ComboFix 10-03-29.04 - Matteo 01/04/2010 17.08.09.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1015.668 [GMT 2:00]
Eseguito da: c:\documents and settings\Matteo\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
c:\documents and settings\Matteo\Dati applicazioni\avdrn.dat
c:\recycler\S-1-5-21-426921485-1057647532-1183075387-1003
c:\windows\6kSRh.exe
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Creati Da 2010-03-01 al 2010-04-01 )))))))))))))))))))))))))))))))))))
.
2010-04-01 15:02 . 2010-04-01 15:02 2809344 ----a-w- c:\documents and settings\All Users\Dati applicazioni\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe
2010-04-01 15:00 . 2010-04-01 15:00 2288640 ----a-w- c:\windows\system32\TUKernel.exe
2010-04-01 14:21 . 2010-02-25 11:00 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-04-01 14:21 . 2010-02-25 10:53 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-04-01 14:21 . 2010-04-01 14:21 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\TuneUp Software
2010-04-01 14:21 . 2010-04-01 14:24 -------- d-----w- c:\programmi\TuneUp Utilities 2010
2010-04-01 14:20 . 2010-04-01 14:21 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TuneUp Software
2010-04-01 14:20 . 2010-04-01 14:20 -------- d-sh--w- c:\documents and settings\All Users\Dati applicazioni\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-04-01 14:15 . 2010-04-01 14:16 -------- d-----w- c:\programmi\RegCleaner
2010-04-01 14:06 . 2010-04-01 14:06 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\Uniblue
2010-04-01 14:06 . 2010-04-01 14:06 -------- d-----w- c:\programmi\Uniblue
2010-03-31 14:37 . 2010-04-01 13:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-03-31 09:43 . 2010-04-01 13:38 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-03-31 09:43 . 2010-03-31 12:21 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-03-31 09:21 . 2010-03-31 09:21 167936 ----a-w- c:\windows\EoPBv8d3t.exe
2010-03-31 09:14 . 2010-03-31 10:09 -------- d-----w- c:\windows\system32\drivers\sysmgr
2010-03-30 21:26 . 2010-03-30 21:26 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\Orangeline Interactive
2010-03-30 21:26 . 2010-03-30 21:26 -------- d-----w- c:\documents and settings\Matteo\Impostazioni locali\Dati applicazioni\Orangeline_Interactive
2010-03-30 21:26 . 2010-03-30 21:26 -------- d-----w- c:\programmi\Citrus Alarm Clock
2010-03-30 12:54 . 2010-03-30 12:54 -------- d-----w- c:\programmi\WireWorld 3D Screensaver
2010-03-30 12:43 . 2005-09-05 04:01 1056768 ----a-w- c:\windows\system32\FreeImage.dll
2010-03-29 11:32 . 2010-03-29 11:53 -------- d-----w- c:\programmi\File comuni\AVSMedia
2010-03-29 11:32 . 2007-02-27 16:36 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2010-03-29 11:32 . 2007-02-27 16:36 24576 ----a-w- c:\windows\system32\msxml3a.dll
2010-03-28 17:14 . 2010-03-28 17:14 503808 ----a-w- c:\documents and settings\Matteo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\5 4\1a209876-4b484543-n\msvcp71.dll
2010-03-28 17:14 . 2010-03-28 17:14 499712 ----a-w- c:\documents and settings\Matteo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\5 4\1a209876-4b484543-n\jmc.dll
2010-03-28 17:14 . 2010-03-28 17:14 348160 ----a-w- c:\documents and settings\Matteo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\5 4\1a209876-4b484543-n\msvcr71.dll
2010-03-28 17:14 . 2010-03-28 17:14 61440 ----a-w- c:\documents and settings\Matteo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\1 7\6d0ad391-7169c018-n\decora-sse.dll
2010-03-28 17:14 . 2010-03-28 17:14 12800 ----a-w- c:\documents and settings\Matteo\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\1 7\6d0ad391-7169c018-n\decora-d3d.dll
2010-03-23 21:25 . 2010-03-23 21:25 -------- d-----w- c:\programmi\CCleaner
2010-03-23 18:43 . 2010-03-23 18:43 -------- d--h--w- c:\windows\PIF
2010-03-23 18:37 . 2010-03-30 07:57 1 ----a-w- c:\documents and settings\Matteo\Dati applicazioni\OpenOffice.org\3\user\uno_packages\ca che\stamp.sys
2010-03-23 18:37 . 2010-03-23 18:37 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\OpenOffice.org
2010-03-23 18:36 . 2010-03-23 18:36 7424000 ----a-r- c:\documents and settings\Matteo\Dati applicazioni\Microsoft\Installer\{D61B4347-26FD-40F5-92B7-5D020E574DFE}\soffice.exe
2010-03-23 18:35 . 2010-03-23 18:35 -------- d-----w- c:\programmi\JRE
2010-03-23 18:35 . 2010-03-23 18:35 -------- d-----w- c:\programmi\OpenOffice.org 3
2010-03-23 18:35 . 2010-03-23 18:35 -------- d-----w- c:\programmi\File comuni\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
2010-03-31 23:08 . 2009-11-22 17:23 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\uTorrent
2010-03-31 22:55 . 2009-12-27 03:02 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\vlc
2010-03-31 06:42 . 2009-05-11 21:51 84440 ----a-w- c:\windows\system32\perfc010.dat
2010-03-31 06:42 . 2009-05-11 21:51 489192 ----a-w- c:\windows\system32\perfh010.dat
2010-03-29 11:34 . 2009-09-27 21:17 49912 ----a-w- c:\documents and settings\Matteo\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-03-23 20:32 . 2009-05-11 21:33 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-03-23 18:34 . 2009-12-19 17:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-22 18:23 . 2009-05-11 20:02 76875 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-22 18:13 . 2009-09-27 23:21 1530 ----a-w- c:\documents and settings\Matteo\Dati applicazioni\wklnhst.dat
2010-02-25 20:12 . 2010-02-25 20:12 35808 ---ha-w- c:\windows\system32\mlfcache.dat
2010-02-24 17:28 . 2010-02-24 17:28 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\Template
2010-02-21 12:25 . 2010-02-20 18:15 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\Apple Computer
2010-02-21 11:30 . 2010-02-21 11:29 -------- d-----w- c:\programmi\File comuni\DVDVideoSoft
2010-02-21 11:29 . 2010-02-21 11:29 -------- d-----w- c:\programmi\DVDVideoSoft
2010-02-20 21:41 . 2010-02-20 21:41 -------- d-----w- c:\documents and settings\Matteo\Dati applicazioni\dvdcss
2010-02-20 18:15 . 2010-02-20 18:14 -------- d-----w- c:\programmi\iTunes
2010-02-20 18:15 . 2010-02-20 18:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-02-20 18:14 . 2010-02-20 18:14 -------- d-----w- c:\programmi\iPod
2010-02-20 18:14 . 2010-02-20 18:10 -------- d-----w- c:\programmi\File comuni\Apple
2010-02-20 18:14 . 2010-02-20 18:13 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
2010-02-20 18:13 . 2010-02-20 18:13 -------- d-----w- c:\programmi\Bonjour
2010-02-20 18:13 . 2010-02-20 18:13 -------- d-----w- c:\programmi\QuickTime
2010-02-20 18:12 . 2010-02-20 18:12 -------- d-----w- c:\programmi\Apple Software Update
2010-02-20 18:10 . 2010-02-20 18:10 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple
2010-02-15 17:41 . 2010-02-15 17:41 72488 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-09 10:05 . 2010-02-09 09:57 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-01-11 15:23 . 2010-01-11 15:21 45808 ----a-w- c:\documents and settings\Guest\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.ex e" [2007-12-19 131072]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-27 17881088]
"AsusACPIServer"="c:\programmi\EeePC\ACPI\AsAcpiSv r.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\programmi\EeePC\ACPI\AsEPCMon .exe" [2009-03-13 98304]
"AsusTray"="c:\programmi\EeePC\ACPI\AsTray.exe " [2009-04-16 118784]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh. exe" [2009-03-06 1434920]
"SynAsusAcpi"="c:\programmi\Synaptics\SynTP\SynAsu sAcpi.exe" [2009-03-06 79144]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Matteo\Menu Avvio\Programmi\Esecuzione automatica\
Citrus Alarm Clock.lnk - c:\programmi\Citrus Alarm Clock\Citrus Alarm Clock.exe [2010-3-30 406016]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
SuperHybridEngine.lnk - c:\programmi\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-5-11 376832]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Dati applicazioni\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 ----a-w- c:\programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.e xe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-15 17:07 141608 ----a-w- c:\programmi\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\programmi\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 14:21 246504 ----a-w- c:\programmi\File comuni\Java\Java Update\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\ASUS\\EzMessenger\\Clotho.exe" =
"c:\\Programmi\\ASUS\\EzMessenger\\EzMessenger.exe "=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmi\\File comuni\\Adobe\\CS4ServiceManager\\CS4ServiceManage r.exe"=
"c:\\Programmi\\Pinnacle\\VideoSpin\\Programs\\Vid eoSpin.exe"=
"c:\\Programmi\\Pinnacle\\VideoSpin\\Programs\\RM. exe"=
"c:\\Programmi\\Pinnacle\\VideoSpin\\Programs\\umi .exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\QuickTime\\QuickTimePlayer.exe "=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:*isabled:Adobe CSI CS4
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\programmi\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [25/02/2010 12.57.22 1047880]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\programmi \TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14/10/2009 7.24.44 10064]
S2 WDI;Windows Device Instrumentation;"c:\windows\system32\drivers\sysmg r\svchost.exe" [31/03/2010 11.14.17 167936]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfil t.sys [11/05/2009 22.33.24 1684736]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwd x.sys [31/03/2010 11.43.17 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [31/03/2010 11.43.17 30104]
S3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sy s [28/04/2009 3.59.09 38912]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [11/05/2009 22.35.48 966912]
S3 SRS_PremiumSound_Service;SRS Labs Premium Sound;c:\windows\system32\drivers\SRS_PremiumSound _i386.sys [12/05/2009 0.31.12 232872]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [28/04/2009 7.47.12 39040]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.