ComboFix 12-02-29.01 - Alessio 02/03/2012 21.39.51.2.2 - x86Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.39.1040.18.2047.984 [GMT 1:00]
Eseguito da: C:\Users\Alessio\Desktop\abc.exe
Opzioni usate :: C:\Users\Alessio\Downloads\CFScript (1).txt
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
C:\Users\Alessio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Videos.url
C:\Users\Alessio\Favorites\Videos.url
C:\Users\Alessio\java.exe
C:\Windows\system32\drivers\etc\hosts.ics
((((((((((((((((((((((((( Files Creati Da 2012-02-02 al 2012-03-02 )))))))))))))))))))))))))))))))))))
2012-03-02 20:56:05 . 2012-03-02 21:12:13 -------- d-----w- C:\Users\Alessio\AppData\Local\temp
2012-03-02 20:56:05 . 2012-03-02 20:56:05 -------- d-----w- C:\Users\Default\AppData\Local\temp
2012-03-02 20:56:05 . 2012-03-02 20:56:05 -------- d-----w- C:\Users\Administrator\AppData\Local\temp
2012-03-02 09:26:59 . 2012-02-08 06:03:00 6552120 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DF780576-F82E-4AE3-88F3-8F706F211C75}\mpengine.dll
2012-02-29 21:38:02 . 2012-02-29 22:14:47 -------- d-----w- C:\abc
2012-02-29 13:16:29 . 2012-02-29 13:16:29 -------- d-----w- C:\Program Files\LogMeIn Hamachi
2012-02-28 21:55:37 . 2012-02-28 21:55:37 159744 ----a-w- C:\Program Files\Internet Explorer\Plugin\npqtplugin7.dll
2012-02-28 21:55:37 . 2012-02-28 21:55:37 159744 ----a-w- C:\Program Files\Internet Explorer\Plugin\npqtplugin6.dll
2012-02-28 21:55:37 . 2012-02-28 21:55:37 159744 ----a-w- C:\Program Files\Internet Explorer\Plugin\npqtplugin5.dll
2012-02-28 21:55:37 . 2012-02-28 21:55:36 159744 ----a-w- C:\Program Files\Internet Explorer\Plugin\npqtplugin4.dll
2012-02-28 21:55:37 . 2012-02-28 21:55:36 159744 ----a-w- C:\Program Files\Internet Explorer\Plugin\npqtplugin3.dll
2012-02-28 21:55:37 . 2012-02-28 21:55:36 159744 ----a-w- C:\Program Files\Internet Explorer\Plugin\npqtplugin2.dll
2012-02-28 21:55:37 . 2012-02-28 21:55:35 159744 ----a-w- C:\Program Files\Internet Explorer\Plugin\npqtplugin.dll
2012-02-27 11:16:27 . 2012-02-27 11:16:27 -------- d-----w- C:\Users\Alessio\AppData\Local\ADDP
2012-02-27 11:16:21 . 2012-02-27 11:17:06 -------- d-----w- C:\Users\Alessio\AppData\Local\Acer
2012-02-27 11:14:31 . 2012-02-28 16:14:33 -------- d-----w- C:\ProgramData\Acer
2012-02-27 11:11:47 . 2012-02-27 11:11:47 -------- d-----w- C:\Program Files\Acer
2012-02-27 11:02:04 . 2009-08-14 16:08:50 105984 ----a-w- C:\Windows\system32\drivers\qcusbser.sys
2012-02-27 11:02:03 . 2009-08-21 16:41:02 25728 ----a-w- C:\Windows\system32\drivers\androidusb.sys
2012-02-24 23:08:28 . 2012-02-26 20:30:10 -------- d-----w- C:\Users\Alessio\AppData\Roaming\gtk-2.0
2012-02-24 23:08:16 . 2012-02-24 23:08:16 -------- d-----w- C:\Users\Alessio\.thumbnails
2012-02-07 23:15:38 . 2012-02-08 21:40:21 -------- d-----w- C:\ProgramData\AVAST Software
2012-02-07 23:15:38 . 2012-02-07 23:15:38 -------- d-----w- C:\Program Files\AVAST Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
2012-02-22 13:26:07 . 2011-05-15 10:29:00 414368 ----a-w- C:\Windows\system32\FlashPlayerCPLApp.cpl
2012-01-29 04:10:42 . 2010-02-05 16:19:59 237072 ------w- C:\Windows\system32\MpSigStub.exe
2011-12-07 17:22:16 . 2011-12-22 20:18:17 83360 ----a-w- C:\Windows\system32\LMIRfsClientNP.dll
2011-12-07 17:22:08 . 2011-12-22 20:18:27 52096 ----a-w- C:\Windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-12-07 17:22:00 . 2011-12-22 20:18:26 30592 ----a-w- C:\Windows\system32\LMIport.dll
2011-12-07 17:21:58 . 2011-12-22 20:18:04 87424 ----a-w- C:\Windows\system32\LMIinit.dll
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2009-04-10 21:28:04 1233920]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 13:30:30 249856]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-03 21:04:25 68856]
"Akamai NetSession Interface"="C:\Users\Alessio\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 01:44:30 3329824]
"Acer AnySync"="C:\Program Files\Acer\AcerSync\AcerSync.exe" [2011-06-16 16:03:34 3044456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 09:07:16 4390912]
"Acer Empowering Technology Monitor"="C:\Acer\Empowering Technology\SysMonitor.exe" [2007-01-24 09:27:50 319488]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 23:04:16 464168]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30:30 81920]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 20:34:40 49152]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-04-12 15:07:00 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-04-12 15:07:00 8429568]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-04-12 15:07:00 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2012-01-16 16:22:12 421736]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2009-11-30 10:01:45 198160]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 22:15:02 202296]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2011-07-05 16:36:48 421888]
"LogMeIn Hamachi Ui"="C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 16:38:56 1987976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39:08 151552]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 21:11:46 3872080]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-1-12 528384]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:5704dae8b
[HKLM\~\startupfolder\C:^Users^Alessio^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Ritaglio schermata e avvio di OneNote 2007.lnk]
path=C:\Users\Alessio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ritaglio schermata e avvio di OneNote 2007.lnk
backup=C:\Windows\pss\Ritaglio schermata e avvio di OneNote 2007.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Heck Aim]
C:\ProgramData\five byte byte.r11hu [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LESS CITY AMEN SETUP]
C:\ProgramData\Mags Bags Owns.j5mov [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
2007-02-15 17:39:08 151552 ----a-w- C:\Acer\AcerTour\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-04-13 00:29:02 47392 ----a-w- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-11-01 22:25:58 59240 ----a-w- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-08-02 07:33:30 4910912 ----a-w- C:\Program Files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GM4IE]
2006-07-23 08:32:16 61440 ----a-w- C:\Program Files\SocialPlus\gm4ie.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-01-16 16:22:12 421736 ----a-w- C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2011-09-16 13:10:50 63048 ----a-w- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2012-02-28 16:38:56 1987976 ----a-w- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-16 21:11:46 3872080 ----a-w- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
2008-06-17 14:00:34 1249280 ----a-w- C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2008-06-18 12:31:00 1122816 ----a-w- C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-01-12 20:24:58 151552 ------w- C:\Acer\Empowering Technology\eMode\PCM\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSPAP]
2007-02-02 10:30:34 2990080 ----a-w- C:\Program Files\Thrustmaster\FunAccess\PSPAP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-11-30 10:01:45 198160 ----a-w- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
2006-11-05 19:48:22 57344 ----a-w- C:\Acer\WR_PopUp\WarReg_PopUp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38:38 1008184 ----a-w- C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WPCUMI]
2006-11-02 12:34:44 176128 ----a-w- C:\Windows\System32\wpcumi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
S2 AcerSyncSystemService;AcerSyncSystemService;C:\Program Files\Acer\AcerSync\AcerSyncSystemService.exe [2011-06-16 16:59:14 60312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Contenuto della cartella 'Scheduled Tasks'
2012-03-02 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-11 20:40:09 . 2009-05-11 20:39:50]
2012-03-02 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-11 20:40:09 . 2009-05-11 20:39:50]
2012-03-02 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786955474-3549510060-3803283922-1000Core.job
- C:\Users\Alessio\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-25 22:37:11 . 2011-10-18 21:28:57]
2012-03-02 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786955474-3549510060-3803283922-1000UA.job
- C:\Users\Alessio\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-25 22:37:11 . 2011-10-18 21:28:57]
2010-12-15 C:\Windows\Tasks\User_Feed_Synchronization-{35774BE7-2DE0-4C32-A470-2606B1CBB571}.job
- C:\Windows\system32\msfeedssync.exe [2012-02-19 15:21:04 . 2011-12-15 04:44:22]
------- Scansione supplementare -------
uStart Page = hxxp://www.google.it/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://home.sweetim.com
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: &SHOUTcast Search - C:\ProgramData\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: Aggiungi ad Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
IE: E&sporta in Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: C:\Windows\system32\wpclsp.dll
- - - - CHIAVI ORFANE RIMOSSE - - - -
BHO-{08d495ab-a86c-47b0-82ef-da87bf92f730} - (no file)
BHO-{9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
Toolbar-{9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
Toolbar-{08d495ab-a86c-47b0-82ef-da87bf92f730} - (no file)
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
WebBrowser-{9565115D-C7D6-46D3-BD63-B67B481A4368} - (no file)
WebBrowser-{08D495AB-A86C-47B0-82EF-DA87BF92F730} - (no file)