))))))))))))))))))))))))
.
.
2013-09-22 19:28 . 2013-09-22 19:28 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-09-22 19:28 . 2013-09-22 19:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-22 19:28 . 2013-09-22 19:28 -------- d-----w- c:\users\Babbo\AppData\Local\temp
2013-09-22 15:15 . 2013-09-22 15:15 -------- d-----w- c:\users\Matteo\AppData\Local\Macromedia
2013-09-22 15:14 . 2013-09-22 15:14 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-09-22 15:12 . 2013-09-22 15:12 -------- d-----w- c:\users\Matteo\AppData\Local\Wajam
2013-09-22 15:12 . 2013-09-22 15:13 -------- d-----w- c:\program files (x86)\Wajam
2013-09-22 15:12 . 2013-09-22 15:12 -------- d-----w- c:\users\Matteo\AppData\Local\BonanzaDealsLive
2013-09-22 15:12 . 2013-09-22 15:12 -------- d-----w- c:\programdata\BonanzaDealsLive
2013-09-22 15:12 . 2013-09-22 15:12 -------- d-----w- c:\program files (x86)\BonanzaDeals
2013-09-22 11:41 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F8E47692-4298-4446-BF76-E49A1E5AE813}\mpengine.dll
2013-09-14 23:05 . 2013-09-14 23:05 -------- d-----w- c:\users\Matteo\AppData\Local\avgchrome
2013-09-14 09:47 . 2013-09-14 09:47 -------- d-----w- c:\programdata\BitGuard
2013-09-12 22:39 . 2013-08-10 05:20 15404544 ----a-w- c:\windows\system32\ieframe.dll
2013-09-12 22:39 . 2013-08-10 05:21 19246592 ----a-w- c:\windows\system32\mshtml.dll
2013-08-29 17:46 . 2013-08-29 17:46 -------- d-----w- c:\users\Guest\AppData\Local\Diagnostics
2013-08-29 17:41 . 2013-08-29 17:41 -------- d-----w- c:\users\Guest\AppData\Local\Opera Software
2013-08-29 17:41 . 2013-08-29 17:41 -------- d-----w- c:\users\Guest\AppData\Roaming\Opera Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-22 19:32 . 2012-10-24 17:20 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-09-21 16:28 . 2012-04-15 10:57 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-21 16:28 . 2011-05-14 11:16 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-05 05:32 . 2012-12-03 14:26 9694160 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-08-02 01:48 . 2013-09-12 22:23 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-14 05:35 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-14 05:35 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-14 05:37 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-14 05:37 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-14 05:39 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-14 05:35 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-14 05:39 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-14 05:39 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-14 05:39 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-14 05:35 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-14 05:39 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-14 05:39 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-14 05:39 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 05:39 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-14 05:34 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{4ae0c3d6-f713-4eed-bc65-25dc3ffdaac1}"= "c:\program files (x86)\uTorrentBar_IT\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{4ae0c3d6-f713-4eed-bc65-25dc3ffdaac1}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}]
2010-10-18 11:26 3908192 ----a-w- c:\program files (x86)\MAX_IT_Atube\tbMAX_.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-09-12 14:02 3863136 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{4ae0c3d6-f713-4eed-bc65-25dc3ffdaac1}]
2011-05-09 09:49 176936 ----a-w- c:\program files (x86)\uTorrentBar_IT\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
2013-01-23 12:24 247704 ----a-w- c:\program files (x86)\Delta\delta\1.8.10.0\bh\delta.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-02-01 17:17 1487240 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{e3393495-8103-46a0-8181-270273eddd60}]
2010-06-03 16:24 2736736 ----a-w- c:\program files (x86)\Softonic-IT\tbSoft.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-05-16 18:37 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}]
2013-08-21 17:36 100336 ----a-w- c:\program files (x86)\BonanzaDeals\BonanzaDealsIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\program files (x86)\Softonic-IT\tbSoft.dll" [2010-06-03 2736736]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-09-12 3863136]
"{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}"= "c:\program files (x86)\MAX_IT_Atube\tbMAX_.dll" [2010-10-18 3908192]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
"{4ae0c3d6-f713-4eed-bc65-25dc3ffdaac1}"= "c:\program files (x86)\uTorrentBar_IT\prxtbuTor.dll" [2011-05-09 176936]
"{82E1477C-B154-48D3-9891-33D83C26BCD3}"= "c:\program files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll" [2013-01-23 321944]
.
[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{0e9c9453-038b-4c2d-999d-21e0d2aa7ce5}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{4ae0c3d6-f713-4eed-bc65-25dc3ffdaac1}]
.
[HKEY_CLASSES_ROOT\clsid\{82e1477c-b154-48d3-9891-33d83c26bcd3}]
[HKEY_CLASSES_ROOT\delta.deltadskBnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
[HKEY_CLASSES_ROOT\delta.deltadskBnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Matteo\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-16 138096]
"Spotify Web Helper"="c:\users\Matteo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-07-09 1104384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl8"="c:\program files (x86)\ASUSTek\ASUSDVD 8\PDVD8Serv.exe" [2009-04-16 91432]
"PDVD8LanguageShortcut"="c:\program files (x86)\ASUSTek\ASUSDVD 8\Language\Language.exe" [2009-04-16 50472]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-07-13 2244096]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-04-20 159744]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Nikon Transfer Monitor"="c:\program files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe" [2009-02-24 479232]
"4StoryPrePatch"="c:\program files (x86)\Gameforge4D\4Story\PrePatch.exe" [2010-08-31 319488]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-08-16 152392]
.
c:\users\Matteo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2009-10-09 20:58 72248 ----a-w- c:\windows\AsScrProlog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2009-10-09 20:58 3054136 ----a-w- c:\windows\AsScrPro.exe
.
R2 bonanzadealslive;Servizio BonanzaDealsLive (bonanzadealslive);c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe;c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
R3 bonanzadealslivem;Servizio BonanzaDealsLive (bonanzadealslivem);c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe;c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys;c:\windows\SYSNATIVE\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys;c:\windows\SYSNATIVE\Drivers\TFsExDisk.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys;c:\program files\ATKGFNEX\ASMMAP64.sys [x]
S2 BitGuard;BitGuard;c:\programdata\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe;c:\programdata\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [x]
S2 FastBootAgent;FastBootAgent;c:\windows\SysWOW64\Fast Boot\FastBootAgent.exe;c:\windows\SysWOW64\Fast Boot\FastBootAgent.exe [x]
S2 WajamUpdater;WajamUpdater;c:\program files (x86)\Wajam\Updater\WajamUpdater.exe;c:\program files (x86)\Wajam\Updater\WajamUpdater.exe [x]
S3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\DRIVERS\activhidsermini.sys;c:\windows\SYSNATIVE\DRIVERS\activhidsermini.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\DRIVERS\activmouse.sys;c:\windows\SYSNATIVE\DRIVERS\activmouse.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Altri Servizi/Drivers In Memoria ---
.
*NewlyCreated* - WS2IFSL
.
Contenuto della cartella 'Scheduled Tasks'
.
2013-09-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-21 16:28]
.
2013-09-22 c:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
- c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-09-22 15:12]
.
2013-09-22 c:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job
- c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-09-22 15:12]
.
2013-09-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3815279068-2318928426-3713527259-1000Core.job
- c:\users\Matteo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-10 08:41]
.
2013-09-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3815279068-2318928426-3713527259-1000UA.job
- c:\users\Matteo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-10 08:41]
.
2013-09-14 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3815279068-2318928426-3713527259-1003Core.job
- c:\users\Babbo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-05-23 22:35]
.
2013-09-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3815279068-2318928426-3713527259-1003UA.job
- c:\users\Babbo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-05-23 22:35]
.
2013-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3815279068-2318928426-3713527259-1000Core.job
- c:\users\Matteo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-15 16:16]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3815279068-2318928426-3713527259-1000UA.job
- c:\users\Matteo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-15 16:16]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3815279068-2318928426-3713527259-1003Core.job
- c:\users\Babbo\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-20 11:42]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3815279068-2318928426-3713527259-1003UA.job
- c:\users\Babbo\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-20 11:42]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-06-12 619392]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 2184520]
"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"ActivControl"="c:\program files\Activ Software\Activdriver\ActivControl2x64.exe" [2009-04-03 1237504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 415256]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST9500325AS_5VE4KYZWXXXX5VE4KYZW&ts=1379877212
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST9500325AS_5VE4KYZWXXXX5VE4KYZW&ts=1379877212
mStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST9500325AS_5VE4KYZWXXXX5VE4KYZW&ts=1379877212
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = ${URL_SEARCHPAGE}
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\
FF - prefs.js: browser.search.selectedEngine - qvo6
FF - prefs.js: browser.startup.homepage - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST9500325AS_5VE4KYZWXXXX5VE4KYZW&ts=1379862855
FF - ExtSQL: 2013-08-02 17:20;
ffxtlbr@babylon.com; c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\ffxtlbr@babylon.com
FF - ExtSQL: 2013-09-22 17:12; {f9d03c26-0575-497e-821d-f7956d23e0ca}; c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}
FF - ExtSQL: 2013-09-22 17:12; {5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}; c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}
FF - ExtSQL: !HIDDEN! 2013-03-06 14:50;
psydmu-aq@ayia-ywvip.com; c:\users\Matteo\AppData\Roaming\Mozilla\Firefox\Profiles\c7xf2w88.default\extensions\psydmu-aq@ayia-ywvip.com
FF - ExtSQL: !HIDDEN! 2013-05-02 21:21; {5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}; c:\program files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
FF - user.js: extensions.BabylonToolbar_i.id - 7883a1c20000000000001a4bd635998d
FF - user.js: extensions.BabylonToolbar_i.hardId - 7883a1c20000000000001a4bd635998d
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15310
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1722:36
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=101293
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.funmoods.hmpg - false
FF - user.js: extensions.funmoods.hmpgUrl - hxxp://searchfunmoods.com/?f=1&a=stonicrio&chnl=stonicrio&cd=2XzuyEtN2Y1L1QzuzytD0EyC0B0AyC0Ezy0Azz0F0AtC0CtBtN0D0Tzu0CtAtCyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1916319824
FF - user.js: extensions.funmoods.dfltSrch - false
FF - user.js: extensions.funmoods.srchPrvdr - Search
FF - user.js: extensions.funmoods.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - false
FF - user.js: extensions.funmoods.newTabUrl - hxxp://searchfunmoods.com/?f=2&a=stonicrio&chnl=stonicrio&cd=2XzuyEtN2Y1L1QzuzytD0EyC0B0AyC0Ezy0Azz0F0AtC0CtBtN0D0Tzu0CtAtCyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1916319824
FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://searchfunmoods.com/?f=3&a=stonicrio&chnl=stonicrio&cd=2XzuyEtN2Y1L1QzuzytD0EyC0B0AyC0Ezy0Azz0F0AtC0CtBtN0D0Tzu0CtAtCyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1916319824&q=
FF - user.js: extensions.funmoods.id - 90E6BA6E9A8FA1C2
FF - user.js: extensions.funmoods.instlDay - 15656
FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2221:25
FF - user.js: extensions.funmoods.prtnrId - funmoods
FF - user.js: extensions.funmoods.prdct - funmoods
FF - user.js: extensions.funmoods.aflt - stonicrio
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods.tlbrId - base
FF - user.js: extensions.funmoods.instlRef - stonicrio
FF - user.js: extensions.funmoods.dfltLng -
FF - user.js: extensions.funmoods.excTlbr - false
FF - user.js: extensions.funmoods.autoRvrt - false
FF - user.js: extensions.funmoods.envrmnt - production
FF - user.js: extensions.funmoods.isdcmntcmplt - true
FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - 7883a1c20000000000001a4bd635998d
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15790
FF - user.js: extensions.delta.vrsn - 1.8.10.0
FF - user.js: extensions.delta.vrsni - 1.8.10.0
FF - user.js: extensions.delta.vrsnTs - 1.8.10.018:22
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
BHO-{6E13D095-45C3-4271-9475-F3B48227DD9F} - c:\program files (x86)\StartNow Toolbar\Toolbar32.dll
BHO-{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - c:\program files (x86)\Funmoods\1.5.23.22\bh\escort.dll
BHO-{DAF4D811-9561-09B8-6EA6-3380BF31925F} - c:\programdata\BBrroWse2seaveo\51374945e86bc.dll
Toolbar-Locked - (no file)
Toolbar-{5911488E-9D1E-40ec-8CBB-06B231CC153F} - c:\program files (x86)\StartNow Toolbar\Toolbar32.dll
Toolbar-{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - c:\program files (x86)\Funmoods\1.5.23.22\escorTlbr.dll
Wow6432Node-HKCU-Run-PoService - (no file)
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKCU-Run-cacaoweb - c:\users\Matteo\AppData\Roaming\cacaoweb\cacaoweb.exe
Wow6432Node-HKCU-Run-lollipop_08262026 - c:\users\matteo\appdata\local\lollipop\lollipop_08262026.exe
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
c:\users\Matteo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk - c:\users\Matteo\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-CLMLServer - c:\program files (x86)\Cyberlink\Power2Go\CLMLSvc.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
WebBrowser-{2C965F3F-8EFD-4BFC-A2C5-1672845FDBBF} - (no file)
WebBrowser-{E3393495-8103-46A0-8181-270273EDDD60} - (no file)
WebBrowser-{0E9C9453-038B-4C2D-999D-21E0D2AA7CE5} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
WebBrowser-{4AE0C3D6-F713-4EED-BC65-25DC3FFDAAC1} - (no file)
AddRemove-1ClickDownloader - c:\users\Matteo\Desktop\uninst.exe
AddRemove-DProtect - c:\users\Matteo\AppData\Local\DProtect\DPUninstall.exe
AddRemove-funmoods - c:\program files (x86)\Funmoods\1.5.23.22\uninstall.exe
AddRemove-StartNow Toolbar - c:\program files (x86)\StartNow Toolbar\StartNowToolbarUninstall.exe
AddRemove-{C3F3165C-74D3-6FDB-3274-14FDA8698CFA} - c:\programdata\BBrroWse2seaveo\uninstall.exe
AddRemove-GeoGebra 4 - c:\windows\system32\javaws.exe
AddRemove-lollipop_08262026 - c:\users\matteo\appdata\local\lollipop\lollipop_08262026.bat
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @
DenieD: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @
DenieD: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @
DenieD: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @
DenieD: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @
DenieD: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @
DenieD: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @
DenieD: (A) (Users) @
DenieD: (A) (Everyone) @
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @
DenieD: (Full) (Everyone)
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\SysWOW64\schtasks.exe
c:\program files (x86)\Canon\IJPLM\IJPLMSVC.EXE
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ATK Hotkey\WDC.exe
c:\program files\Activ Software\Activdriver\activmgr.exe
c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe
c:\program files (x86)\ASUS\ASUS Live Update\ALU.exe
.
**************************************************************************
.
Ora fine scansione: 2013-09-22 21:38:24 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2013-09-22 19:38
.
Pre-Run: 81.021.419.520 byte disponibili
Post-Run: 82.628.284.416 byte disponibili
.
- - End Of File - - 9D9CE1AE39DA08BCB8728FA9055413E9
5C616939100B85E558DA92B899A0FC36