Codice:
ComboFix 11-01-20.04 - Davide 21/01/2011 20:35:37.1.4 - x86 NETWORK
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.39.1040.18.3575.2805 [GMT 1:00]
Eseguito da: c:\users\Davide\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\302639201.dll
c:\windows\system32\asd
c:\windows\system32\asd\AccurateShutdown.exe
c:\windows\system32\asd\adkt.dll
c:\windows\system32\asd\date.cfg
c:\windows\system32\asd\desktop.ini
c:\windows\system32\asd\doit.exe
c:\windows\system32\asd\help.chm
c:\windows\system32\asd\images\but0.gif
c:\windows\system32\asd\images\but1.gif
c:\windows\system32\asd\images\but2.gif
c:\windows\system32\asd\images\but3.gif
c:\windows\system32\asd\images\ch0.gif
c:\windows\system32\asd\images\ch1.gif
c:\windows\system32\asd\images\ch2.gif
c:\windows\system32\asd\images\ch3.gif
c:\windows\system32\asd\images\ch4.gif
c:\windows\system32\asd\images\ch5.gif
c:\windows\system32\asd\images\ch6.gif
c:\windows\system32\asd\images\ch7.gif
c:\windows\system32\asd\images\i30.gif
c:\windows\system32\asd\images\i31.gif
c:\windows\system32\asd\images\i310.gif
c:\windows\system32\asd\images\i311.gif
c:\windows\system32\asd\images\i32.gif
c:\windows\system32\asd\images\i33.gif
c:\windows\system32\asd\images\i34.gif
c:\windows\system32\asd\images\i35.gif
c:\windows\system32\asd\images\i36.gif
c:\windows\system32\asd\images\i37.gif
c:\windows\system32\asd\images\i38.gif
c:\windows\system32\asd\images\i39.gif
c:\windows\system32\asd\images\iclose0.gif
c:\windows\system32\asd\images\iclose1.gif
c:\windows\system32\asd\images\opt0.gif
c:\windows\system32\asd\images\opt1.gif
c:\windows\system32\asd\images\opt2.gif
c:\windows\system32\asd\images\opt3.gif
c:\windows\system32\asd\images\opt4.gif
c:\windows\system32\asd\images\opt5.gif
c:\windows\system32\asd\images\opt6.gif
c:\windows\system32\asd\images\opt7.gif
c:\windows\system32\asd\images\tbk.gif
c:\windows\system32\asd\images\tit.gif
c:\windows\system32\asd\images\title.gif
c:\windows\system32\asd\loadqm.exe
c:\windows\system32\asd\mylng.cfg
c:\windows\system32\asd\newsdsave.dll
c:\windows\system32\asd\poki.sys
c:\windows\system32\asd\rule.cfg
c:\windows\system32\asd\unins00.dat
c:\windows\system32\asd\unins00.exe
c:\windows\system32\asd\unins000.exe
c:\windows\system32\asd\w1.wav
c:\windows\system32\asd\YFSysKeys.ocx
c:\windows\system32\k_KBD0.dll
c:\windows\system32\k_KBD2.dll
c:\windows\system32\KBD2.dll
c:\windows\system32\sysogg.dll
.
((((((((((((((((((((((((( Files Creati Da 2010-12-21 al 2011-01-21 )))))))))))))))))))))))))))))))))))
.
2011-01-21 19:40 . 2011-01-21 19:40 -------- d-----w- c:\users\Davide\AppData\Local\temp
2011-01-21 19:40 . 2011-01-21 19:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-21 16:08 . 2011-01-21 16:08 -------- d-----w- c:\users\Davide\AppData\Roaming\Malwarebytes
2011-01-21 16:06 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-21 16:06 . 2011-01-21 16:06 -------- d-----w- c:\programdata\Malwarebytes
2011-01-21 16:06 . 2011-01-21 17:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-21 16:06 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-21 15:35 . 2011-01-21 17:00 -------- d-----w- c:\programdata\REPORTS
2011-01-21 15:35 . 2011-01-21 17:00 -------- d-----w- c:\programdata\INFECTED
2011-01-21 15:35 . 2011-01-21 16:48 -------- d-----w- c:\programdata\LOGFILES
2011-01-21 15:20 . 2011-01-21 17:23 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-21 15:20 . 2011-01-21 17:23 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-01-21 15:05 . 2011-01-21 17:23 -------- d-----w- c:\users\Davide\AppData\Roaming\Msnet
2011-01-18 10:46 . 2011-01-18 10:46 -------- d-----w- c:\users\Davide\AppData\Local\PackageAware
2011-01-18 09:55 . 2011-01-21 17:23 -------- d-----w- c:\programdata\IObit
2011-01-17 21:24 . 2011-01-21 17:24 -------- d-----w- c:\program files\avisplit
2011-01-17 09:37 . 2011-01-17 09:37 -------- d-----w- c:\users\Davide\AppData\Roaming\bKhRbhdpG
2011-01-17 09:36 . 2011-01-17 09:39 -------- d-----w- c:\program files\ConvertGenius
2011-01-17 08:46 . 2011-01-21 17:23 -------- d-----w- c:\users\Davide\AppData\Roaming\WinAVI
2011-01-17 08:46 . 2011-01-17 08:46 -------- d-----w- c:\users\Davide\AppData\Local\WinAVI
2011-01-17 08:46 . 2011-01-21 17:23 -------- d-----w- c:\program files\Video Converter
2011-01-17 08:41 . 2011-01-17 08:41 -------- d-----w- c:\users\Davide\AppData\Local\IsolatedStorage
2011-01-17 08:41 . 2011-01-18 08:22 -------- d-----w- c:\program files\Swf2Avi
2011-01-16 22:10 . 2011-01-16 22:10 -------- d-----w- c:\users\Davide\AppData\Local\Xara
2011-01-16 22:08 . 2011-01-16 22:08 -------- d-----w- c:\program files\Common Files\MAGIX Services
2011-01-16 18:42 . 2011-01-16 18:42 -------- d-----w- c:\program files\PC Magazine Utilities
2011-01-16 18:24 . 2011-01-16 18:24 -------- d-----w- c:\users\Davide\AppData\Local\Microsoft_Corporation
2011-01-12 22:24 . 2011-01-12 22:24 -------- d-----w- c:\users\Davide\AppData\Roaming\Thinstall
2011-01-12 22:24 . 2011-01-12 22:24 -------- d-----w- c:\users\Davide\AppData\Local\Thinstall
2011-01-12 21:15 . 2011-01-12 21:17 -------- d-----w- c:\program files\Exif Pilot Pro Demo
2011-01-12 15:59 . 2011-01-12 15:59 -------- d-----w- c:\programdata\FileCure
2011-01-12 11:29 . 2011-01-12 11:29 -------- d-----w- c:\users\Davide\AppData\Local\Apps
2011-01-11 22:39 . 2011-01-11 22:41 -------- d-----w- c:\program files\GPicSync
2011-01-11 19:18 . 2011-01-21 17:23 -------- d-----w- c:\programdata\Yahoo! Companion
2011-01-10 22:45 . 2002-06-13 12:50 376832 ----a-w- c:\windows\system32\actskin4.ocx
2011-01-10 22:45 . 2011-01-10 22:45 -------- d-----w- c:\program files\Ogg Converter
2011-01-09 20:03 . 2011-01-09 20:07 -------- d-----w- c:\users\Davide\AppData\Roaming\U3
2011-01-07 09:45 . 2011-01-07 09:45 -------- d-----w- c:\users\Davide\AppData\Local\ElevatedDiagnostics
2011-01-06 15:39 . 2011-01-06 15:39 -------- d-----w- c:\users\Davide\AppData\Roaming\Auslogics
2011-01-06 15:18 . 2011-01-06 15:18 -------- d-----w- c:\users\Davide\AppData\Roaming\Avira
2011-01-06 13:58 . 2011-01-06 15:47 -------- d-----w- c:\program files\Yahoo!
2011-01-06 13:58 . 2011-01-06 15:47 -------- d-----w- c:\program files\CCleaner
2011-01-06 10:27 . 2011-01-12 22:24 -------- d-----w- c:\program files\Exifer
2011-01-06 10:22 . 2011-01-12 21:17 -------- d-----w- c:\users\Davide\AppData\Roaming\Two Pilots
2011-01-06 10:22 . 2011-01-11 22:48 -------- d-----w- c:\program files\Exif Pilot
2011-01-05 22:51 . 2011-01-06 15:47 -------- d-----w- c:\program files\PhotoME
2011-01-05 22:50 . 2011-01-08 15:01 -------- d-----w- c:\program files\Opanda
2011-01-05 12:24 . 2011-01-06 15:47 -------- d-----w- c:\program files\CrystalDiskInfo
2011-01-05 09:21 . 2011-01-06 15:47 -------- d-----w- c:\program files\File Type Manager
2011-01-05 09:21 . 2011-01-05 09:21 249856 ------w- c:\windows\Setup1.exe
2011-01-05 09:21 . 2011-01-05 09:21 73216 ----a-w- c:\windows\ST6UNST.EXE
2011-01-04 22:34 . 2001-03-12 16:07 260096 ----a-w- c:\windows\system32\richtx32.ocx
2011-01-04 22:34 . 2011-01-05 22:51 -------- d-----w- c:\programdata\PhotoME
2011-01-03 18:50 . 2011-01-06 15:47 -------- d-----w- c:\program files\iTunes
2011-01-03 18:50 . 2011-01-03 18:50 -------- d-----w- c:\program files\iPod
2010-12-28 22:38 . 2010-12-28 22:38 -------- d-----w- c:\users\Davide\AppData\Roaming\AVCWare
2010-12-28 22:36 . 2010-12-28 22:36 -------- d-----w- c:\program files\AVCWare
2010-12-28 22:04 . 2011-01-16 19:39 -------- d-----w- c:\users\Davide\AppData\Local\Nero
2010-12-28 18:41 . 2010-12-28 18:43 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2010-12-28 18:30 . 2011-01-06 15:47 -------- d-----w- c:\program files\Adobe Media Player
2010-12-28 18:28 . 2010-12-28 18:28 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-12-28 18:24 . 2010-12-28 18:24 -------- d-----w- c:\programdata\Adobe Systems
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 13:13 . 2010-03-17 23:09 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-21 13:13 . 2010-03-17 23:09 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-09 15:06 . 2010-03-19 22:07 215152 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-11-09 15:01 . 2010-03-19 14:28 137200 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-11-09 15:01 . 2010-03-19 14:28 215152 ----a-w- c:\windows\system32\PnkBstrB.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"="c:\program files\Mozilla Thunderbird\thunderbird -turbo" [X]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2010-03-18 323392]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"$Volumouse$"="c:\program files\Volumouse\volumouse.exe" [2009-08-05 33280]
"Linktree"="c:\users\Davide\AppData\Roaming\Msnet\treecsc.exe" [2011-01-21 280576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-09-01 281768]
"mylbx"="c:\program files\My Lockbox\mylbx.exe" [2009-08-20 1075888]
"Arctosa"="c:\program files\Razer\Arctosa\razerhid.exe" [2009-08-19 232960]
"Lachesis"="c:\program files\Razer\Lachesis\razerhid.exe" [2009-11-10 248320]
"NBAgent"="c:\program files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-04-02 1234216]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-03 98304]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"TrayServer"="c:\progra~1\MAGIX\Video_deluxe_17_Premium_Download-Version\TrayServer.exe" [2008-08-07 90112]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-12-20 443728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-12-20 443728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-04-27 697328]
R2 acedrv10;acedrv10;c:\windows\system32\drivers\acedrv10.sys [2007-07-24 328824]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-08-04 176128]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [2009-05-03 73392]
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2010-06-11 312152]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-12-20 363344]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-03-12 86016]
R2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2009-11-12 220128]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-08-04 6096384]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-08-04 214016]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2010-07-15 101904]
R3 cpuz130;cpuz130;c:\users\Davide\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-12-20 20952]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 544768]
S0 FSProFilter;FSPro File Filter;c:\windows\System32\Drivers\FSPFltd.sys [2008-06-05 43792]
S0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\DRIVERS\pssnap.sys [2008-05-20 15328]
S2 acehlp10;acehlp10;c:\windows\system32\drivers\acehlp10.sys [2007-07-11 201848]
S3 ArcFltr;Arctosa Keyboard;c:\windows\system32\Drivers\Arctosa.sys [2009-08-19 16000]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2009-09-28 12032]
S3 RTL8167;Driver Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
.
------- Scansione supplementare -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Locate Spot on Map by GPS - c:\program files\Opanda\IExif 2.3\IExifMap.htm
IE: View Exif/GPS/IPTC with IExif - c:\program files\Opanda\IExif 2.3\IExifCom.htm
FF - ProfilePath - c:\users\Davide\AppData\Roaming\Mozilla\Firefox\Profiles\lxeo54m2.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - www.google.it | www.facebook.it
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Tab Mix Plus: {dc572301-7619-498c-a57d-39143191b318} - %profile%\extensions\{dc572301-7619-498c-a57d-39143191b318}
FF - Ext: Easy Youtube Video Downloader: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} - %profile%\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
FF - Ext: <?xmlversion=1.0?><RDF xmlns=http://www.w3.org/1999/02/22-rdf-syntax-ns# xmlns:em=http://www.mozilla.org/2004/em-rdf#><Description about=urn:mozilla:install-manifest><em:id>{a3442e61-57b7-4a7f-b0c8-e1e20a2278a9}: {a3442e61-57b7-4a7f-b0c8-e1e20a2278a9} - %profile%\extensions\{a3442e61-57b7-4a7f-b0c8-e1e20a2278a9}
FF - Ext: Toggle Private Browsing: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Personas: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: Locationbar²: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Tab Wheel Scroll: tabscroll@mthamil - %profile%\extensions\tabscroll@mthamil
FF - Ext: Speed Dial: {64161300-e22b-11db-8314-0800200c9a66} - %profile%\extensions\{64161300-e22b-11db-8314-0800200c9a66}
FF - Ext: FireGestures: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Scroll Search Engines: [email protected] - %profile%\extensions\[email protected]
FF - Ext: PhotoJacker: Photo Album Downloader for Facebook (fka FacePAD): [email protected] - %profile%\extensions\[email protected]
FF - Ext: Facebook Chat History Manager: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Site Launcher: {20291fcc-1471-46c8-8213-5911f5ce6d67} - %profile%\extensions\{20291fcc-1471-46c8-8213-5911f5ce6d67}
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKLM-RunOnce-<NO NAME> - (no file)
AddRemove-Accurate Shutdown_is1 - c:\windows\system32\asd\unins000.exe
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-3285024216-181935409-538795150-1000\Software\SecuROM\License information*]
"datasecu"=hex:56,86,1d,68,4a,40,7e,97,d9,27,db,00,18,59,9a,3f,0d,31,b6,4d,83,
4b,47,5d,84,f6,e9,91,3c,a2,63,57,c5,62,38,e9,c4,8b,02,9a,56,0c,cb,c0,72,0b,\
"rkeysecu"=hex:a2,28,f6,59,fa,28,22,98,3a,b7,c2,0a,2a,51,f9,98
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence"="0108804-1F5A-6507-CB3C-E8BB"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2011-01-21 20:41:50
ComboFix-quarantined-files.txt 2011-01-21 19:41
Pre-Run: 37.394.911.232 byte disponibili
Post-Run: 37.292.785.664 byte disponibili
- - End Of File - - BB120FA699C02A10B42AD18397FA09C0
La scansione completa con Avira non l'ho finita, dovrei lasciarlo acceso tutta la notte per quanto è lento. Comunque ormai sembra certo che i file di sistema siano danneggiati. Proverò in ogni caso a completare la scansione di Avira prima di passare a rimedi più drastici.