------- Scansione supplementare -------
.
uStart Page = hxxp://WWW.BLUEWIN.CH/INDEX_I.HTML
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\programmi\Windows Live Toolbar\msntb.dll/search.htm
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {58B75CA3-C38C-4C39-8B43-7D4DF1EF1BE9} = 195.186.1.111,195.186.4.111
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\programmi\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Ciao\Dati applicazioni\Mozilla\Firefox\Profiles\s9k7bzkr.def ault\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.ch
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\npr pbrowserrecordplugin.dll
FF - component: c:\programmi\DoubleD\Desktop Smiley Toolbar\3.6.1.7000\FFToolbar\components\SmileyCore .dll
FF - component: c:\programmi\Internet Saving Optimizer\2.0.0.2440\FF\components\NPFFAddOn.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\programmi\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\programmi\Real\RealArcade\Plugins\Mozilla\nprac plug.dll
.

************************************************** ************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-24 17:13:46
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

************************************************** ************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(1732)
c:\windows\system32\Ati2evxx.dll
c:\programmi\Funk Software\Odyssey Client\odLogin.dll
.
Ora fine scansione: 2009-01-24 17:15:25
ComboFix-quarantined-files.txt 2009-01-24 16:15:23
ComboFix2.txt 2009-01-24 13:58:22

Pre-Run: 86'171'332'608 byte disponibili
Post-Run: 86,158,696,448 byte disponibili

207 --- E O F --- 2009-01-15 00:14:25