ComboFix 12-08-10.02 - Moonraine 12/08/2012 12:04:27.3.6 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1252.39.1033.18.4093.2640 [GMT 2:00]
Eseguito da: c:\users\Moonraine\Desktop\ComboFix.exe
Opzioni usate :: c:\users\Moonraine\Desktop\CFScript.txt.txt
AV: PC Tools Internet Security Anti-Virus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2}
FW: PC Tools Internet Security Firewall *Disabled* {175D0B73-9F8F-2CA9-8BF1-62277A276DC9}
SP: PC Tools Internet Security Anti-Spyware *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\IObit
c:\program files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll
c:\program files (x86)\IObit\IObit Malware Fighter\license.dat
c:\program files (x86)\IObit\IObit Malware Fighter\log\realtime\realtime_2012-08-06-18-51 .txt
c:\program files (x86)\IObit\IObit Malware Fighter\log\realtime\realtime_2012-08-06-18-53 .txt
c:\program files\Enigma Software Group
c:\program files\Enigma Software Group\SpyHunter\gil.dat
c:\program files\Enigma Software Group\SpyHunter\INSTALL.LOG
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20120806_154857.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20120806_160852.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20120806_161207.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20120806_172206.log
c:\program files\Enigma Software Group\SpyHunter\SpyHunter4.exe.BAK
c:\program files\Enigma Software Group\SpyHunter\SpyHunter4.exe.tmp
c:\program files\Enigma Software Group\SpyHunter\supportlog.txt
c:\users\Moonraine\AppData\Roaming\IObit
c:\users\Moonraine\AppData\Roaming\IObit\IObit Malware Fighter\config.ini
c:\users\Moonraine\AppData\Roaming\IObit\IObit Malware Fighter\ignore.ini
c:\users\Moonraine\AppData\Roaming\IObit\IObit Malware Fighter\remember.ini
c:\users\Moonraine\AppData\Roaming\TestApp
c:\users\Moonraine\AppData\Roaming\TestApp\TestApp.txt
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseCustomCall.dll
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseCustomCalla.dll
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseCustomCalla17.dll
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseCustomCalla18.exe
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseCustomCalla19.dll
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseCustomCalla2.dll
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseCustomCalla20.dll
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseCustomCalla21.exe
c:\windows\B3CB613C58D34692B2DA8F3EAC6288D4.TMP\WiseData.ini
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCall.dll
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla.dll
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla2.dll
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla21.dll
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla31.exe
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla32.dll
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla33.dll
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla34.dll
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla36.dll
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla36.exe
c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseData.ini
.
.
((((((((((((((((((((((((( Files Creati Da 2012-07-12 al 2012-08-12 )))))))))))))))))))))))))))))))))))
.
.
2012-08-12 10:08 . 2012-08-12 10:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-08 13:14 . 2012-08-08 13:14 -------- d-----w- c:\program files (x86)\ESET
2012-08-07 15:53 . 2012-08-07 15:53 -------- d-----w- c:\users\Moonraine\AppData\Local\Threat Expert
2012-08-06 17:06 . 2012-06-22 12:21 706776 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2012-08-06 17:06 . 2012-06-22 12:21 65664 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2012-08-06 17:06 . 2012-06-22 12:21 41968 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2012-08-06 17:04 . 2012-06-22 09:39 85224 ----a-w- c:\windows\system32\drivers\PCTBD64.sys
2012-08-06 16:56 . 2012-06-22 13:35 251560 ----a-w- c:\windows\system32\drivers\PCTSD64.sys
2012-08-06 16:56 . 2012-08-06 17:06 -------- d-----w- c:\programdata\PC Tools
2012-08-06 15:44 . 2012-08-06 20:12 -------- d-----w- c:\windows\system32\appmgmt
2012-08-06 12:42 . 2012-08-06 12:42 -------- d-----w- c:\users\Moonraine\AppData\Roaming\Malwarebytes
2012-08-06 12:42 . 2012-08-06 12:42 -------- d-----w- c:\programdata\Malwarebytes
2012-08-06 11:05 . 2012-07-03 16:21 142128 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-08-06 11:05 . 2012-07-03 16:21 266776 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-08-06 11:05 . 2012-07-03 16:21 19600 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-08-06 11:05 . 2012-06-27 20:33 12368 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-07-28 14:56 . 2012-08-06 13:59 -------- d-----w- c:\users\Moonraine\AppData\Local\TomTom
2012-07-28 14:56 . 2012-07-28 14:56 -------- d-----w- c:\program files (x86)\TomTom International B.V
2012-07-21 19:22 . 2012-07-21 19:22 -------- d-----w- c:\users\Moonraine\AppData\Local\Chromium
2012-07-21 11:00 . 2012-07-21 19:21 -------- d-----w- c:\programdata\Hi-Rez Studios
2012-07-18 15:15 . 2012-07-18 15:15 -------- d-----w- c:\programdata\Nokia
2012-07-18 14:33 . 2012-07-18 14:33 -------- d-----w- c:\program files (x86)\MSXML 4.0
2012-07-18 14:33 . 2012-07-18 14:33 73728 ----a-r- c:\users\Moonraine\AppData\Roaming\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\NewShortcut47_74B9CE5DF1F4447F982DCA29A461B529.exe
2012-07-18 14:33 . 2012-07-18 14:33 73728 ----a-r- c:\users\Moonraine\AppData\Roaming\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\NewShortcut46_74B9CE5DF1F4447F982DCA29A461B529.exe
2012-07-18 14:33 . 2012-07-18 14:33 53248 ----a-r- c:\users\Moonraine\AppData\Roaming\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\ARPPRODUCTICON.exe
2012-07-18 14:33 . 2012-07-18 14:33 49152 ----a-r- c:\users\Moonraine\AppData\Roaming\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\Uninstall_QA_OTI_H_FE5D756F71E147C4972AD6775344B40B.exe
2012-07-18 14:33 . 2012-07-18 14:33 49152 ----a-r- c:\users\Moonraine\AppData\Roaming\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\NewShortcut2_1C7B7089989A424FB39D41A32581C775.exe
2012-07-18 14:33 . 2012-07-18 15:15 -------- d-----w- c:\users\Moonraine\AppData\Local\Nokia
2012-07-18 14:25 . 2012-07-18 14:26 -------- d-----w- c:\users\Moonraine\AppData\Roaming\PC Suite
2012-07-18 14:25 . 2012-07-18 14:26 -------- d-----w- c:\users\Moonraine\AppData\Roaming\Nokia
2012-07-18 14:25 . 2012-07-18 14:25 -------- d-----w- c:\programdata\PC Suite
2012-07-18 14:25 . 2012-07-18 15:15 -------- d-----w- c:\program files (x86)\Common Files\Nokia
2012-07-18 14:25 . 2012-06-11 09:33 26112 ----a-w- c:\windows\system32\drivers\pccsmcfdx64.sys
2012-07-18 14:25 . 2012-07-18 14:25 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2012-07-18 14:25 . 2012-07-18 15:15 -------- d-----w- c:\program files (x86)\Nokia
2012-07-18 14:25 . 2012-01-09 15:28 57856 ----a-w- c:\windows\system32\nmwcdclsX64.dll
2012-07-18 14:23 . 2012-07-18 14:32 -------- d-----w- c:\programdata\Installations
2012-07-17 21:47 . 2012-07-17 21:47 -------- d-----w- c:\users\Moonraine\AppData\Local\CutePDF Writer
2012-07-17 21:46 . 2012-07-17 21:46 -------- d-----w- c:\program files (x86)\GPLGS
2012-07-17 21:45 . 2012-03-11 12:56 86608 ----a-w- c:\windows\system32\cpwmon64.dll
2012-07-17 21:45 . 2012-07-17 21:45 -------- d-----w- c:\program files (x86)\Acro Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-12 09:59 . 2012-03-28 08:15 25640 ----a-w- c:\windows\gdrv.sys
2012-08-11 16:23 . 2012-07-01 01:06 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-08-11 16:23 . 2012-07-01 00:54 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-08-11 13:05 . 2012-07-01 00:54 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-07-26 22:29 . 2012-03-28 21:52 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-26 22:29 . 2012-03-28 18:12 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-06 13:35 . 2012-07-01 00:54 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-07-04 18:09 . 2012-07-06 13:27 3130440 ----a-w- c:\windows\SysWow64\pbsvc_blr.exe
2012-07-03 16:21 . 2012-03-28 15:51 355856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2012-03-28 15:51 958400 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2012-03-28 15:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2012-03-28 15:51 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-07-03 16:21 . 2012-03-28 15:51 71064 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21 . 2012-03-28 15:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2012-03-28 15:51 41224 ----a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2012-03-28 15:51 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-07-03 16:21 . 2012-03-28 15:51 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-06-22 08:43 . 2012-08-06 17:04 3488 ----a-w- c:\windows\UDB.zip
2012-06-22 08:43 . 2012-08-06 17:04 131 ----a-w- c:\windows\IDB.zip
2012-06-16 21:54 . 2012-06-16 21:54 772592 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-06-02 22:19 . 2012-06-19 14:08 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 14:08 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-19 14:08 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 14:08 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 14:08 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-19 14:08 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-19 14:08 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-19 14:08 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-19 14:08 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-01 05:14 . 2012-06-01 05:14 3166792 ------w- c:\windows\SysWow64\pbsvc.exe
2012-01-24 11:50 . 2012-04-11 20:01 168864 ----a-w- c:\program files\Common Files\WireHelpSvc.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-07_20.11.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2012-08-07 19:39 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-08-12 10:01 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-08-12 10:01 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-07 19:39 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-03-28 07:56 . 2012-08-12 10:01 41654 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-08-12 10:01 33832 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-03-28 08:02 . 2012-08-12 10:01 12158 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2633914705-2322214657-749838959-1001_UserData.bin
+ 2012-03-28 16:47 . 2012-08-12 10:02 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-03-28 16:47 . 2012-08-07 19:40 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-03-28 16:47 . 2012-08-07 19:40 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-03-28 16:47 . 2012-08-12 10:02 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-08-12 10:02 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-07 19:40 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-03-28 07:56 . 2012-08-07 19:40 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-03-28 07:56 . 2012-08-12 09:59 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-03-28 07:56 . 2012-08-12 09:59 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-03-28 07:56 . 2012-08-07 19:40 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-03-28 07:56 . 2012-08-07 19:40 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-03-28 07:56 . 2012-08-12 09:59 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-03-28 07:56 . 2012-08-07 19:40 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-03-28 07:56 . 2012-08-12 10:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-03-28 07:56 . 2012-08-07 19:40 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-03-28 07:56 . 2012-08-12 10:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-08-07 19:39 . 2012-08-07 19:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-08-12 09:59 . 2012-08-12 09:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-08-07 19:39 . 2012-08-07 19:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-08-12 09:59 . 2012-08-12 09:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 04:54 . 2012-08-12 10:01 229376 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-03-28 08:46 . 2012-08-12 02:37 988856 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-07-14 05:01 . 2012-08-07 19:37 235256 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-08-12 02:37 235256 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 02:34 . 2012-08-07 15:28 9437184 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-08-11 10:56 9437184 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2012-03-30 19:13 . 2012-08-12 02:37 34007177 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2633914705-2322214657-749838959-1001-12288.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* I valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-03-28 742264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-03-09 636032]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe [2009-07-14 27136]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
R3 ASUSU1;ASUS Xonar U3 Audio Interface;c:\windows\system32\drivers\cm11264.sys [2010-12-15 1312256]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-18 113120]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD64.sys [2012-06-22 85224]
R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [2012-06-22 92928]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe [2012-06-22 402368]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2012-06-22 41968]
R3 ThreatFire;ThreatFire;c:\program files (x86)\PC Tools\PC Tools Security\TFEngine\TFService.exe service [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-04-25 52736]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-06-27 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [2012-04-23 426616]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2012-02-28 453896]
S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2012-02-28 1096176]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2012-06-22 65664]
S0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [2012-06-22 706776]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2010-04-06 21544]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [2012-06-22 341200]
S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [2012-06-22 251560]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-03-09 235520]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-03-08 361984]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-07-03 71064]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-07-03 133912]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-06-22 575448]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys [2012-01-24 147472]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe [2010-01-19 72304]
S2 WireHelpSvc;WireHelpSvc;c:\program files\Common Files\WireHelpSvc.exe [2012-01-24 168864]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-03-09 10857984]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-03-09 328704]
S3 busenum;SteelBusSvc;c:\windows\system32\DRIVERS\SteelBus64.sys [2011-09-16 106496]
S3 ESLvnic1;ESLvnic Virtual Network 64 Bit;c:\windows\system32\DRIVERS\ESLvnic.sys [2012-01-24 25528]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 75776]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 177152]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
S3 SAlphamHid;SteelHIDSvc;c:\windows\system32\DRIVERS\SAlpham64.sys [2011-09-16 34944]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cm112Sound"="c:\windows\Syswow64\cm112.dll" [2009-12-08 8146944]
"Cm112GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704]
"Cm112GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112]
.
------- Scansione supplementare -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://cool-itv.net
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://
www.google.ro
LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 62.101.93.101 83.103.25.250
FF - ProfilePath - c:\users\Moonraine\AppData\Roaming\Mozilla\Firefox\Profiles\chrmvr3o.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage -
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*v*à<¦_\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*ƒ=¦_]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*ƒ=¦_\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*e*l*l*<¦_\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m*p*4*!ú<\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m*p*4*°5Ág\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m*p*4*ß:3\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*R*e*d*T*u*b*e*_*-*_*C*u*t*e*_*G*I*r*l*_*g*I*v*¸0Æy\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*R*e*d*T*u*b*e*_*-*_*C*u*t*e*_*G*I*r*l*_*g*I*v*ݑ1O\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*R*e*d*T*u*b*e*_*-*_*C*u*t*e*_*G*I*r*l*_*g*I*v*-ØjG\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*R*e*d*T*u*b*e*_*-*_*C*u*t*e*_*G*I*r*l*_*g*I*v*ÏØjG\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*w*m*v*ˆaW\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.
<¦_]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.
<¦_\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*N<¦_]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*N<¦_\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*\?¦_]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*\?¦_\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*a*ƒ=¦_]
@Allowed: (Read) (RestrictedCode)
"0"=hex:32,00,36,00,30,00,32,00,32,00,30,00,31,00,31,00,30,00,37,00,2e,00,61,
00,83,3d,a6,5f,00,00,86,00,36,00,00,00,00,00,00,00,00,00,00,00,32,00,36,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.
<¦_]
@Allowed: (Read) (RestrictedCode)
"0"=hex:45,3a,5c,75,54,6f,72,72,65,6e,74,5c,42,72,75,63,65,20,41,6c,6d,69,67,
68,74,79,5c,78,78,78,5c,6e,65,77,5c,6e,65,77,5c,4e,65,77,5c,41,6d,61,74,65,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*N<¦_]
@Allowed: (Read) (RestrictedCode)
"0"=hex:6b,00,74,00,72,00,2e,00,74,00,69,00,66,00,66,00,70,00,2e,00,31,00,31,
00,2e,00,30,00,37,00,2e,00,4e,3c,a6,5f,00,00,96,00,36,00,00,00,00,00,00,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-2633914705-2322214657-749838959-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*\?¦_]
@Allowed: (Read) (RestrictedCode)
"0"=hex:6b,00,74,00,72,00,2e,00,74,00,69,00,66,00,66,00,70,00,2e,00,31,00,31,
00,2e,00,30,00,37,00,2e,00,5c,3f,a6,5f,00,00,96,00,36,00,00,00,00,00,00,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2012-08-12 12:10:18
ComboFix-quarantined-files.txt 2012-08-12 10:10
ComboFix2.txt 2012-08-08 13:09
ComboFix3.txt 2012-08-07 20:13
.
Pre-Run: 66.838.994.944 bytes free
Post-Run: 66.582.867.968 bytes free
.
- - End Of File - - 5CA4EFBBB62179BC58418892B693D94B