DOMANDA Problema: il PC non esegue più le applicazioni che riguardano il ripristino

sca1965

Nuovo Utente
3
0
Sono i difficolta con il PC succede una cosa strana: quando vado ad eseguire programmi che riguardano il controllo del sistema il ripristino della configurazione o comunque qualsiasi app. che controlli o i programmi antivirus risultano disattivati o impieghi la memoria interna del PC queste si bloccano (vedi es. file jpg allegato), per questo motivo ho fatto controllo con l'app. Combofix (file allegato combofix.txt). Se qualche buona anima mi aiuta a risolvere questo problema mi farebbe un grosso piacere, anche perché questo PC lo uso quotidianamente per il mio lavoro d'ufficio.

Grazie
Fabio Tortoioli


ComboFix 12-12-14.01 - f.tortoioli 17/12/2012 8.48.00.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3071.2343 [GMT 1:00]
Eseguito da: c:\documents and settings\f.tortoioli\desktop\abc.exe
Opzioni usate :: /killall
AV: ESET NOD32 antivirus system 2.70 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: McAfee VirusScan Enterprise+AntiSpyware Enterprise *Disabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
* Creato nuovo punto di ripristino
* Resident AV is active
.
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\952670046D.sys
c:\documents and settings\All Users\Dati applicazioni\TEMP
c:\documents and settings\F.Tortoioli\Dati applicazioni\OfferBox
c:\documents and settings\F.Tortoioli\Dati applicazioni\OfferBox\config.xml
c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\109.tmp
c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\18.tmp
c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\235.tmp
c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\4E.tmp
c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\5E.tmp
c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\6F.tmp
c:\documents and settings\F.Tortoioli\WINDOWS
c:\documents and settings\Fabio\Dati applicazioni\PriceGong
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\1.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\a.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\b.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\c.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\d.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\e.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\f.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\g.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\h.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\i.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\j.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\k.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\l.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\m.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\mru.xml
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\n.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\o.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\p.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\q.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\r.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\s.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\t.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\u.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\v.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\w.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\wlu.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\x.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\y.txt
c:\documents and settings\Fabio\Dati applicazioni\PriceGong\Data\z.txt
c:\documents and settings\Fabio\Dati applicazioni\Toolbar4
c:\documents and settings\Fabio\Impostazioni locali\Dati applicazioni\138.tmp
c:\documents and settings\Fabio\Impostazioni locali\Dati applicazioni\143.tmp
c:\documents and settings\l.fedelini\Dati applicazioni\OfferBox
c:\documents and settings\l.fedelini\Dati applicazioni\OfferBox\config.dat
c:\documents and settings\l.fedelini\Dati applicazioni\OfferBox\config.xml
c:\programmi\smartdl
c:\programmi\smartdl\header.bmp
c:\programmi\smartdl\header2.bmp
c:\programmi\smartdl\header3.bmp
c:\programmi\smartdl\installid
c:\programmi\smartdl\next.bmp
c:\programmi\smartdl\skip.bmp
c:\windows\IsUn0410.exe
c:\windows\system32\DIASUninst.ini
c:\windows\system32\SET51.tmp
c:\windows\system32\SET56.tmp
c:\windows\system32\SET5D.tmp
c:\windows\system32\SET66.tmp
c:\windows\system32\SET67.tmp
c:\windows\system32\SET68.tmp
c:\windows\system32\SET6B.tmp
c:\windows\system32\SET97.tmp
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\Tasks\pwyegjup.job
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SYSDRV32
.
.
((((((((((((((((((((((((( Files Creati Da 2012-11-17 al 2012-12-17 )))))))))))))))))))))))))))))))))))
.
.
2012-12-14 09:55 . 2012-12-14 09:55 14664 ----a-w- c:\windows\stinger.sys
2012-12-14 09:54 . 2012-12-14 11:09 -------- d-----w- c:\programmi\stinger
2012-12-14 09:43 . 2012-11-19 00:04 6812136 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Microsoft\Microsoft Antimalware\Definition Updates\{032D8CDA-2187-4E09-986F-4FB1A068185F}\mpengine.dll
2012-12-14 09:43 . 2012-05-31 10:25 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-12-14 09:33 . 2012-12-14 09:33 -------- d-----w- c:\programmi\Microsoft Security Client
2012-12-13 11:44 . 2012-12-13 11:44 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2012-12-12 12:42 . 2012-12-12 12:42 -------- d-----w- c:\programmi\Electronic Arts
2012-12-12 12:42 . 2012-12-12 12:42 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Electronic Arts
2012-12-07 12:33 . 2012-12-07 12:33 -------- d-----w- c:\documents and settings\g.cristofori
2012-12-06 11:40 . 2011-11-04 19:13 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-12-06 11:40 . 2011-11-04 19:13 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-12-06 11:40 . 2011-11-04 19:13 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2012-12-06 11:40 . 2011-11-04 19:13 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2012-12-06 11:40 . 2011-11-04 19:13 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-12-06 11:40 . 2011-11-04 19:13 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-12-06 11:40 . 2011-11-04 19:13 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2012-12-06 11:00 . 2012-12-06 11:00 -------- d-----w- c:\documents and settings\e.varani\Impostazioni locali\Dati applicazioni\McAfee
2012-12-06 10:59 . 2012-12-06 10:59 -------- d-----w- c:\documents and settings\s.digennaro
2012-12-06 07:44 . 2012-12-06 07:44 -------- d-----w- c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\PCHealth
2012-12-05 10:27 . 2012-12-05 10:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Mobile Partner
2012-12-05 10:27 . 2012-12-05 10:26 28672 ----a-w- c:\windows\system32\drivers\usbccid.sys
2012-12-05 10:27 . 2012-12-05 10:26 90368 ----a-w- c:\windows\system32\drivers\ew_jucdcacm.sys
2012-12-05 10:27 . 2012-12-05 10:26 73216 ----a-w- c:\windows\system32\drivers\ew_jubusenum.sys
2012-12-05 10:27 . 2012-12-05 10:26 64384 ----a-w- c:\windows\system32\drivers\ew_jucdcecm.sys
2012-12-05 10:27 . 2012-12-05 10:26 26624 ----a-w- c:\windows\system32\drivers\ew_juextctrl.sys
2012-12-05 10:27 . 2012-12-05 10:26 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2012-12-05 10:27 . 2012-12-05 10:26 1112288 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01007.dll
2012-12-05 10:27 . 2012-12-05 10:26 861696 ----a-w- c:\windows\system32\drivers\mod7700.sys
2012-12-05 10:27 . 2012-12-05 10:26 11136 ----a-w- c:\windows\system32\drivers\ew_usbenumfilter.sys
2012-12-05 10:27 . 2012-12-05 10:26 102784 ----a-w- c:\windows\system32\drivers\ew_hwusbdev.sys
2012-12-05 10:27 . 2012-12-05 10:26 19200 ----a-w- c:\windows\system32\drivers\ew_hwupgrade.sys
2012-12-05 10:26 . 2012-12-05 10:28 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DatacardService
2012-12-04 08:08 . 2012-12-05 10:26 25856 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2012-12-04 08:08 . 2012-12-05 10:26 235392 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2012-12-04 08:08 . 2012-12-05 10:26 194816 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2012-12-04 08:07 . 2012-12-04 08:10 -------- d-----w- c:\programmi\Chiavetta Internet
2012-11-29 10:03 . 2012-11-29 10:03 -------- d-----w- c:\programmi\WinPcap
2012-11-29 10:03 . 2012-11-29 10:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Freemake
2012-11-29 10:02 . 2012-11-29 10:03 -------- d-----w- c:\programmi\Freemake
2012-11-29 09:10 . 2012-11-29 10:13 -------- d-----w- c:\programmi\TubeMaster++
2012-11-20 17:39 . 2009-03-04 16:30 709248 ----a-w- c:\windows\system32\drivers\rt2870.sys
2012-11-20 17:39 . 2009-03-04 16:23 221184 ----a-w- c:\windows\system32\RaCoInst.dll
2012-11-20 17:39 . 2012-11-20 17:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Ralink Driver
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-14 09:54 . 2012-05-31 09:15 87656 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2012-11-13 11:55 . 2004-08-19 15:31 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 00:41 . 2004-08-19 15:37 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-02 02:02 . 2004-08-19 15:39 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-10-02 18:04 . 2004-08-19 15:39 58368 ----a-w- c:\windows\system32\synceng.dll
2012-12-14 17:03 . 2012-12-14 17:03 262112 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-10-05 . 1DBD3966123AC2F6ADE783F7F17F8C7F . 504832 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesHelper"="c:\programmi\Samsung\Kies\KiesHelper.exe" [2011-12-27 937360]
"KiesPDLR"="c:\programmi\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-12-27 21392]
"Advanced SystemCare 6"="c:\programmi\IObit\Advanced SystemCare 6\ASCTray.exe" [2012-09-24 490880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="c:\programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"McAfeeUpdaterUI"="c:\programmi\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"KiesTrayAgent"="c:\programmi\Samsung\Kies\KiesTrayAgent.exe" [2011-12-27 3508624]
"ShStatEXE"="c:\programmi\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2011-09-14 215360]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-09-17 254896]
"McAfee NAC Tray Icon"="c:\programmi\McAfee\MNAC Scanner\ScannerTray.exe" [2012-07-02 407144]
"MSC"="c:\programmi\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"pcsmig"="c:\programmi\IBM\Personal Communications\pcsmig.exe" [2001-08-21 126976]
.
c:\documents and settings\Administrator\Menu Avvio\Programmi\Esecuzione automatica\
Collegamento a shstat.lnk - c:\programmi\McAfee\VirusScan Enterprise\shstat.exe [2011-9-14 215360]
.
c:\documents and settings\Fabio\Menu Avvio\Programmi\Esecuzione automatica\
Dropbox.lnk - c:\documents and settings\F.Tortoioli\Dati applicazioni\Dropbox\bin\Dropbox.exe [N/A]
.
c:\documents and settings\Sis-Rete\Menu Avvio\Programmi\Esecuzione automatica\
DW_Start.lnk - c:\windows\system32\rwwnw64d.exe [N/A]
.
c:\documents and settings\assistenza.OLIDATA-VIMPZ\Menu Avvio\Programmi\Esecuzione automatica\
Deewoo.lnk - c:\windows\system32\lcntktdl.exe [N/A]
DW_Start.lnk - c:\windows\system32\rpwnw64k.exe [N/A]
.
c:\documents and settings\F.Tortoioli\Menu Avvio\Programmi\Esecuzione automatica\
StripSaver2.lnk - c:\programmi\StripSaver2\StripSaver2.exe [2011-8-14 4255744]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\LMabcoms.exE"=
"c:\\Programmi\\Imperivm Anthology\\Imperivm III\\gbr.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\CheckPoint\\SSL Network Extender\\slimsvc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/03/2010 13.30.10 691696]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [31/05/2012 10.15.32 90368]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\programmi\IObit\Advanced SystemCare 6\ASCService.exe [05/12/2012 12.16.28 464256]
R2 cpextender;Check Point SSL Network Extender;c:\programmi\CheckPoint\SSL Network Extender\slimsvc.exe [12/04/2011 14.49.08 353800]
R2 HWDeviceService.exe;HWDeviceService.exe;c:\documents and settings\All Users\Dati applicazioni\DatacardService\HWDeviceService.exe [14/03/2011 16.27.28 271712]
R2 mfefire;McAfee Firewall Core Service;c:\programmi\File comuni\McAfee\SystemCore\mfefire.exe [22/10/2012 10.02.03 163200]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [31/05/2012 10.15.31 159640]
R2 NACClient;McAfee Network Access Control Client;c:\programmi\McAfee\MNAC Scanner\NACScanner.exe [02/07/2012 22.42.16 1918568]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/02/2011 22.23.34 35088]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\programmi\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [30/11/2010 16.20.18 1483072]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [05/12/2012 11.27.20 73216]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [22/10/2012 10.01.38 348880]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [22/10/2012 10.01.41 83920]
R3 onda_mx83xup_dc_enum;ONDA Mx83xUP DC Enumerator;c:\windows\system32\drivers\onda_mx83xup_dc_enum.sys [13/05/2010 13.54.16 67200]
R3 Pcouffin;Low level access layer for CD devices;c:\windows\system32\drivers\Pcouffin.sys [02/12/2008 14.46.05 47616]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\programmi\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [07/10/2010 12.34.32 10064]
R3 VNA;Check Point Virtual Network Adapter;c:\windows\system32\drivers\vna.sys [10/06/2007 15.48.02 129304]
S0 a347scsi;a347scsi;c:\windows\system32\Drivers\a347scsi.sys --> c:\windows\system32\Drivers\a347scsi.sys [?]
S1 e9d6b5aa;e9d6b5aa;c:\windows\system32\drivers\e9d6b5aa.sys --> c:\windows\system32\drivers\e9d6b5aa.sys [?]
S1 fcf1e5a7;fcf1e5a7;c:\windows\system32\drivers\fcf1e5a7.sys [30/01/2009 12.53.02 0]
S2 Mobile Partner. RunOuc;Mobile Partner. OUC;c:\programmi\Mobile Partner\UpdateDog\ouc.exe [05/12/2012 11.27.03 246112]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [30/01/2012 11.28.56 30312]
S3 EAGLE2RC;Analog/DVB-T Hybrid Tv Infrared Receiver;c:\windows\system32\DRIVERS\Eagle2RC.sys --> c:\windows\system32\DRIVERS\Eagle2RC.sys [?]
S3 Eagle2TV;TV tuner device;c:\windows\system32\Drivers\eagle2tv_B.sys --> c:\windows\system32\Drivers\eagle2tv_B.sys [?]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [05/12/2012 11.27.19 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [05/12/2012 11.27.19 11136]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [04/12/2012 9.08.02 235392]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys --> c:\windows\system32\DRIVERS\ewusbfake.sys [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [22/10/2012 10.01.41 83920]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [31/05/2012 10.15.41 87656]
S3 onda_mx83xup_cdc_acm;ONDA Mx83xUP CDC-ACM driver;c:\windows\system32\drivers\onda_mx83xup_cdc_acm.sys [13/05/2010 13.54.18 70400]
S3 onda_mx83xup_cpo;ONDA Mx83xUP Mass Storage Device;c:\windows\system32\drivers\onda_mx83xup_cpo.sys [13/05/2010 13.54.18 9728]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [10/12/2009 11.44.15 335104]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [30/01/2012 11.28.55 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [30/01/2012 11.28.56 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [30/01/2012 11.28.56 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [30/01/2012 11.28.57 114280]
S4 FreemakeVideoCapture;FreemakeVideoCapture;c:\programmi\Freemake\CaptureLib\CaptureLibService.exe [29/11/2012 11.03.08 8704]
.
--- Altri Servizi/Drivers In Memoria ---
.
*Deregistered* - mfeavfk01
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-983971780-233310153-1287535205-17785Core1cab915ac37f7a2.job
- c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-02-10 10:49]
.
2012-12-17 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\programmi\Microsoft Security Client\MpCmdRun.exe [2012-09-12 16:25]
.
2012-12-17 c:\windows\Tasks\MpIdleTask.job
- c:\programmi\Microsoft Security Client\MpCmdRun.exe [2012-09-12 16:25]
.
.
------- Scansione supplementare -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = proxymds.sanita.it:8080
uInternet Settings,ProxyOverride = <local>
IE: &Point&&Go - c:\programmi\File comuni\Expert System\PGPlatform\PGPlatform.htm
IE: Add to AMV Converter... - c:\programmi\MP3 Player Utilities 4.05\AMVConverter\grab.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\programmi\MP3 Player Utilities 4.05\MediaManager\grab.html
IE: Salva oggetto con Star Downloader - c:\programmi\Star Downloader\sdie.htm
IE: Scarica link utilizzando Mega Manager...
Trusted Zone: carabinieri.it\retewebopz.rete.arma
Trusted Zone: carabinieri.it\vpn
Trusted Zone: interno.it\sii.cedinterforze
Trusted Zone: carabinieri.it\retewebopz.rete.arma
Trusted Zone: carabinieri.it\vpn
TCP: DhcpNameServer = 10.176.10.225 10.176.10.226
DPF: {414FB93D-DEDD-4FEF-AD7F-167992EBDB52} - hxxps://vpn.carabinieri.it/SNX/CSHELL/extender.cab
DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxps://vpn.carabinieri.it/sre/ICSScanner.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\F.Tortoioli\Dati applicazioni\Mozilla\Firefox\Profiles\f6uzbh9s.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: network.proxy.ftp - proxymds.sanita.it
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - proxy.sanita.it
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - proxymds.sanita.it
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxymds.sanita.it
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxymds.sanita.it
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 1
FF - ExtSQL: 2012-10-18 12:41; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF - ExtSQL: 2012-11-29 11:03; fmdownloader@gmail.com; c:\programmi\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF - ExtSQL: 2012-11-29 11:03; ytfmdownloader@gmail.com; c:\programmi\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=111798&tt=3012_6
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 3c90da6c000000000000544f60e9620a
FF - user.js: extensions.BabylonToolbar_i.hardId - 3c90da6c000000000000544f60e9620a
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15544
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.178:23
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
------- Associazioni dei file -------
.
JSEFile=NOTEPAD.EXE %1
.txt=
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
SafeBoot-SVCWINSPOOL
AddRemove-Microsoft Interactive Training - c:\windows\IsUn0410.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-12-17 08:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-983971780-233310153-1287535205-17785\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{13E24795-78EE-4B52-EF91-6B4229ED7FA0}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode)
"jabipfcpijimdchjiidf"=hex:6f,61,6a,6b,63,67,62,6f,6f,63,6e,6e,67,63,6f,63,6b,
6f,63,66,68,69,63,66,6f,6e,6d,6e,66,6b,00,ff
.
[HKEY_USERS\S-1-5-21-983971780-233310153-1287535205-17785\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7DE86B24-6665-5D15-2466-0697A5C566F0}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode)
"oabmhjpkeknpjeeaepkabojobdnkhj"=hex:64,61,65,6f,6a,6f,6d,61,00,85
"oafjhgjdhabhicgkohmnfpofnbfgho"=hex:6a,61,65,6f,64,6f,6a,64,65,64,68,67,69,64,
61,64,6c,65,66,6f,00,07
"napjfiiepkoccihlnllgmdolmonl"=hex:6a,61,62,6f,6a,70,67,66,68,67,6c,68,62,63,
65,67,6b,6c,63,68,00,07
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="1809B4F094A1C0D14B9FC94F1096C3FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C8EDD5E5BE2F6E6678901F07F589925C543F44B76CD5E46EAB0A9DCBA915F4D63A32722800BE6DA3E1AF1F9E7A9B5853F3AB4A86A9ED1613CCE307398ACA4213BDD0BC1237EEF47E8C8E8D4BC0F0BE1DDFE5115C12AF359B2406BDA36713151E2707FE4137C021284FA5941E27CDB8C483F685C2C7B3F64521BBA9431A65492DD794A5E792561912FF48D80AF89029BD889E5D5CEC340F8D358D3A31CB3EFDEDFFA0384F6BB64E1B9E424D9F172686B1ED30DD6C3D918D221D53C11FD287A73515B182F9E26F65EA9D70E976997109B5AF4763B17B37CF2DAD4506A4FB57D50CD66C83EF57096AB39C3908849FB8D0E84AA8B63C9F0B51ED3F9C040FD33173A27C72A9179C8D92D557EC700394788EAC6150B33D15123DA93D09026ED987ABB6293240F1701E4909F429E535547BD9C7FB8089197B834F6D54417B573856D2237BFF521B312F4416D31585EAEE8FCD2C17CE96A77B16E018A26028B59BA4AFC11A7AD34A4965871494D0A7EC843AB01D4AE6A2DC368EB4E542ECEC75D1FFE229188323CB44CF21A6FFD1F171B8CBF5DB0FE184EBF2ED9F58B72520FB13C8F2C0E85BAABA4963C71D28E5310129FC8628602D7C4A7F67855BBF2B48AFBBE8FF68D24D5FE257C3EF797AE3A520EFEE35137AFDD0CA45C9E8CA38F70E6577A2BA24D50E2B260A819EF9771384CE3CC47ACD9E536A35A9BB3FE370FD654506420963DD716C86E6A005F60CF08F1D851B9BA39E2BE10DC9436549E998A08E99641F9036B79455FB4BA8F34A2B5B9AB789987D3CB2C59354EB6F9333D04B919CEF23C77A3E9B4B69E248E082AA59D0B5255E15C2A0489E06EDB9F08EA0F2749EEB18BA4F997A26AE12BAF058B8B1C1C92F1DCB768A031D0445D3ADD784B11D7FC8BDECD4D87A167DD538889CB7239F49008508258B1E3E9C08A7F2D1FAB3B97A2A0EFE5DF12468A17B3F2A6D737F9234AC3D50BAEB9B904F642EE21FBF86DCC2FA93B965764AAA7B1F70EA1FD8CEA27DCE44DD1838ECD6EA1F9469A11CF76B31270803ABEFE6E07FA5FBAF4F2F619F30EBFDB8F51DCBFE79C3D892A431D26F76252C76406B730E1E0BC204DCDD09671C5BDE4AD7B21B3286928031A5C27D0BD5BC1D7577C3617E77577270C08C9FB7B0ED917CBC430D0D52D6ABCE50A06CF99D8C53F8CD9F7CCBC718C7FC704E0E3E399A4DF3B5630C28E30CB883C5C237F16DD78CD30B94C7F76AE881BC883EBEAEC39417103BB9B39E35F24F700C9BF40B1900898A298595F202C8F2F0D2E17B5CEE7EA455E6540E7DACA61E6C8ACEFF5DC39B57BF8DA1822398C5AB5460F"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(6076)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\programmi\McAfee\Common Framework\McTrayLegacySupportPlugin.dll
c:\programmi\McAfee\Common Framework\McTrayInterfaceLib.dll
c:\programmi\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\programmi\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\IVT Corporation\BlueSoleil\BTNtService.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\McAfee\Common Framework\FrameworkService.exe
c:\programmi\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\programmi\McAfee\VirusScan Enterprise\mfeann.exe
c:\documents and settings\All Users\Dati applicazioni\Mobile Partner\OnlineUpdate\ouc.exe
c:\programmi\McAfee\Common Framework\naPrdMgr.exe
c:\programmi\Nero\Nero8\Nero BackItUp\NBService.exe
c:\programmi\McAfee\MNAC Scanner\Engine\enginemain.exe
c:\windows\system32\IoctlSvc.exe
c:\programmi\File comuni\McAfee\SystemCore\mcshield.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\programmi\McAfee\Common Framework\McTray.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
.
**************************************************************************
.
Ora fine scansione: 2012-12-17 09:05:50 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-12-17 08:05
.
Pre-Run: 42.918.604.800 byte disponibili
Post-Run: 43.539.398.656 byte disponibili
.
- - End Of File - - 33AD4A1C615966D1F14CB93ACDA05452
 

tecnico24

Utente Èlite
10,706
1,072
Ciao e benvenuto.

Innanzitutto , avere tre antivirus comporta dei conflitti , se non il blocco totale del pc.
In ordine:
Disinstalla
Mcafee
Microsoft SE

Seconda operazione:
Disattiva il ripristino configurazione di sistema.
Start
tasto destro su Risorse del computer
proprietà
scheda Ripristino configurazione
Disattiva -> Applica -> OK.

terza operazione:
Vedo che Combofix ha eliminato un rootkit , ma il sistema è ancora infetto.
Scarica il file CFScript.txt che ti ho allegato qui in basso sul desktop
trascinalo nell'icona rossa di combofix
Attendi le operazioni e dopo il riavvio del pc posta il report che ti appare

quarta operazione:
Fai start
tutti i programmi
esecuzione automatica
Elimina tutto ciò che trovi facendo tasto destro -> elimina.
 

Allegati

  • CFScript.txt
    226 bytes · Visualizzazioni: 166

sca1965

Nuovo Utente
3
0
Hoeseguito la procedura decreitta e il prog. combofix mi ha dato questo report che posto.
Attualmente non è stato risolto nulla - le applicazioni che utilizzano la memotia (stile Tuneup 2011 etc.) non funzionano. Il sistema non mi fa disistallare Mcaffe agent.
Grazie dell'aiuto
Fabio Tortoioli

ComboFix 12-12-14.01 - f.tortoioli 18/12/2012 8.42.50.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.3071.2461 [GMT 1:00]
Eseguito da: c:\documents and settings\F.Tortoioli\Desktop\ABC.exe
Opzioni usate :: c:\documents and settings\F.Tortoioli\Desktop\CFScript.txt
AV: ESET NOD32 antivirus system 2.70 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
FILE ::
"c:\windows\system32\drivers\e9d6b5aa.sys"
"c:\windows\system32\drivers\fcf1e5a7.sys"
"c:\windows\system32\lcntktdl.exe"
"c:\windows\system32\rpwnw64k.exe"
"c:\windows\system32\rwwnw64d.exe"
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dati applicazioni\TEMP
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_e9d6b5aa
-------\Service_fcf1e5a7
.
.
((((((((((((((((((((((((( Files Creati Da 2012-11-18 al 2012-12-18 )))))))))))))))))))))))))))))))))))
.
.
2012-12-14 09:55 . 2012-12-14 09:55 14664 ----a-w- c:\windows\stinger.sys
2012-12-14 09:54 . 2012-12-14 11:09 -------- d-----w- c:\programmi\stinger
2012-12-14 09:43 . 2012-05-31 10:25 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-12-13 11:44 . 2012-12-13 11:44 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2012-12-12 12:42 . 2012-12-12 12:42 -------- d-----w- c:\programmi\Electronic Arts
2012-12-12 12:42 . 2012-12-12 12:42 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Electronic Arts
2012-12-07 12:33 . 2012-12-07 12:33 -------- d-----w- c:\documents and settings\g.cristofori
2012-12-06 11:40 . 2011-11-04 19:13 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-12-06 11:40 . 2011-11-04 19:13 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-12-06 11:40 . 2011-11-04 19:13 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2012-12-06 11:40 . 2011-11-04 19:13 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2012-12-06 11:40 . 2011-11-04 19:13 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-12-06 11:40 . 2011-11-04 19:13 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-12-06 11:40 . 2011-11-04 19:13 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2012-12-06 11:00 . 2012-12-06 11:00 -------- d-----w- c:\documents and settings\e.varani\Impostazioni locali\Dati applicazioni\McAfee
2012-12-06 10:59 . 2012-12-06 10:59 -------- d-----w- c:\documents and settings\s.digennaro
2012-12-06 07:44 . 2012-12-06 07:44 -------- d-----w- c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\PCHealth
2012-12-05 10:27 . 2012-12-05 10:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Mobile Partner
2012-12-05 10:27 . 2012-12-05 10:26 28672 ----a-w- c:\windows\system32\drivers\usbccid.sys
2012-12-05 10:27 . 2012-12-05 10:26 90368 ----a-w- c:\windows\system32\drivers\ew_jucdcacm.sys
2012-12-05 10:27 . 2012-12-05 10:26 73216 ----a-w- c:\windows\system32\drivers\ew_jubusenum.sys
2012-12-05 10:27 . 2012-12-05 10:26 64384 ----a-w- c:\windows\system32\drivers\ew_jucdcecm.sys
2012-12-05 10:27 . 2012-12-05 10:26 26624 ----a-w- c:\windows\system32\drivers\ew_juextctrl.sys
2012-12-05 10:27 . 2012-12-05 10:26 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2012-12-05 10:27 . 2012-12-05 10:26 1112288 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01007.dll
2012-12-05 10:27 . 2012-12-05 10:26 861696 ----a-w- c:\windows\system32\drivers\mod7700.sys
2012-12-05 10:27 . 2012-12-05 10:26 11136 ----a-w- c:\windows\system32\drivers\ew_usbenumfilter.sys
2012-12-05 10:27 . 2012-12-05 10:26 102784 ----a-w- c:\windows\system32\drivers\ew_hwusbdev.sys
2012-12-05 10:27 . 2012-12-05 10:26 19200 ----a-w- c:\windows\system32\drivers\ew_hwupgrade.sys
2012-12-05 10:26 . 2012-12-05 10:28 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DatacardService
2012-12-04 08:08 . 2012-12-05 10:26 25856 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2012-12-04 08:08 . 2012-12-05 10:26 235392 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2012-12-04 08:08 . 2012-12-05 10:26 194816 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2012-12-04 08:07 . 2012-12-04 08:10 -------- d-----w- c:\programmi\Chiavetta Internet
2012-11-29 10:03 . 2012-11-29 10:03 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Freemake
2012-11-29 10:02 . 2012-11-29 10:03 -------- d-----w- c:\programmi\Freemake
2012-11-29 09:10 . 2012-11-29 10:13 -------- d-----w- c:\programmi\TubeMaster++
2012-11-20 17:39 . 2009-03-04 16:30 709248 ----a-w- c:\windows\system32\drivers\rt2870.sys
2012-11-20 17:39 . 2009-03-04 16:23 221184 ----a-w- c:\windows\system32\RaCoInst.dll
2012-11-20 17:39 . 2012-11-20 17:39 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Ralink Driver
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-13 11:55 . 2004-08-19 15:31 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 00:41 . 2004-08-19 15:37 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-02 02:02 . 2004-08-19 15:39 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-10-02 18:04 . 2004-08-19 15:39 58368 ----a-w- c:\windows\system32\synceng.dll
2012-12-14 17:03 . 2012-12-14 17:03 262112 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-10-05 . 1DBD3966123AC2F6ADE783F7F17F8C7F . 504832 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesHelper"="c:\programmi\Samsung\Kies\KiesHelper.exe" [2011-12-27 937360]
"KiesPDLR"="c:\programmi\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-12-27 21392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="c:\programmi\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"McAfeeUpdaterUI"="c:\programmi\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"KiesTrayAgent"="c:\programmi\Samsung\Kies\KiesTrayAgent.exe" [2011-12-27 3508624]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2012-09-17 254896]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"pcsmig"="c:\programmi\IBM\Personal Communications\pcsmig.exe" [2001-08-21 126976]
.
c:\documents and settings\Administrator\Menu Avvio\Programmi\Esecuzione automatica\
Collegamento a shstat.lnk - c:\programmi\McAfee\VirusScan Enterprise\shstat.exe [N/A]
.
c:\documents and settings\Fabio\Menu Avvio\Programmi\Esecuzione automatica\
Dropbox.lnk - c:\documents and settings\F.Tortoioli\Dati applicazioni\Dropbox\bin\Dropbox.exe [N/A]
.
c:\documents and settings\Sis-Rete\Menu Avvio\Programmi\Esecuzione automatica\
DW_Start.lnk - c:\windows\system32\rwwnw64d.exe [N/A]
.
c:\documents and settings\assistenza.OLIDATA-VIMPZ\Menu Avvio\Programmi\Esecuzione automatica\
Deewoo.lnk - c:\windows\system32\lcntktdl.exe [N/A]
DW_Start.lnk - c:\windows\system32\rpwnw64k.exe [N/A]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="c:\programmi\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
"StartCCC"="c:\programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" -atboottime
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\LMabcoms.exE"=
"c:\\Programmi\\Imperivm Anthology\\Imperivm III\\gbr.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmi\\CheckPoint\\SSL Network Extender\\slimsvc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/03/2010 13.30.10 691696]
R2 cpextender;Check Point SSL Network Extender;c:\programmi\CheckPoint\SSL Network Extender\slimsvc.exe [12/04/2011 14.49.08 353800]
R2 HWDeviceService.exe;HWDeviceService.exe;c:\documents and settings\All Users\Dati applicazioni\DatacardService\HWDeviceService.exe [14/03/2011 16.27.28 271712]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\programmi\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [30/11/2010 16.20.18 1483072]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [05/12/2012 11.27.20 73216]
R3 onda_mx83xup_dc_enum;ONDA Mx83xUP DC Enumerator;c:\windows\system32\drivers\onda_mx83xup_dc_enum.sys [13/05/2010 13.54.16 67200]
R3 Pcouffin;Low level access layer for CD devices;c:\windows\system32\drivers\Pcouffin.sys [02/12/2008 14.46.05 47616]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\programmi\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [07/10/2010 12.34.32 10064]
R3 VNA;Check Point Virtual Network Adapter;c:\windows\system32\drivers\vna.sys [10/06/2007 15.48.02 129304]
S0 a347scsi;a347scsi;c:\windows\system32\Drivers\a347scsi.sys --> c:\windows\system32\Drivers\a347scsi.sys [?]
S2 Mobile Partner. RunOuc;Mobile Partner. OUC;c:\programmi\Mobile Partner\UpdateDog\ouc.exe [05/12/2012 11.27.03 246112]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [30/01/2012 11.28.56 30312]
S3 EAGLE2RC;Analog/DVB-T Hybrid Tv Infrared Receiver;c:\windows\system32\DRIVERS\Eagle2RC.sys --> c:\windows\system32\DRIVERS\Eagle2RC.sys [?]
S3 Eagle2TV;TV tuner device;c:\windows\system32\Drivers\eagle2tv_B.sys --> c:\windows\system32\Drivers\eagle2tv_B.sys [?]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [05/12/2012 11.27.19 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [05/12/2012 11.27.19 11136]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [04/12/2012 9.08.02 235392]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys --> c:\windows\system32\DRIVERS\ewusbfake.sys [?]
S3 onda_mx83xup_cdc_acm;ONDA Mx83xUP CDC-ACM driver;c:\windows\system32\drivers\onda_mx83xup_cdc_acm.sys [13/05/2010 13.54.18 70400]
S3 onda_mx83xup_cpo;ONDA Mx83xUP Mass Storage Device;c:\windows\system32\drivers\onda_mx83xup_cpo.sys [13/05/2010 13.54.18 9728]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [10/12/2009 11.44.15 335104]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [30/01/2012 11.28.55 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [30/01/2012 11.28.56 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [30/01/2012 11.28.56 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [30/01/2012 11.28.57 114280]
S4 FreemakeVideoCapture;FreemakeVideoCapture;c:\programmi\Freemake\CaptureLib\CaptureLibService.exe [29/11/2012 11.03.08 8704]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-983971780-233310153-1287535205-17785Core1cab915ac37f7a2.job
- c:\documents and settings\F.Tortoioli\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-02-10 10:49]
.
.
------- Scansione supplementare -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = proxymds.sanita.it:8080
uInternet Settings,ProxyOverride = <local>
IE: &Point&&Go - c:\programmi\File comuni\Expert System\PGPlatform\PGPlatform.htm
IE: Add to AMV Converter... - c:\programmi\MP3 Player Utilities 4.05\AMVConverter\grab.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\programmi\MP3 Player Utilities 4.05\MediaManager\grab.html
IE: Salva oggetto con Star Downloader - c:\programmi\Star Downloader\sdie.htm
IE: Scarica link utilizzando Mega Manager...
Trusted Zone: carabinieri.it\retewebopz.rete.arma
Trusted Zone: carabinieri.it\vpn
Trusted Zone: interno.it\sii.cedinterforze
Trusted Zone: carabinieri.it\retewebopz.rete.arma
Trusted Zone: carabinieri.it\vpn
DPF: {414FB93D-DEDD-4FEF-AD7F-167992EBDB52} - hxxps://vpn.carabinieri.it/SNX/CSHELL/extender.cab
DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxps://vpn.carabinieri.it/sre/ICSScanner.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\F.Tortoioli\Dati applicazioni\Mozilla\Firefox\Profiles\f6uzbh9s.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: network.proxy.ftp - proxymds.sanita.it
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - proxy.sanita.it
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - proxymds.sanita.it
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxymds.sanita.it
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxymds.sanita.it
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 1
FF - ExtSQL: 2012-10-18 12:41; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF - ExtSQL: 2012-11-29 11:03; fmdownloader@gmail.com; c:\programmi\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF - ExtSQL: 2012-11-29 11:03; ytfmdownloader@gmail.com; c:\programmi\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=111798&tt=3012_6
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 3c90da6c000000000000544f60e9620a
FF - user.js: extensions.BabylonToolbar_i.hardId - 3c90da6c000000000000544f60e9620a
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15544
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.178:23
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-12-18 08:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-983971780-233310153-1287535205-17785\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{13E24795-78EE-4B52-EF91-6B4229ED7FA0}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode)
"jabipfcpijimdchjiidf"=hex:6f,61,6a,6b,63,67,62,6f,6f,63,6e,6e,67,63,6f,63,6b,
6f,63,66,68,69,63,66,6f,6e,6d,6e,66,6b,00,ff
.
[HKEY_USERS\S-1-5-21-983971780-233310153-1287535205-17785\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7DE86B24-6665-5D15-2466-0697A5C566F0}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode)
"oabmhjpkeknpjeeaepkabojobdnkhj"=hex:64,61,65,6f,6a,6f,6d,61,00,85
"oafjhgjdhabhicgkohmnfpofnbfgho"=hex:6a,61,65,6f,64,6f,6a,64,65,64,68,67,69,64,
61,64,6c,65,66,6f,00,07
"napjfiiepkoccihlnllgmdolmonl"=hex:6a,61,62,6f,6a,70,67,66,68,67,6c,68,62,63,
65,67,6b,6c,63,68,00,07
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="1809B4F094A1C0D14B9FC94F1096C3FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C8EDD5E5BE2F6E6678901F07F589925C543F44B76CD5E46EAB0A9DCBA915F4D63A32722800BE6DA3E1AF1F9E7A9B5853F3AB4A86A9ED1613CCE307398ACA4213BDD0BC1237EEF47E8C8E8D4BC0F0BE1DDFE5115C12AF359B2406BDA36713151E2707FE4137C021284FA5941E27CDB8C483F685C2C7B3F64521BBA9431A65492DD794A5E792561912FF48D80AF89029BD889E5D5CEC340F8D358D3A31CB3EFDEDFFA0384F6BB64E1B9E424D9F172686B1ED30DD6C3D918D221D53C11FD287A73515B182F9E26F65EA9D70E976997109B5AF4763B17B37CF2DAD4506A4FB57D50CD66C83EF57096AB39C3908849FB8D0E84AA8B63C9F0B51ED3F9C040FD33173A27C72A9179C8D92D557EC700394788EAC6150B33D15123DA93D09026ED987ABB6293240F1701E4909F429E535547BD9C7FB8089197B834F6D54417B573856D2237BFF521B312F4416D31585EAEE8FCD2C17CE96A77B16E018A26028B59BA4AFC11A7AD34A4965871494D0A7EC843AB01D4AE6A2DC368EB4E542ECEC75D1FFE229188323CB44CF21A6FFD1F171B8CBF5DB0FE184EBF2ED9F58B72520FB13C8F2C0E85BAABA4963C71D28E5310129FC8628602D7C4A7F67855BBF2B48AFBBE8FF68D24D5FE257C3EF797AE3A520EFEE35137AFDD0CA45C9E8CA38F70E6577A2BA24D50E2B260A819EF9771384CE3CC47ACD9E536A35A9BB3FE370FD654506420963DD716C86E6A005F60CF08F1D851B9BA39E2BE10DC9436549E998A08E99641F9036B79455FB4BA8F34A2B5B9AB789987D3CB2C59354EB6F9333D04B919CEF23C77A3E9B4B69E248E082AA59D0B5255E15C2A0489E06EDB9F08EA0F2749EEB18BA4F997A26AE12BAF058B8B1C1C92F1DCB768A031D0445D3ADD784B11D7FC8BDECD4D87A167DD538889CB7239F49008508258B1E3E9C08A7F2D1FAB3B97A2A0EFE5DF12468A17B3F2A6D737F9234AC3D50BAEB9B904F642EE21FBF86DCC2FA93B965764AAA7B1F70EA1FD8CEA27DCE44DD1838ECD6EA1F9469A11CF76B31270803ABEFE6E07FA5FBAF4F2F619F30EBFDB8F51DCBFE79C3D892A431D26F76252C76406B730E1E0BC204DCDD09671C5BDE4AD7B21B3286928031A5C27D0BD5BC1D7577C3617E77577270C08C9FB7B0ED917CBC430D0D52D6ABCE50A06CF99D8C53F8CD9F7CCBC718C7FC704E0E3E399A4DF3B5630C28E30CB883C5C237F16DD78CD30B94C7F76AE881BC883EBEAEC39417103BB9B39E35F24F700C9BF40B1900898A298595F202C8F2F0D2E17B5CEE7EA455E6540E7DACA61E6C8ACEFF5DC39B57BF8DA1822398C5AB5460F"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'winlogon.exe'(1084)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3812)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\programmi\IVT Corporation\BlueSoleil\BTNtService.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\McAfee\Common Framework\FrameworkService.exe
c:\programmi\McAfee\Common Framework\naPrdMgr.exe
c:\documents and settings\All Users\Dati applicazioni\Mobile Partner\OnlineUpdate\ouc.exe
c:\programmi\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmi\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\programmi\McAfee\Common Framework\McTray.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
.
**************************************************************************
.
Ora fine scansione: 2012-12-18 08:57:37 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2012-12-18 07:57
ComboFix2.txt 2012-12-17 08:05
.
Pre-Run: 47.913.054.208 byte disponibili
Post-Run: 47.934.099.456 byte disponibili
.
- - End Of File - - 966FD6F7CA3B03CF765C88A8CA0CC3F5

-----------------------------------------------------------------------------------------------------------------------------------------------

Ciao e benvenuto.

Innanzitutto , avere tre antivirus comporta dei conflitti , se non il blocco totale del pc.
In ordine:
Disinstalla
Mcafee
Microsoft SE

Seconda operazione:
Disattiva il ripristino configurazione di sistema.
Start
tasto destro su Risorse del computer
proprietà
scheda Ripristino configurazione
Disattiva -> Applica -> OK.

terza operazione:
Vedo che Combofix ha eliminato un rootkit , ma il sistema è ancora infetto.
Scarica il file CFScript.txt che ti ho allegato qui in basso sul desktop
trascinalo nell'icona rossa di combofix
Attendi le operazioni e dopo il riavvio del pc posta il report che ti appare

quarta operazione:
Fai start
tutti i programmi
esecuzione automatica
Elimina tutto ciò che trovi facendo tasto destro -> elimina.
 

tecnico24

Utente Èlite
10,706
1,072
L'immagine Jpeg non si visualizza.

Alcuni file eliminati con combofix si sono ricreati.
Verifichiamo se ci sono ancora infezioni in corso o se ci sono dei file di sistema danneggiati:
Segui questa guida -> http://www.tomshw.it/forum/sicurezz...omputer-infetto-leggere-prima-di-postare.html
Esegui in ordine:
Malwarebytes
TDSS Killer
(come da istruzioni , non tralasciando nessun passaggio)
Quindi allega nel forum il report di Mbam e TDSS Killer.

P.S:verifica se in modalità provvisoria hai lo stesso problema
 
Ultima modifica:

sca1965

Nuovo Utente
3
0
Come descritto nel tuo post e nel post indicato ho eseguito le tre applicazione indicate: Malwarebytes Anti-Malware (PRO) 1.65.1.1000, TDSS rootkit removing tool 2.8.15.0 e AdwCleaner v2.101 - di seguito allego i relativi report:
ps: anche in modalità provvisoria presenta lo stesso problema.

grazie del tuo interessamento (tecnico 24) e ti porgo gli auguri di buone feste.
Aspetto una gradita tua risposta.
Fabio Tortoioli

---------------------------------------------------------------------------------------------------------------------------------------------
Malwarebytes Anti-Malware (PRO) 1.65.1.1000

Malwarebytes Anti-Malware (PRO) 1.65.1.1000
Malwarebytes : Free anti-malware download

Versione database: v2012.12.19.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 6.0.2900.2180
f.tortoioli :: N-TORTOIOLIF [amministratore]

Protezione: Disattivata

19/12/2012 13.25.21
mbam-log-2012-12-19 (13-25-21).txt

Tipo di scansione: Scansione completa (C:\|E:\|)
Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File di sistema | Euristica/Extra | Euristica/Shuriken | PUP | PUM
Opzioni di scansione disattivate: P2P
Elementi esaminati: 622820
Tempo impiegato: 42 minuti, 36 secondi

Processi rilevati in memoria: 0
(non sono stati rilevati elementi nocivi)

Moduli di memoria rilevati: 0
(non sono stati rilevati elementi nocivi)

Chiavi di registro rilevate: 0
(non sono stati rilevati elementi nocivi)

Valori di registro rilevati: 0
(non sono stati rilevati elementi nocivi)

Voci rilevate nei dati di registro: 0
(non sono stati rilevati elementi nocivi)

Cartelle rilevate: 0
(non sono stati rilevati elementi nocivi)

File rilevati: 27
C:\Downloads\installer_intervideo_windvd_10_(2010)_English.exe (PUP.SmsPay.pns) -> Nessuna azione intrapresa.
C:\Downloads\Garmin\GarminMobileXTforWindowsMobile_50020w\garmin_kgen.exe (RiskWare.Tool.CK) -> Spostato in quarantena ed eliminato con successo.
C:\Downloads\Garmin\GarminMobileXTforWindowsMobile_50020w\GarminXT_5.00.20w\GarminXT 5.00.20w\4. Jetmouse Keygen\garmin_kgen_15.exe (RiskWare.Tool.CK) -> Spostato in quarantena ed eliminato con successo.
C:\Downloads\Garmin\garmin_mobile_xt_v6.00.10.Europamap.2011.by.age\Garmin Mobile XT v6.00.10 S60v3 S60v5 SymbianOS9.x Signed [Update]\GarminKGv1.5.exe (RiskWare.Tool.CK) -> Spostato in quarantena ed eliminato con successo.
C:\Downloads\penna 2 gb blu\Giochi\Pro Pinball Fantastic Journey\Stubs\6560f3c9708044e9a1ea8f561ceaa6cb649886b\FantasticJourney.exe (Trojan.Backdoor) -> Spostato in quarantena ed eliminato con successo.
C:\Downloads\Reti wi-fi\installer_winpcap_4_0_2_Italiano_Italian.exe (PUP.SmsPay.pns) -> Spostato in quarantena ed eliminato con successo.
C:\Downloads\Settings\Native\STUBEXE\8.0.1112\@SYSTEM@\verclsid.exe (Trojan.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\Downloads\Settings\Virtual\STUBEXE\8.0.1112\@PROGRAMFILES@\LibreOffice 3\program\soffice.bin (Trojan.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\Downloads\Settings\Virtual\STUBEXE\8.0.1112\@PROGRAMFILES@\LibreOffice 3\program\soffice.exe (Trojan.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\RECYCLER\S-1-5-21-1417001333-527237240-682003330-500\Dc2541.exe (Trojan.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\RECYCLER\S-1-5-21-1417001333-527237240-682003330-500\Dc2616.bin (Trojan.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\RECYCLER\S-1-5-21-1417001333-527237240-682003330-500\Dc2617.exe (Trojan.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\RECYCLER\S-1-5-21-1417001333-527237240-682003330-500\Dc3962.exe (Trojan.Backdoor) -> Spostato in quarantena ed eliminato con successo.
C:\System Volume Information\_restore{8A02C781-33C2-4609-A051-BD18A884DA17}\RP292\A0078590.exe (Adware.GamePlayLabs) -> Spostato in quarantena ed eliminato con successo.
C:\System Volume Information\_restore{8A02C781-33C2-4609-A051-BD18A884DA17}\RP314\A0082528.exe (PUP.OfferBundler.ST) -> Spostato in quarantena ed eliminato con successo.
E:\Download\Directlinks\Lupo PenSuite v6.71 Full\Apps\CCleaner Portable\unicows.dll (Malware.Packer.Gen) -> Spostato in quarantena ed eliminato con successo.
E:\Download\Directlinks\Lupo PenSuite v6.71 Full\Apps\FDM Lite\dbghelp.dll (Malware.Packer.Gen) -> Spostato in quarantena ed eliminato con successo.
E:\Download\Directlinks\Lupo PenSuite v6.71 Full\Apps\FDM Lite\msvcp60.dll (Malware.Packer.Gen) -> Spostato in quarantena ed eliminato con successo.
E:\Download\Directlinks\Lupo PenSuite v6.71 Full\Apps\Gnumeric Plus\App\Gnumeric\lib\gnumeric\1.9.3\plugins\fn-tsa\plugin.dll (Trojan.Downloader) -> Spostato in quarantena ed eliminato con successo.
E:\Download\Directlinks\Lupo PenSuite v6.71 Full\Apps\Recuva Portable\unicows.dll (Malware.Packer.Gen) -> Spostato in quarantena ed eliminato con successo.
E:\Programmi\Adobe CS3 Portable\Adobe Photoshop CS3\Msvcrt.dll (Malware.Packer.Gen) -> Spostato in quarantena ed eliminato con successo.
E:\Programmi\Winrar 3.70 Portable\Default.SFX (Backdoor.Bifrose) -> Spostato in quarantena ed eliminato con successo.
E:\Programmi\Winrar 3.70 Portable\Zip.SFX (Backdoor.Bifrose) -> Spostato in quarantena ed eliminato con successo.
C:\Documents and Settings\assistenza.OLIDATA-VIMPZ\Menu Avvio\Programmi\Esecuzione automatica\Deewoo.lnk (Malware.Links) -> Spostato in quarantena ed eliminato con successo.
C:\Documents and Settings\assistenza.OLIDATA-VIMPZ\Menu Avvio\Programmi\Esecuzione automatica\DW_Start.lnk (Malware.Links) -> Spostato in quarantena ed eliminato con successo.
C:\Documents and Settings\assistenza\Menu Avvio\Programmi\Esecuzione automatica\DW_Start.lnk (Malware.Links) -> Spostato in quarantena ed eliminato con successo.
C:\Documents and Settings\Sis-Rete\Menu Avvio\Programmi\Esecuzione automatica\DW_Start.lnk (Malware.Links) -> Spostato in quarantena ed eliminato con successo.

------------------------------------------------------------------------------------------------------------------------------------------
TDSS rootkit removing tool 2.8.15.0

13:20:56.0468 3044 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
13:20:58.0468 3044 ============================================================
13:20:58.0468 3044 Current date / time: 2012/12/19 13:20:58.0468
13:20:58.0468 3044 SystemInfo:
13:20:58.0468 3044
13:20:58.0468 3044 OS Version: 5.1.2600 ServicePack: 3.0
13:20:58.0468 3044 Product type: Workstation
13:20:58.0468 3044 ComputerName: N-TORTOIOLIF
13:20:58.0468 3044 UserName: f.tortoioli
13:20:58.0468 3044 Windows directory: C:\WINDOWS
13:20:58.0468 3044 System windows directory: C:\WINDOWS
13:20:58.0468 3044 Processor architecture: Intel x86
13:20:58.0468 3044 Number of processors: 2
13:20:58.0468 3044 Page size: 0x1000
13:20:58.0468 3044 Boot type: Normal boot
13:20:58.0468 3044 ============================================================
13:20:59.0421 3044 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
13:20:59.0421 3044 ============================================================
13:20:59.0421 3044 \Device\Harddisk0\DR0:
13:20:59.0421 3044 MBR partitions:
13:20:59.0421 3044 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xF6055FB
13:20:59.0437 3044 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xF605679, BlocksNum 0xDBBEF08
13:20:59.0437 3044 ============================================================
13:20:59.0468 3044 C: <-> \Device\Harddisk0\DR0\Partition1
13:20:59.0500 3044 E: <-> \Device\Harddisk0\DR0\Partition2
13:20:59.0500 3044 ============================================================
13:20:59.0500 3044 Initialize success
13:20:59.0500 3044 ============================================================
13:21:01.0187 3244 ============================================================
13:21:01.0187 3244 Scan started
13:21:01.0187 3244 Mode: Manual;
13:21:01.0187 3244 ============================================================
13:21:02.0140 3244 ================ Scan system memory ========================
13:21:02.0140 3244 System memory - ok
13:21:02.0140 3244 ================ Scan services =============================
13:21:02.0234 3244 a347scsi - ok
13:21:02.0234 3244 Abiosdsk - ok
13:21:02.0234 3244 abp480n5 - ok
13:21:02.0265 3244 [ AD825CB3397C837D1FB91D566D78DE04 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
13:21:02.0265 3244 ACPI - ok
13:21:02.0296 3244 [ 49AC5CD87FBDDA62F3E25190019E7627 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
13:21:02.0296 3244 ACPIEC - ok
13:21:02.0296 3244 adpu160m - ok
13:21:02.0343 3244 [ 841F385C6CFAF66B58FBD898722BB4F0 ] aec C:\WINDOWS\system32\drivers\aec.sys
13:21:02.0343 3244 aec - ok
13:21:02.0359 3244 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
13:21:02.0359 3244 AFD - ok
13:21:02.0359 3244 Aha154x - ok
13:21:02.0359 3244 aic78u2 - ok
13:21:02.0375 3244 aic78xx - ok
13:21:02.0406 3244 [ AD78B916B3CB2B7BCA9503B929E534B9 ] Alerter C:\WINDOWS\system32\alrsvc.dll
13:21:02.0406 3244 Alerter - ok
13:21:02.0421 3244 [ D4A42BF3C11302AA3CCD857034EF1E54 ] ALG C:\WINDOWS\System32\alg.exe
13:21:02.0421 3244 ALG - ok
13:21:02.0437 3244 AliIde - ok
13:21:02.0453 3244 [ 1928A2A6D7ADC3623A43C21DAC259F24 ] AmdK8 C:\WINDOWS\system32\DRIVERS\AmdK8.sys
13:21:02.0453 3244 AmdK8 - ok
13:21:02.0453 3244 amsint - ok
13:21:02.0484 3244 [ DD8D9C597AF7CD2F6B70A3D6A4A1ACEA ] androidusb C:\WINDOWS\system32\Drivers\ssadadb.sys
13:21:02.0484 3244 androidusb - ok
13:21:02.0515 3244 [ FF6BC17D290F6FC7CAFEE7C762ECFFC8 ] Anydlc C:\WINDOWS\System32\drivers\anydlc.sys
13:21:02.0515 3244 Anydlc - ok
13:21:02.0546 3244 [ 00E50CD4D9247CB56EFC1360C32AB755 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
13:21:02.0546 3244 AppMgmt - ok
13:21:02.0593 3244 [ CD052727FF5CDC71ECE1883672540D0F ] Appn C:\WINDOWS\System32\drivers\appn.sys
13:21:02.0593 3244 Appn - ok
13:21:02.0609 3244 [ E80365522A583AFE6102C57EBFB5FA79 ] AppnApi C:\WINDOWS\System32\drivers\appnapi.sys
13:21:02.0609 3244 AppnApi - ok
13:21:02.0625 3244 [ D4B274C10EBF0E9A0B82A9216BE25AC8 ] AppnBase C:\WINDOWS\System32\drivers\AppnBase.sys
13:21:02.0625 3244 AppnBase - ok
13:21:02.0625 3244 asc - ok
13:21:02.0625 3244 asc3350p - ok
13:21:02.0640 3244 asc3550 - ok
13:21:02.0734 3244 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
13:21:02.0734 3244 aspnet_state - ok
13:21:02.0750 3244 [ 02000ABF34AF4C218C35D257024807D6 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
13:21:02.0750 3244 AsyncMac - ok
13:21:02.0781 3244 [ CDFE4411A69C224BD1D11B2DA92DAC51 ] atapi C:\WINDOWS\system32\drivers\atapi.sys
13:21:02.0781 3244 atapi - ok
13:21:02.0781 3244 Atdisk - ok
13:21:02.0828 3244 [ 454DFDC3D40B777455846E749D3B49FF ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
13:21:02.0828 3244 Ati HotKey Poller - ok
13:21:02.0859 3244 [ EF94E95E9D5366A88275FBB15E9D6E74 ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe
13:21:02.0859 3244 ATI Smart - ok
13:21:02.0953 3244 [ C51608BBA3248BE2F6D21B132910752A ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
13:21:02.0968 3244 ati2mtag - ok
13:21:03.0000 3244 [ EC88DA854AB7D7752EC8BE11A741BB7F ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
13:21:03.0000 3244 Atmarpc - ok
13:21:03.0015 3244 [ 15EE9EFF206DAA73B9642FCD51A69BB1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
13:21:03.0031 3244 AudioSrv - ok
13:21:03.0031 3244 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
13:21:03.0046 3244 audstub - ok
13:21:03.0078 3244 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
13:21:03.0078 3244 Beep - ok
13:21:03.0109 3244 [ 04E8321935AD5643FF59901F3EF5F4F3 ] BITS C:\WINDOWS\system32\qmgr.dll
13:21:03.0109 3244 BITS - ok
13:21:03.0125 3244 [ 04E84C8049EE93614A2FF6D676D1E247 ] BlueletAudio C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
13:21:03.0125 3244 BlueletAudio - ok
13:21:03.0218 3244 [ 55F24E6EC983FCC7510293B05A27CEEC ] BlueSoleil Hid Service C:\Programmi\IVT Corporation\BlueSoleil\BTNtService.exe
13:21:03.0218 3244 BlueSoleil Hid Service - ok
13:21:03.0265 3244 [ 076D11B52F066ED33E3A80F8070A3E2E ] Browser C:\WINDOWS\System32\browser.dll
13:21:03.0265 3244 Browser - ok
13:21:03.0296 3244 [ D1813668A0117AE05BC0B81C874F91D4 ] BT C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
13:21:03.0296 3244 BT - ok
13:21:03.0312 3244 [ 7304ACC25455746912DE37D7DED387ED ] Btcsrusb C:\WINDOWS\system32\Drivers\btcusb.sys
13:21:03.0312 3244 Btcsrusb - ok
13:21:03.0312 3244 [ 161969D2DD1D39CD2F1EDBC60C61FA99 ] BTHidEnum C:\WINDOWS\system32\DRIVERS\vbtenum.sys
13:21:03.0312 3244 BTHidEnum - ok
13:21:03.0343 3244 [ A9164C2A39BD917B9F42AE087560AC3D ] BTHidMgr C:\WINDOWS\system32\Drivers\BTHidMgr.sys
13:21:03.0343 3244 BTHidMgr - ok
13:21:03.0359 3244 [ 6B05FDC0CFC3753B520D2D4176CC32D0 ] BTNetFilter C:\WINDOWS\system32\drivers\BTNetFilter.sys
13:21:03.0359 3244 BTNetFilter - ok
13:21:03.0453 3244 [ DADEAA1407E2ED1163DC8964F920E84E ] Canon Driver Information Assist Service C:\Programmi\Canon\DIAS\CnxDIAS.exe
13:21:03.0453 3244 Canon Driver Information Assist Service - ok
13:21:03.0468 3244 catchme - ok
13:21:03.0484 3244 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
13:21:03.0500 3244 cbidf2k - ok
13:21:03.0515 3244 [ 6163ED60B684BAB19D3352AB22FC48B2 ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
13:21:03.0515 3244 CCDECODE - ok
13:21:03.0531 3244 cd20xrnt - ok
13:21:03.0531 3244 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
13:21:03.0531 3244 Cdaudio - ok
13:21:03.0562 3244 [ CD7D5152DF32B47F4E36F710B35AAE02 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
13:21:03.0562 3244 Cdfs - ok
13:21:03.0562 3244 [ 80AC946628DE5DEAB071474E30D7A071 ] cdrbsvsd C:\WINDOWS\system32\drivers\cdrbsvsd.sys
13:21:03.0562 3244 cdrbsvsd - ok
13:21:03.0593 3244 [ AF9C19B3100FE010496B1A27181FBF72 ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
13:21:03.0593 3244 Cdrom - ok
13:21:03.0593 3244 Changer - ok
13:21:03.0609 3244 [ C4E84243292E37CA3B6FAF4A1855B8A7 ] CiSvc C:\WINDOWS\system32\cisvc.exe
13:21:03.0609 3244 CiSvc - ok
13:21:03.0625 3244 [ 0A215E4BAC9A1A9381D88C67517C850B ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
13:21:03.0625 3244 ClipSrv - ok
13:21:03.0671 3244 [ 3D560AF01BDC50B4A1E1BFB5CDC06D63 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:21:03.0671 3244 clr_optimization_v2.0.50727_32 - ok
13:21:03.0703 3244 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:21:03.0703 3244 clr_optimization_v4.0.30319_32 - ok
13:21:03.0718 3244 CmdIde - ok
13:21:03.0718 3244 COMSysApp - ok
13:21:03.0781 3244 [ A79CBC990D839286ADC0C36263F8EFE5 ] cpextender C:\Programmi\CheckPoint\SSL Network Extender\slimsvc.exe
13:21:03.0781 3244 cpextender - ok
13:21:03.0781 3244 Cpqarray - ok
13:21:03.0812 3244 [ E0CC838265401128097D182FB583889A ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
13:21:03.0812 3244 CryptSvc - ok
13:21:03.0812 3244 dac2w2k - ok
13:21:03.0828 3244 dac960nt - ok
13:21:03.0859 3244 [ BC4E0226341AAEC1222336B3AED86BAB ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
13:21:03.0859 3244 DcomLaunch - ok
13:21:03.0906 3244 [ 3D6F9B5C5C396BFBC14DC565CE624CEF ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
13:21:03.0906 3244 Dhcp - ok
13:21:03.0906 3244 [ 00CA44E4534865F8A3B64F7C0984BFF0 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
13:21:03.0906 3244 Disk - ok
13:21:03.0906 3244 dmadmin - ok
13:21:03.0937 3244 [ 6570B4C952F0D8FEE4C6EF2FF5E10C08 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
13:21:03.0953 3244 dmboot - ok
13:21:03.0953 3244 [ C57D35621782C7F40770F3E5CA20A182 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
13:21:03.0953 3244 dmio - ok
13:21:03.0984 3244 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
13:21:03.0984 3244 dmload - ok
13:21:03.0984 3244 [ 499FFF7BCA07009A23447776286F0510 ] dmserver C:\WINDOWS\System32\dmserver.dll
13:21:03.0984 3244 dmserver - ok
13:21:04.0015 3244 [ A6F881284AC1150E37D9AE47FF601267 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
13:21:04.0015 3244 DMusic - ok
13:21:04.0062 3244 [ B7A1162B1A26DF7B60D5D9500006096C ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
13:21:04.0062 3244 Dnscache - ok
13:21:04.0093 3244 [ D580D77DFF316BD8C9D73B38695DE8DC ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
13:21:04.0093 3244 Dot3svc - ok
13:21:04.0093 3244 dpti2o - ok
13:21:04.0109 3244 [ 1ED4DBBAE9F5D558DBBA4CC450E3EB2E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
13:21:04.0109 3244 drmkaud - ok
13:21:04.0125 3244 EAGLE2RC - ok
13:21:04.0125 3244 Eagle2TV - ok
13:21:04.0140 3244 [ 86B1F123BACD444E81960B339BAE3FF2 ] EapHost C:\WINDOWS\System32\eapsvc.dll
13:21:04.0140 3244 EapHost - ok
13:21:04.0187 3244 [ 44996A2ADDD2DB7454F2CA40B67D8941 ] ElbyCDIO C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
13:21:04.0187 3244 ElbyCDIO - ok
13:21:04.0203 3244 [ FF547B3876B6E652431412345FB8EE11 ] ERSvc C:\WINDOWS\System32\ersvc.dll
13:21:04.0203 3244 ERSvc - ok
13:21:04.0218 3244 [ 6C08BDC02F633AD426653A7EE175C40A ] EU3_USB C:\WINDOWS\system32\DRIVERS\EU3USB.sys
13:21:04.0234 3244 EU3_USB - ok
13:21:04.0250 3244 [ 26845F272435302E0F3322E660A24F7D ] Eventlog C:\WINDOWS\system32\services.exe
13:21:04.0250 3244 Eventlog - ok
13:21:04.0296 3244 [ 8360CB9756E598A5C6214EACFB3677C3 ] EventSystem C:\WINDOWS\system32\es.dll
13:21:04.0296 3244 EventSystem - ok
13:21:04.0343 3244 [ FB54F67974D13D73BE3E2F1DF042D295 ] ewusbnet C:\WINDOWS\system32\DRIVERS\ewusbnet.sys
13:21:04.0343 3244 ewusbnet - ok
13:21:04.0359 3244 [ 57C171EA22F0A7F068FCB0CAEDD1E8E7 ] ew_hwusbdev C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys
13:21:04.0359 3244 ew_hwusbdev - ok
13:21:04.0375 3244 [ 61A973F60E94A551BA7B15F3460444FB ] ew_usbenumfilter C:\WINDOWS\system32\DRIVERS\ew_usbenumfilter.sys
13:21:04.0375 3244 ew_usbenumfilter - ok
13:21:04.0406 3244 [ 3117F595E9615E04F05A54FC15A03B20 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
13:21:04.0406 3244 Fastfat - ok
13:21:04.0437 3244 [ DCCC606FC144F6E44E497F9A906F1C30 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
13:21:04.0437 3244 FastUserSwitchingCompatibility - ok
13:21:04.0468 3244 [ CED2E8396A8838E59D8FD529C680E02C ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
13:21:04.0468 3244 Fdc - ok
13:21:04.0484 3244 [ 333FBBC71BDCBB46C58A3B51B3D51184 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
13:21:04.0484 3244 Fips - ok
13:21:04.0500 3244 [ 0DD1DE43115B93F4D85E889D7A86F548 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
13:21:04.0500 3244 Flpydisk - ok
13:21:04.0531 3244 [ 157754F0DF355A9E0A6F54721914F9C6 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
13:21:04.0531 3244 FltMgr - ok
13:21:04.0609 3244 [ E7A80D98F9E8FC18F448BA2E2E2B040C ] FreemakeVideoCapture C:\Programmi\Freemake\CaptureLib\CaptureLibService.exe
13:21:04.0609 3244 FreemakeVideoCapture - ok
13:21:04.0625 3244 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
13:21:04.0625 3244 Fs_Rec - ok
13:21:04.0640 3244 [ F3269A6EE547EA87B949A1CEA4816B38 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
13:21:04.0640 3244 Ftdisk - ok
13:21:04.0656 3244 [ C0F1D4A21DE5A415DF8170616703DEBF ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
13:21:04.0656 3244 Gpc - ok
13:21:04.0687 3244 [ D956358054E99E6FFAC69CD87E893A89 ] grmnusb C:\WINDOWS\system32\drivers\grmnusb.sys
13:21:04.0687 3244 grmnusb - ok
13:21:04.0718 3244 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
13:21:04.0718 3244 HDAudBus - ok
13:21:04.0765 3244 [ 03A7A19834E2A63C445B3AC5E73AAB50 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
13:21:04.0765 3244 helpsvc - ok
13:21:04.0765 3244 HidServ - ok
13:21:04.0796 3244 [ 00CAD842F48947887A972828ACA665F7 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
13:21:04.0796 3244 hkmsvc - ok
13:21:04.0796 3244 hpn - ok
13:21:04.0828 3244 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
13:21:04.0828 3244 HTTP - ok
13:21:04.0859 3244 [ 730374DCF08DF00178D190F9EBD0058A ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
13:21:04.0859 3244 HTTPFilter - ok
13:21:04.0890 3244 [ F44461E66F1B7DD267957FE9BAA63ED0 ] huawei_enumerator C:\WINDOWS\system32\DRIVERS\ew_jubusenum.sys
13:21:04.0890 3244 huawei_enumerator - ok
13:21:04.0906 3244 [ B50E1D8627354BA8E4DF83470F1272C8 ] hwdatacard C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys
13:21:04.0906 3244 hwdatacard - ok
13:21:05.0000 3244 [ 5EF3427AE503B5C03A48F7C9FF458B69 ] HWDeviceService.exe C:\Documents and Settings\All Users\Dati applicazioni\DatacardService\HWDeviceService.exe
13:21:05.0015 3244 HWDeviceService.exe - ok
13:21:05.0015 3244 hwusbdev - ok
13:21:05.0015 3244 hwusbfake - ok
13:21:05.0031 3244 i2omgmt - ok
13:21:05.0031 3244 i2omp - ok
13:21:05.0046 3244 [ 30E64DFA4EFAACC8142EA07766181FB4 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
13:21:05.0046 3244 i8042prt - ok
13:21:05.0093 3244 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
13:21:05.0093 3244 IDriverT - ok
13:21:05.0109 3244 [ F8AA320C6A0409C0380E5D8A99D76EC6 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
13:21:05.0109 3244 Imapi - ok
13:21:05.0156 3244 [ ED7ABB35C81709FB41972D30FE15311E ] ImapiService C:\WINDOWS\system32\imapi.exe
13:21:05.0156 3244 ImapiService - ok
13:21:05.0156 3244 ini910u - ok
13:21:05.0250 3244 [ CDFD5A68A2E1CAA89C5C0E0B3CB98731 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
13:21:05.0281 3244 IntcAzAudAddService - ok
13:21:05.0281 3244 IntelIde - ok
13:21:05.0312 3244 [ 4448006B6BC60E6C027932CFC38D6855 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
13:21:05.0312 3244 Ip6Fw - ok
13:21:05.0343 3244 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
13:21:05.0343 3244 IpFilterDriver - ok
13:21:05.0343 3244 [ E1EC7F5DA720B640CD8FB8424F1B14BB ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
13:21:05.0343 3244 IpInIp - ok
13:21:05.0359 3244 [ B5A8E215AC29D24D60B4D1250EF05ACE ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
13:21:05.0359 3244 IpNat - ok
13:21:05.0359 3244 [ 64537AA5C003A6AFEEE1DF819062D0D1 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
13:21:05.0359 3244 IPSec - ok
13:21:05.0390 3244 [ 50708DAA1B1CBB7D6AC1CF8F56A24410 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
13:21:05.0390 3244 IRENUM - ok
13:21:05.0421 3244 [ EA3245A8E8758D6B84DE189A5CAAA75E ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
13:21:05.0421 3244 isapnp - ok
13:21:05.0515 3244 [ 691B9B7C0CC1653732717D292D6B305D ] JavaQuickStarterService C:\Programmi\Java\jre6\bin\jqs.exe
13:21:05.0515 3244 JavaQuickStarterService - ok
13:21:05.0531 3244 [ E883AE6EA0B313E659225AA32E449CE9 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
13:21:05.0531 3244 Kbdclass - ok
13:21:05.0546 3244 [ 24F4D51E89822C349044C28BE255C8A5 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
13:21:05.0546 3244 kbdhid - ok
13:21:05.0578 3244 [ E84BC08BBCCA5739C229978ED4569AF6 ] KLOGNT C:\WINDOWS\System32\drivers\klognt.sys
13:21:05.0578 3244 KLOGNT - ok
13:21:05.0609 3244 [ D93CAD07C5683DB066B0B2D2D3790EAD ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
13:21:05.0609 3244 kmixer - ok
13:21:05.0640 3244 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
13:21:05.0640 3244 KSecDD - ok
13:21:05.0671 3244 [ 0F726D49C0B19E5A506A1CDFCE0EE42F ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
13:21:05.0671 3244 lanmanserver - ok
13:21:05.0703 3244 [ E13B0181DDA60B93E3253EFF52A79CBE ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
13:21:05.0703 3244 lanmanworkstation - ok
13:21:05.0703 3244 lbrtfdc - ok
13:21:05.0750 3244 [ E751112D8EBED196728EC44852D81562 ] ldlcserv C:\WINDOWS\system32\drivers\ldlcserv.exe
13:21:05.0750 3244 ldlcserv - ok
13:21:05.0750 3244 lmab_device - ok
13:21:05.0781 3244 [ 6E008B7EB9B67D555B5EE1C1091F3A7E ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
13:21:05.0781 3244 LmHosts - ok
13:21:05.0796 3244 [ 0DB7527DB188C7D967A37BB51BBF3963 ] MBAMSwissArmy C:\WINDOWS\system32\drivers\mbamswissarmy.sys
13:21:05.0796 3244 MBAMSwissArmy - ok
13:21:05.0843 3244 [ 062D80F13D762F7BC2F38430D60F5048 ] McAfeeFramework C:\Programmi\McAfee\Common Framework\FrameworkService.exe
13:21:05.0859 3244 McAfeeFramework - ok
13:21:05.0875 3244 [ 3777AB9537D05BFD404B0FBC13A140A6 ] Messenger C:\WINDOWS\System32\msgsvc.dll
13:21:05.0875 3244 Messenger - ok
13:21:05.0890 3244 mferkdk - ok
13:21:05.0890 3244 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
13:21:05.0890 3244 mnmdd - ok
13:21:05.0921 3244 [ 940A4E02B7F03C2592A52E16DDDB3E46 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
13:21:05.0921 3244 mnmsrvc - ok
13:21:05.0953 3244 [ 1CE0621B591913C12BECAA5B50E88BB2 ] Mobile Partner. RunOuc C:\Programmi\Mobile Partner\UpdateDog\ouc.exe
13:21:05.0953 3244 Mobile Partner. RunOuc - ok
13:21:05.0953 3244 [ B30D2DB351E3191BD71232036CFE711A ] Modem C:\WINDOWS\system32\drivers\Modem.sys
13:21:05.0953 3244 Modem - ok
13:21:05.0968 3244 [ C458E314B8722253897C94A714C2E0C0 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
13:21:05.0968 3244 Mouclass - ok
13:21:05.0968 3244 [ 65653F3B4477F3C63E68A9659F85EE2E ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
13:21:05.0968 3244 MountMgr - ok
13:21:06.0015 3244 [ 55A9A7E6BB297BF0F5B144029DCB79CC ] MPE C:\WINDOWS\system32\DRIVERS\MPE.sys
13:21:06.0015 3244 MPE - ok
13:21:06.0015 3244 mraid35x - ok
13:21:06.0031 3244 [ 46EDCC8F2DB2F322C24F48785CB46366 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
13:21:06.0031 3244 MRxDAV - ok
13:21:06.0078 3244 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
13:21:06.0078 3244 MRxSmb - ok
13:21:06.0093 3244 [ 3124662B40761A3EF8F4254D2F32E3F4 ] MSDTC C:\WINDOWS\system32\msdtc.exe
13:21:06.0093 3244 MSDTC - ok
13:21:06.0109 3244 [ 561B3A4333CA2DBDBA28B5B956822519 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
13:21:06.0109 3244 Msfs - ok
13:21:06.0109 3244 MSIServer - ok
13:21:06.0140 3244 [ AE431A8DD3C1D0D0610CDBAC16057AD0 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
13:21:06.0140 3244 MSKSSRV - ok
13:21:06.0156 3244 [ 13E75FEF9DFEB08EEDED9D0246E1F448 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
13:21:06.0156 3244 MSPCLOCK - ok
13:21:06.0171 3244 [ 1988A33FF19242576C3D0EF9CE785DA7 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
13:21:06.0171 3244 MSPQM - ok
13:21:06.0187 3244 [ 469541F8BFD2B32659D5D463A6714BCE ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
13:21:06.0187 3244 mssmbios - ok
13:21:06.0218 3244 [ BF13612142995096AB084F2DB7F40F77 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
13:21:06.0218 3244 MSTEE - ok
13:21:06.0250 3244 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
13:21:06.0250 3244 MTsensor - ok
13:21:06.0265 3244 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
13:21:06.0265 3244 Mup - ok
13:21:06.0296 3244 [ 5C8DC6429C43DC6177C1FA5B76290D1A ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
13:21:06.0296 3244 NABTSFEC - ok
13:21:06.0328 3244 [ 911587FD303C9690A428BB4B04732B61 ] napagent C:\WINDOWS\System32\qagentrt.dll
13:21:06.0328 3244 napagent - ok
13:21:06.0343 3244 [ 558635D3AF1C7546D26067D5D9B6959E ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
13:21:06.0343 3244 NDIS - ok
13:21:06.0375 3244 [ 520CE427A8B298F54112857BCF6BDE15 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
13:21:06.0375 3244 NdisIP - ok
13:21:06.0375 3244 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
13:21:06.0375 3244 NdisTapi - ok
13:21:06.0406 3244 [ 34D6CD56409DA9A7ED573E1C90A308BF ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
13:21:06.0406 3244 Ndisuio - ok
13:21:06.0406 3244 [ 0B90E255A9490166AB368CD55A529893 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
13:21:06.0406 3244 NdisWan - ok
13:21:06.0437 3244 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
13:21:06.0437 3244 NDProxy - ok
13:21:06.0531 3244 [ 40D7D0A208EE863BCA8D89E299216F15 ] Nero BackItUp Scheduler 3 C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
13:21:06.0531 3244 Nero BackItUp Scheduler 3 - ok
13:21:06.0546 3244 [ 3A2ACA8FC1D7786902CA434998D7CEB4 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
13:21:06.0546 3244 NetBIOS - ok
13:21:06.0562 3244 [ 0C80E410CD2F47134407EE7DD19CC86B ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
13:21:06.0562 3244 NetBT - ok
13:21:06.0578 3244 [ DE62EE316FAB09DE3D7A5180F0775ABF ] NetDDE C:\WINDOWS\system32\netdde.exe
13:21:06.0593 3244 NetDDE - ok
13:21:06.0593 3244 [ DE62EE316FAB09DE3D7A5180F0775ABF ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
13:21:06.0593 3244 NetDDEdsdm - ok
13:21:06.0625 3244 [ 0815E8DA286775FA432C7C9EE5E10BA1 ] Netlogon C:\WINDOWS\system32\lsass.exe
13:21:06.0625 3244 Netlogon - ok
13:21:06.0656 3244 [ 4AD6F202266A25BC0CC1DCE2A3D91563 ] Netman C:\WINDOWS\System32\netman.dll
13:21:06.0656 3244 Netman - ok
13:21:06.0687 3244 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:21:06.0687 3244 NetTcpPortSharing - ok
13:21:06.0718 3244 [ C6B69A18D39744725FB73AC85E46032B ] Nla C:\WINDOWS\System32\mswsock.dll
13:21:06.0734 3244 Nla - ok
13:21:06.0765 3244 [ 60CF8C7192B3614F240838DDBAA4A245 ] nm C:\WINDOWS\system32\DRIVERS\NMnt.sys
13:21:06.0765 3244 nm - ok
13:21:06.0812 3244 [ EBA1B4BF2E2375ABDADEDB649F283541 ] NMIndexingService C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
13:21:06.0812 3244 NMIndexingService - ok
13:21:06.0828 3244 [ 4F601BCB8F64EA3AC0994F98FED03F8E ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
13:21:06.0828 3244 Npfs - ok
13:21:06.0828 3244 NSNDIS5 - ok
13:21:06.0859 3244 [ FAC266AA9710ADADD1ED81037B30C5A8 ] NsTrcNT C:\WINDOWS\System32\drivers\nstrcnt.sys
13:21:06.0859 3244 NsTrcNT - ok
13:21:06.0875 3244 [ B78BE402C3F63DD55521F73876951CDD ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
13:21:06.0875 3244 Ntfs - ok
13:21:06.0875 3244 [ 0815E8DA286775FA432C7C9EE5E10BA1 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
13:21:06.0890 3244 NtLmSsp - ok
13:21:06.0906 3244 [ 6D96A941EED90224486F9AF30B9666E1 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
13:21:06.0906 3244 NtmsSvc - ok
13:21:06.0937 3244 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
13:21:06.0937 3244 Null - ok
13:21:06.0968 3244 [ D875346596BD48D74AC9B9BE791B8D69 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
13:21:06.0984 3244 NVENETFD - ok
13:21:06.0984 3244 [ F02C1C5E84C37667ECD3EEA5958449BC ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
13:21:06.0984 3244 nvnetbus - ok
13:21:07.0015 3244 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
13:21:07.0015 3244 NwlnkFlt - ok
13:21:07.0031 3244 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
13:21:07.0031 3244 NwlnkFwd - ok
13:21:07.0078 3244 [ E54AA592A65F317390EEE386A8821692 ] odserv C:\Programmi\File comuni\Microsoft Shared\OFFICE12\ODSERV.EXE
13:21:07.0078 3244 odserv - ok
13:21:07.0109 3244 [ 166CAF140557ACD9FF70ECADA5AE43F4 ] onda_mx83xup_cdc_acm C:\WINDOWS\system32\DRIVERS\onda_mx83xup_cdc_acm.sys
13:21:07.0109 3244 onda_mx83xup_cdc_acm - ok
13:21:07.0125 3244 [ D46091AFFF71A263C52D882447E26AB9 ] onda_mx83xup_cpo C:\WINDOWS\system32\DRIVERS\onda_mx83xup_cpo.sys
13:21:07.0125 3244 onda_mx83xup_cpo - ok
13:21:07.0156 3244 [ 7C53BCAE06B5DBD1D2EDDF9450BBBF6E ] onda_mx83xup_dc_enum C:\WINDOWS\system32\DRIVERS\onda_mx83xup_dc_enum.sys
13:21:07.0156 3244 onda_mx83xup_dc_enum - ok
13:21:07.0187 3244 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Programmi\File comuni\Microsoft Shared\Source Engine\OSE.EXE
13:21:07.0187 3244 ose - ok
13:21:07.0203 3244 [ 3490EAD0612BFD0E7C1B864EE24E6A4A ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
13:21:07.0203 3244 Parport - ok
13:21:07.0234 3244 [ 3334430C29DC338092F79C38EF7B4CD0 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
13:21:07.0234 3244 PartMgr - ok
13:21:07.0265 3244 [ 0DABEF655A444CB1E193626FB1D24B9F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
13:21:07.0265 3244 ParVdm - ok
13:21:07.0281 3244 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
13:21:07.0281 3244 pccsmcfd - ok
13:21:07.0296 3244 [ 91FC1D483D900B1C0600A08B871C39D5 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
13:21:07.0296 3244 PCI - ok
13:21:07.0296 3244 PCIDump - ok
13:21:07.0312 3244 [ B2DF00D650FD6C4EE781740ED3C8E67F ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
13:21:07.0312 3244 PCIIde - ok
13:21:07.0328 3244 [ 28F3538A2091993A03506311A05053E8 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
13:21:07.0328 3244 Pcmcia - ok
13:21:07.0359 3244 [ 1471CC65C2A44BF61025D54A79F93510 ] Pcouffin C:\WINDOWS\system32\Drivers\Pcouffin.sys
13:21:07.0359 3244 Pcouffin - ok
13:21:07.0359 3244 PDCOMP - ok
13:21:07.0359 3244 PDFRAME - ok
13:21:07.0390 3244 [ 156E851A070C60CB8EE29A338EC47DEF ] pdlnacom C:\WINDOWS\System32\drivers\pdlnacom.sys
13:21:07.0390 3244 pdlnacom - ok
13:21:07.0406 3244 [ 19AA56243804330B5B4C32C886A62345 ] pdlnafac C:\WINDOWS\System32\drivers\pdlnafac.sys
13:21:07.0406 3244 pdlnafac - ok
13:21:07.0421 3244 [ 2F9F47A85F79DC3ED951008C0B616266 ] pdlnatcm C:\WINDOWS\System32\drivers\pdlnatcm.sys
13:21:07.0421 3244 pdlnatcm - ok
13:21:07.0421 3244 [ 1F519CFFB457BF9F22B0B847513E71BA ] pdlnatdl C:\WINDOWS\System32\drivers\pdlnatdl.sys
13:21:07.0421 3244 pdlnatdl - ok
13:21:07.0437 3244 [ C29BCB6B1E4FF59E10CEEF881460696E ] pdlncbas C:\WINDOWS\System32\drivers\pdlncbas.sys
13:21:07.0437 3244 pdlncbas - ok
13:21:07.0468 3244 [ 66443F5D88BF1C3C17EA2C7F1C04E955 ] pdlncfwk C:\WINDOWS\System32\drivers\pdlncfwk.sys
13:21:07.0468 3244 pdlncfwk - ok
13:21:07.0468 3244 [ 265131B32EC00C14320383EB0547C45C ] pdlnctdl C:\WINDOWS\System32\drivers\pdlnctdl.sys
13:21:07.0468 3244 pdlnctdl - ok
13:21:07.0468 3244 [ C923BCEB2E28EBCF7E79EE92C171112B ] pdlndint C:\WINDOWS\System32\drivers\pdlndint.sys
13:21:07.0484 3244 pdlndint - ok
13:21:07.0500 3244 [ 12281330A0D0E956EECED83BF01239CA ] pdlndldl C:\WINDOWS\System32\drivers\pdlndldl.sys
13:21:07.0500 3244 pdlndldl - ok
13:21:07.0500 3244 [ F1A2FA74DAE12056AFBD554DD4E92D90 ] pdlndlpb C:\WINDOWS\System32\drivers\pdlndlpb.sys
13:21:07.0500 3244 pdlndlpb - ok
13:21:07.0500 3244 [ 7006D2E8ADE435F0727FDCFFE1D2CCAB ] pdlndoem C:\WINDOWS\System32\drivers\pdlndoem.sys
13:21:07.0500 3244 pdlndoem - ok
13:21:07.0515 3244 [ 3EC38683251ED7B106A4BD40573EDBAF ] pdlndqll C:\WINDOWS\System32\drivers\pdlndqll.sys
13:21:07.0515 3244 pdlndqll - ok
13:21:07.0515 3244 [ E4BC7DA128E2EB2B75E9D4BAA6516CD6 ] pdlndsdl C:\WINDOWS\System32\drivers\pdlndsdl.sys
13:21:07.0515 3244 pdlndsdl - ok
13:21:07.0515 3244 [ 5012598AB8E5782DCA0EB731CFB3C28D ] pdlndtdl C:\WINDOWS\System32\drivers\pdlndtdl.sys
13:21:07.0515 3244 pdlndtdl - ok
13:21:07.0531 3244 [ 0FCF7481C6711A7F9F57ADA5FCB2086B ] pdlnebas C:\WINDOWS\System32\drivers\pdlnebas.sys
13:21:07.0531 3244 pdlnebas - ok
13:21:07.0531 3244 [ 81FC43C810B0294C6780927DBEA55620 ] pdlnecfg C:\WINDOWS\System32\drivers\pdlnecfg.sys
13:21:07.0531 3244 pdlnecfg - ok
13:21:07.0546 3244 [ C5DD7C6B627E0DBC5D884D1403EDE193 ] pdlnemap C:\WINDOWS\System32\drivers\pdlnemap.sys
13:21:07.0546 3244 pdlnemap - ok
13:21:07.0546 3244 [ EEB1EB438B4CFDC258D1F0C91A95121B ] pdlnemsg C:\WINDOWS\System32\drivers\pdlnemsg.sys
13:21:07.0546 3244 pdlnemsg - ok
13:21:07.0546 3244 [ FFC666C4B486D68915E5236D81FD7D57 ] pdlnepkt C:\WINDOWS\System32\drivers\pdlnepkt.sys
13:21:07.0546 3244 pdlnepkt - ok
13:21:07.0562 3244 [ 6CF4B509DB89173563306CD101E729D7 ] pdlnshay C:\WINDOWS\System32\drivers\pdlnshay.sys
13:21:07.0562 3244 pdlnshay - ok
13:21:07.0562 3244 [ 3B634959ECD146934B4B8FB1C8A53D56 ] pdlnslea C:\WINDOWS\System32\drivers\pdlnslea.sys
13:21:07.0562 3244 pdlnslea - ok
13:21:07.0578 3244 [ 81BF76971A997564DEA6ADF4F82F65D0 ] pdlnsv25 C:\WINDOWS\System32\drivers\pdlnsv25.sys
13:21:07.0578 3244 pdlnsv25 - ok
13:21:07.0578 3244 [ 76A08D4C20DDCDF2204A2D2CE1E0F767 ] pdlnsx25 C:\WINDOWS\System32\drivers\pdlnsx25.sys
13:21:07.0578 3244 pdlnsx25 - ok
13:21:07.0578 3244 PDRELI - ok
13:21:07.0593 3244 PDRFRAME - ok
13:21:07.0593 3244 perc2 - ok
13:21:07.0593 3244 perc2hib - ok
13:21:07.0625 3244 [ 957B82EC80AD7EAD64E5E47DF6B0DC40 ] pfc C:\WINDOWS\system32\drivers\pfc.sys
13:21:07.0625 3244 pfc - ok
13:21:07.0671 3244 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\WINDOWS\system32\IoctlSvc.exe
13:21:07.0671 3244 PLFlash DeviceIoControl Service - ok
13:21:07.0671 3244 [ 26845F272435302E0F3322E660A24F7D ] PlugPlay C:\WINDOWS\system32\services.exe
13:21:07.0671 3244 PlugPlay - ok
13:21:07.0703 3244 [ 2B85237F904C5BDF7AD386F0EDE19BD3 ] PMEM C:\WINDOWS\system32\drivers\pmemnt.sys
13:21:07.0703 3244 PMEM - ok
13:21:07.0703 3244 [ 0815E8DA286775FA432C7C9EE5E10BA1 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
13:21:07.0703 3244 PolicyAgent - ok
13:21:07.0718 3244 [ 1C5CC65AAC0783C344F16353E60B72AC ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
13:21:07.0718 3244 PptpMiniport - ok
13:21:07.0750 3244 [ C73C8FB27A852A8832F5EAE2C59C23C5 ] PQNTDrv C:\WINDOWS\system32\drivers\PQNTDrv.sys
13:21:07.0750 3244 PQNTDrv - ok
13:21:07.0765 3244 [ 2BE7F01E46970E946AA18CBA3DE019EB ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
13:21:07.0765 3244 Processor - ok
13:21:07.0781 3244 [ 0815E8DA286775FA432C7C9EE5E10BA1 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
13:21:07.0781 3244 ProtectedStorage - ok
13:21:07.0781 3244 [ 48671F327553DCF1D27F6197F622A668 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
13:21:07.0781 3244 PSched - ok
13:21:07.0796 3244 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
13:21:07.0796 3244 Ptilink - ok
13:21:07.0812 3244 ql1080 - ok
13:21:07.0812 3244 Ql10wnt - ok
13:21:07.0812 3244 ql12160 - ok
13:21:07.0828 3244 ql1240 - ok
13:21:07.0828 3244 ql1280 - ok
13:21:07.0828 3244 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
13:21:07.0828 3244 RasAcd - ok
13:21:07.0875 3244 [ 84D4005E21A887F87D943D9526020531 ] RasAuto C:\WINDOWS\System32\rasauto.dll
13:21:07.0875 3244 RasAuto - ok
13:21:07.0890 3244 [ 98FAEB4A4DCF812BA1C6FCA4AA3E115C ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
13:21:07.0890 3244 Rasl2tp - ok
13:21:07.0890 3244 [ EDE7D761426CC2AFFF20A3A460F9C85E ] RasMan C:\WINDOWS\System32\rasmans.dll
13:21:07.0890 3244 RasMan - ok
13:21:07.0906 3244 [ 7306EEED8895454CBED4669BE9F79FAA ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
13:21:07.0906 3244 RasPppoe - ok
13:21:07.0906 3244 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
13:21:07.0906 3244 Raspti - ok
13:21:07.0921 3244 [ 29D66245ADBA878FFF574CD66ABD2884 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
13:21:07.0921 3244 Rdbss - ok
13:21:07.0937 3244 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
13:21:07.0937 3244 RDPCDD - ok
13:21:07.0968 3244 [ A2CAE2C60BC37E0751EF9DDA7CEAF4AD ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
13:21:07.0968 3244 rdpdr - ok
13:21:08.0000 3244 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
13:21:08.0000 3244 RDPWD - ok
13:21:08.0015 3244 [ CC0693C481502844A24EF71B90A7195E ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
13:21:08.0031 3244 RDSessMgr - ok
13:21:08.0031 3244 [ A8EEE004A16AF1D583D9DE9F6DE250E0 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
13:21:08.0031 3244 redbook - ok
13:21:08.0062 3244 [ D9FF0C4EB3A3AEDBA4E7D75A74097F3C ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
13:21:08.0062 3244 RemoteAccess - ok
13:21:08.0078 3244 [ 78FBE7DA29307EDE7ED0E33F1C4969BC ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
13:21:08.0093 3244 RemoteRegistry - ok
13:21:08.0109 3244 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7 ] ROOTMODEM C:\WINDOWS\system32\Drivers\RootMdm.sys
13:21:08.0109 3244 ROOTMODEM - ok
13:21:08.0140 3244 [ 33A8F0FE0005B2D79DF53441679F5149 ] RpcLocator C:\WINDOWS\system32\locator.exe
13:21:08.0140 3244 RpcLocator - ok
13:21:08.0171 3244 [ BC4E0226341AAEC1222336B3AED86BAB ] RpcSs C:\WINDOWS\System32\rpcss.dll
13:21:08.0171 3244 RpcSs - ok
13:21:08.0187 3244 [ DCE0D20F8FB66DF41D53734BFF9D66F0 ] RSVP C:\WINDOWS\system32\rsvp.exe
13:21:08.0187 3244 RSVP - ok
13:21:08.0234 3244 [ EE5AD71A1F576D4D58D8D014560EB856 ] rt2870 C:\WINDOWS\system32\DRIVERS\rt2870.sys
13:21:08.0234 3244 rt2870 - ok
13:21:08.0265 3244 [ 2E2E3A2D1BA5E540C32558F3F37D33E3 ] RTL8187B C:\WINDOWS\system32\DRIVERS\RTL8187B.sys
13:21:08.0265 3244 RTL8187B - ok
13:21:08.0296 3244 [ 0815E8DA286775FA432C7C9EE5E10BA1 ] SamSs C:\WINDOWS\system32\lsass.exe
13:21:08.0296 3244 SamSs - ok
13:21:08.0328 3244 [ 74B1E7FCFCA9A3A23871AA014144013E ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
13:21:08.0328 3244 SCardSvr - ok
13:21:08.0375 3244 [ 546254D4769E165CDC3388D74B201FCB ] Schedule C:\WINDOWS\system32\schedsvc.dll
13:21:08.0375 3244 Schedule - ok
13:21:08.0406 3244 [ D26E26EA516450AF9D072635C60387F4 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
13:21:08.0406 3244 Secdrv - ok
13:21:08.0437 3244 [ 241D074DAB2A67D2D7616CE7C8B05650 ] seclogon C:\WINDOWS\System32\seclogon.dll
13:21:08.0437 3244 seclogon - ok
13:21:08.0453 3244 [ 688BE760C858E347A4E23186B725C86B ] SENS C:\WINDOWS\system32\sens.dll
13:21:08.0453 3244 SENS - ok
13:21:08.0468 3244 [ A2D868AEEFF612E70E213C451A70CAFB ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
13:21:08.0468 3244 serenum - ok
13:21:08.0468 3244 [ DBAB3260E7EB3398CB87267D1410FAD4 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
13:21:08.0468 3244 Serial - ok
13:21:08.0500 3244 [ 0D13B6DF6E9E101013A7AFB0CE629FE0 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
13:21:08.0500 3244 Sfloppy - ok
13:21:08.0515 3244 [ 1DA364FA673E18BC1DE8F5CDF3657DBD ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
13:21:08.0531 3244 SharedAccess - ok
13:21:08.0531 3244 [ DCCC606FC144F6E44E497F9A906F1C30 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
13:21:08.0546 3244 ShellHWDetection - ok
13:21:08.0546 3244 Simbad - ok
13:21:08.0578 3244 [ 5CAEED86821FA2C6139E32E9E05CCDC9 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
13:21:08.0578 3244 SLIP - ok
13:21:08.0593 3244 [ A1ECEEAA5C5E74B2499EB51D38185B84 ] SONYPVU1 C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
13:21:08.0593 3244 SONYPVU1 - ok
13:21:08.0593 3244 Sparrow - ok
13:21:08.0625 3244 [ 8E186B8F23295D1E42C573B82B80D548 ] splitter C:\WINDOWS\system32\drivers\splitter.sys
13:21:08.0625 3244 splitter - ok
13:21:08.0640 3244 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
13:21:08.0640 3244 Spooler - ok
13:21:08.0671 3244 [ CDDDEC541BC3C96F91ECB48759673505 ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
13:21:08.0671 3244 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: CDDDEC541BC3C96F91ECB48759673505
13:21:08.0671 3244 sptd ( LockedFile.Multi.Generic ) - warning
13:21:08.0671 3244 sptd - detected LockedFile.Multi.Generic (1)
13:21:08.0734 3244 [ 9263C8898732E2B890F7E954E7729AB7 ] SQLWriter c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
13:21:08.0734 3244 SQLWriter - ok
13:21:08.0765 3244 [ 896F566AFC498077172EAE8A50E8BAF8 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
13:21:08.0765 3244 sr - ok
13:21:08.0765 3244 [ BA4E8AC9A60C4527C969D08F3ABE9D36 ] srservice C:\WINDOWS\system32\srsvc.dll
13:21:08.0765 3244 srservice - ok
13:21:08.0781 3244 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
13:21:08.0781 3244 Srv - ok
13:21:08.0812 3244 [ 64E44ACD8C238FCBBB78F0BA4BDC4B05 ] ssadbus C:\WINDOWS\system32\DRIVERS\ssadbus.sys
13:21:08.0812 3244 ssadbus - ok
13:21:08.0828 3244 [ BB2C84A15C765DA89FD832B0E73F26CE ] ssadmdfl C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys
13:21:08.0828 3244 ssadmdfl - ok
13:21:08.0843 3244 [ 6D0D132DDC6F43EDA00DCED6D8B1CA31 ] ssadmdm C:\WINDOWS\system32\DRIVERS\ssadmdm.sys
13:21:08.0843 3244 ssadmdm - ok
13:21:08.0859 3244 [ 1A5A397BC459F346AB56492B61EF79F6 ] ssadserd C:\WINDOWS\system32\DRIVERS\ssadserd.sys
13:21:08.0859 3244 ssadserd - ok
13:21:08.0875 3244 [ 1FBF38A525EEDD7402BFA7E27236A64F ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
13:21:08.0875 3244 SSDPSRV - ok
13:21:08.0906 3244 [ 2BB718BB4252909C389B3966492B0F30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
13:21:08.0906 3244 stisvc - ok
13:21:08.0921 3244 [ 284C57DF5DC7ABCA656BC2B96A667AFB ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
13:21:08.0921 3244 streamip - ok
13:21:08.0953 3244 [ 03C1BAE4766E2450219D20B993D6E046 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
13:21:08.0953 3244 swenum - ok
13:21:08.0984 3244 [ 94ABC808FC4B6D7D2BBF42B85E25BB4D ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
13:21:08.0984 3244 swmidi - ok
13:21:08.0984 3244 SwPrv - ok
13:21:09.0000 3244 symc810 - ok
13:21:09.0000 3244 symc8xx - ok
13:21:09.0000 3244 sym_hi - ok
13:21:09.0000 3244 sym_u3 - ok
13:21:09.0015 3244 [ 650AD082D46BAC0E64C9C0E0928492FD ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
13:21:09.0015 3244 sysaudio - ok
13:21:09.0031 3244 [ BC8B8694DEF74B4E6C626322D4321A54 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
13:21:09.0031 3244 SysmonLog - ok
13:21:09.0062 3244 [ 2F8CBA2D2A332EB5D2A7DC084E3B30B3 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
13:21:09.0062 3244 TapiSrv - ok
13:21:09.0078 3244 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
13:21:09.0078 3244 Tcpip - ok
13:21:09.0109 3244 [ 38D437CF2D98965F239B0ABCD66DCB0F ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
13:21:09.0109 3244 TDPIPE - ok
13:21:09.0125 3244 [ ED0580AF02502D00AD8C4C066B156BE9 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
13:21:09.0125 3244 TDTCP - ok
13:21:09.0140 3244 [ A540A99C281D933F3D69D55E48727F47 ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
13:21:09.0140 3244 TermDD - ok
13:21:09.0171 3244 [ C06CD1890279603E15020757E02DE56B ] TermService C:\WINDOWS\System32\termsrv.dll
13:21:09.0187 3244 TermService - ok
13:21:09.0187 3244 [ DCCC606FC144F6E44E497F9A906F1C30 ] Themes C:\WINDOWS\System32\shsvcs.dll
13:21:09.0187 3244 Themes - ok
13:21:09.0218 3244 [ 2A9DAAEF2CC0333DB6F129F2F8B3D3FD ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
13:21:09.0218 3244 TlntSvr - ok
13:21:09.0218 3244 TosIde - ok
13:21:09.0250 3244 [ BD9C5B92FD11B0B502499DC9991AE9D0 ] TrcBoot C:\WINDOWS\system32\drivers\trcboot.exe
13:21:09.0250 3244 TrcBoot - ok
13:21:09.0265 3244 [ 6C7F265BD43A1D85103EC5CB1251D2B6 ] TrkWks C:\WINDOWS\system32\trkwks.dll
13:21:09.0265 3244 TrkWks - ok
13:21:09.0359 3244 [ 9778AB648F4EF27BBE08E5A62704D093 ] TuneUp.UtilitiesSvc C:\Programmi\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
13:21:09.0375 3244 TuneUp.UtilitiesSvc - ok
13:21:09.0375 3244 [ F2107C9D85EC0DF116939CCCE06AE697 ] TuneUpUtilitiesDrv C:\Programmi\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys
13:21:09.0375 3244 TuneUpUtilitiesDrv - ok
13:21:09.0406 3244 [ 12F70256F140CD7D52C58C7048FDE657 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
13:21:09.0406 3244 Udfs - ok
13:21:09.0421 3244 ultra - ok
13:21:09.0421 3244 [ AFF2E5045961BBC0A602BB6F95EB1345 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
13:21:09.0421 3244 Update - ok
13:21:09.0453 3244 [ 55D9782BFE8C70B70E892E51566BF7D4 ] upnphost C:\WINDOWS\System32\upnphost.dll
13:21:09.0453 3244 upnphost - ok
13:21:09.0453 3244 upperdev - ok
13:21:09.0468 3244 [ E4896F38A3F8DACEA6EA8D7EC9889D91 ] UPS C:\WINDOWS\System32\ups.exe
13:21:09.0468 3244 UPS - ok
13:21:09.0484 3244 USBAAPL - ok
13:21:09.0484 3244 [ BFFD9F120CC63BCBAA3D840F3EEF9F79 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
13:21:09.0500 3244 usbccgp - ok
13:21:09.0515 3244 [ 15E993BA2F6946B2BFBBFCD30398621E ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
13:21:09.0515 3244 usbehci - ok
13:21:09.0546 3244 [ C72F40947F92CEA56A8FB532EDF025F1 ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
13:21:09.0546 3244 usbhub - ok
13:21:09.0562 3244 [ BDFE799A8531BAD8A5A985821FE78760 ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys
13:21:09.0562 3244 usbohci - ok
13:21:09.0578 3244 [ A42369B7CD8886CD7C70F33DA6FCBCF5 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
13:21:09.0578 3244 usbprint - ok
13:21:09.0609 3244 [ 6CD7B22193718F1D17A47A1CD6D37E75 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
13:21:09.0609 3244 USBSTOR - ok
13:21:09.0625 3244 [ 8968FF3973A883C49E8B564200F565B9 ] usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys
13:21:09.0625 3244 usbvideo - ok
13:21:09.0640 3244 [ FF7012ECF425959E4ACA0B568E281F48 ] UxTuneUp C:\WINDOWS\System32\uxtuneup.dll
13:21:09.0656 3244 UxTuneUp - ok
13:21:09.0687 3244 [ 94D73B62E458FB56C9CE60AA96D914F9 ] VClone C:\WINDOWS\system32\DRIVERS\VClone.sys
13:21:09.0687 3244 VClone - ok
13:21:09.0718 3244 [ 9EBEE4A060C5364A31AEAA04EAC2AF1E ] VComm C:\WINDOWS\system32\DRIVERS\VComm.sys
13:21:09.0718 3244 VComm - ok
13:21:09.0750 3244 [ 630BBDBF5490F8F57ABE650DA63661A0 ] VcommMgr C:\WINDOWS\system32\Drivers\VcommMgr.sys
13:21:09.0750 3244 VcommMgr - ok
13:21:09.0750 3244 [ 8A60EDD72B4EA5AEA8202DAF0E427925 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
13:21:09.0765 3244 VgaSave - ok
13:21:09.0765 3244 ViaIde - ok
13:21:09.0796 3244 [ 48007916B1D0DAB3E6C0D701DE7C4AFB ] VNA C:\WINDOWS\system32\DRIVERS\vna.sys
13:21:09.0796 3244 VNA - ok
13:21:09.0812 3244 [ 698869E82C57169F2140C04A272BF12B ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
13:21:09.0812 3244 VolSnap - ok
13:21:09.0828 3244 [ 147C653AD61BD01556723B3C8C4FAFC8 ] VSS C:\WINDOWS\System32\vssvc.exe
13:21:09.0843 3244 VSS - ok
13:21:09.0859 3244 [ C9A8BA443F809B70BCCCCD60CC73FA5C ] vulfnths C:\WINDOWS\System32\Drivers\vulfnth.sys
13:21:09.0859 3244 vulfnths - ok
13:21:09.0875 3244 [ 2D8C55889616F7767E9FB8ADEE37A02A ] vulfntrs C:\WINDOWS\System32\Drivers\vulfntr.sys
13:21:09.0875 3244 vulfntrs - ok
13:21:09.0906 3244 [ 8B97D00E5C6A593EBB605CE4B8A5CAA5 ] W32Time C:\WINDOWS\system32\w32time.dll
13:21:09.0921 3244 W32Time - ok
13:21:09.0921 3244 [ 984EF0B9788ABF89974CFED4BFBAACBC ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
13:21:09.0921 3244 Wanarp - ok
13:21:09.0953 3244 [ D918617B46457B9AC28027722E30F647 ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys
13:21:09.0968 3244 Wdf01000 - ok
13:21:09.0968 3244 WDICA - ok
13:21:09.0984 3244 [ 2797F33EBF50466020C430EE4F037933 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
13:21:09.0984 3244 wdmaud - ok
13:21:10.0000 3244 [ EBA8DEA9E279A9A50B608BFF3CBC2CDE ] WebClient C:\WINDOWS\System32\webclnt.dll
13:21:10.0000 3244 WebClient - ok
13:21:10.0062 3244 [ A91ACDD987DC3E0E1FCEDDA6F1FFEF2A ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
13:21:10.0062 3244 winmgmt - ok
13:21:10.0109 3244 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
13:21:10.0109 3244 WmdmPmSN - ok
13:21:10.0156 3244 [ F63CB6DBE268EA0620C67A90CF43885E ] Wmi C:\WINDOWS\System32\advapi32.dll
13:21:10.0156 3244 Wmi - ok
13:21:10.0187 3244 [ AE2C8544E747C20062DB27456EA2D67A ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
13:21:10.0187 3244 WmiAcpi - ok
13:21:10.0203 3244 [ 0EE2A2754039B13A632489726689DAD0 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
13:21:10.0203 3244 WmiApSrv - ok
13:21:10.0296 3244 [ F30DC8F80CF65A323E8B6A2DB81561E3 ] WMPNetworkSvc C:\Programmi\Windows Media Player\WMPNetwk.exe
13:21:10.0296 3244 WMPNetworkSvc - ok
13:21:10.0312 3244 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
13:21:10.0312 3244 WpdUsb - ok
13:21:10.0359 3244 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:21:10.0375 3244 WPFFontCache_v0400 - ok
13:21:10.0390 3244 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
13:21:10.0390 3244 WS2IFSL - ok
13:21:10.0421 3244 [ 17F70F4E37452A30C35565052AB68BE9 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
13:21:10.0421 3244 wscsvc - ok
13:21:10.0453 3244 [ D5842484F05E12121C511AA93F6439EC ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
13:21:10.0453 3244 WSTCODEC - ok
13:21:10.0484 3244 [ 4CBB7CC975E5B67022A7F95DFC6EF9EC ] wuauserv C:\WINDOWS\system32\wuauserv.dll
13:21:10.0484 3244 wuauserv - ok
13:21:10.0515 3244 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
13:21:10.0515 3244 WudfPf - ok
13:21:10.0546 3244 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
13:21:10.0546 3244 WudfRd - ok
13:21:10.0562 3244 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
13:21:10.0562 3244 WudfSvc - ok
13:21:10.0609 3244 [ 312913174D070ED81E9D78DA7B648774 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
13:21:10.0609 3244 WZCSVC - ok
13:21:10.0640 3244 [ 3208BAD59EFA3F4FCCCFBF1317F2A1C1 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
13:21:10.0640 3244 xmlprov - ok
13:21:10.0656 3244 ================ Scan global ===============================
13:21:10.0671 3244 [ 7B37B598B55BF80415C15BFFE7A992A2 ] C:\WINDOWS\system32\basesrv.dll
13:21:10.0703 3244 [ 7B39F8912DF2C266411F7248EC250AE6 ] C:\WINDOWS\system32\winsrv.dll
13:21:10.0718 3244 [ 7B39F8912DF2C266411F7248EC250AE6 ] C:\WINDOWS\system32\winsrv.dll
13:21:10.0734 3244 [ 26845F272435302E0F3322E660A24F7D ] C:\WINDOWS\system32\services.exe
13:21:10.0734 3244 [Global] - ok
13:21:10.0734 3244 ================ Scan MBR ==================================
13:21:10.0750 3244 [ 828E02D5C4A4FBE53441EE9DBEE51F43 ] \Device\Harddisk0\DR0
13:21:10.0875 3244 \Device\Harddisk0\DR0 - ok
13:21:10.0875 3244 ================ Scan VBR ==================================
13:21:10.0875 3244 [ 30634D6C2486F33FDB76758196BF43C3 ] \Device\Harddisk0\DR0\Partition1
13:21:10.0875 3244 \Device\Harddisk0\DR0\Partition1 - ok
13:21:10.0890 3244 [ EC1238BB1F75AE7F14460B005EB4DA47 ] \Device\Harddisk0\DR0\Partition2
13:21:10.0890 3244 \Device\Harddisk0\DR0\Partition2 - ok
13:21:10.0890 3244 ============================================================
13:21:10.0890 3244 Scan finished
13:21:10.0890 3244 ============================================================
13:21:10.0906 3712 Detected object count: 1
13:21:10.0906 3712 Actual detected object count: 1
13:21:15.0859 3712 sptd ( LockedFile.Multi.Generic ) - skipped by user
13:21:15.0859 3712 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

-----------------------------------------------------------------------------------------------------------------------------------------
AdwCleaner v2.101


# AdwCleaner v2.101 - Logfile creato il 19/12/2012 alle 13:17:39
# Aggiornamento 16/12/2012 by Xplode
# Sistema Operativo : Microsoft Windows XP Service Pack 3 (32 bits)
# Utente : f.tortoioli - N-TORTOIOLIF
# Modalità Avvio : Modalità Normale
# Eseguito da : C:\Downloads\AdwCleaner.exe
# Opzioni [Cerca]


***** [Servizi] *****


***** [File / Cartelle] *****

Cartella Trovato : C:\Documents and Settings\All Users\Dati applicazioni\Babylon
Cartella Trovato : C:\Documents and Settings\All Users\Dati applicazioni\Trymedia
Cartella Trovato : C:\Documents and Settings\F.Tortoioli\Dati applicazioni\Babylon
Cartella Trovato : C:\Documents and Settings\F.Tortoioli\Dati applicazioni\BabylonToolbar
Cartella Trovato : C:\Documents and Settings\F.Tortoioli\Dati applicazioni\FissaSearch
Cartella Trovato : C:\Documents and Settings\F.Tortoioli\Dati applicazioni\freeTVRadio
Cartella Trovato : C:\Programmi\AVG Secure Search
Cartella Trovato : C:\Programmi\Conduit
Cartella Trovato : C:\Programmi\File comuni\AVG Secure Search
Cartella Trovato : C:\Programmi\Yontoo
Cartella Trovato : C:\Programmi\yourfiledownloader
Cartella Trovato : C:\WINDOWS\Installer\{2C8574B5-6935-4FCE-860E-F4E8602378FF}
File Trovato : C:\Programmi\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Trovato : C:\Programmi\Mozilla Firefox\searchplugins\babylon.xml
File Trovato : C:\user.js

***** [Registro] *****

Chiave Trovata : HKCU\Software\BabylonToolbar
Chiave Trovata : HKCU\Software\FissaSearch
Chiave Trovata : HKCU\Software\freeTVRadio
Chiave Trovata : HKCU\Software\Microsoft\Babylon
Chiave Trovata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Chiave Trovata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E601996F-E400-41CA-804B-CD6373A7EEE2}
Chiave Trovata : HKCU\Software\Softonic
Chiave Trovata : HKLM\Software\Babylon
Chiave Trovata : HKLM\Software\BabylonToolbar
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Chiave Trovata : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Chiave Trovata : HKLM\SOFTWARE\Classes\b
Chiave Trovata : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Chiave Trovata : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Chiave Trovata : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Chiave Trovata : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Chiave Trovata : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B}
Chiave Trovata : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Chiave Trovata : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Chiave Trovata : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC}
Chiave Trovata : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
Chiave Trovata : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Chiave Trovata : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
Chiave Trovata : HKLM\SOFTWARE\Classes\escort.escortIEPane
Chiave Trovata : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Chiave Trovata : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Chiave Trovata : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc
Chiave Trovata : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1
Chiave Trovata : HKLM\SOFTWARE\Classes\Installer\Products\3192AA38321C641458DBDAF83979D193
Chiave Trovata : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Chiave Trovata : HKLM\SOFTWARE\Classes\Prod.cap
Chiave Trovata : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Chiave Trovata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Chiave Trovata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{83AA2913-C123-4146-85BD-AD8F93971D39}
Chiave Trovata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}
Chiave Trovata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3192AA38321C641458DBDAF83979D193
Chiave Trovata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83AA2913-C123-4146-85BD-AD8F93971D39}
Chiave Trovata : HKU\S-1-5-21-983971780-233310153-1287535205-17785\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Valore Trovata : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Valore Trovata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]

***** [Browser Internet] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registro Pulito.

*************************

AdwCleaner[R1].txt - [5590 octets] - [19/12/2012 12:50:19]
AdwCleaner[R2].txt - [5521 octets] - [19/12/2012 13:17:39]

########## EOF - C:\AdwCleaner[R2].txt - [5581 octets] ##########
 

Entra

oppure Accedi utilizzando
Discord Ufficiale Entra ora!

Discussioni Simili