Marco -
06-10-25 20:25:15.82 Service Pack 2
ComboFix
06.10.19 - Running from: "C:\Documents and Settings\Marco\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Programmi\File comuni\Yazzle1122OinAdmin.exe
C:\Programmi\File comuni\Yazzle1122OinUninstaller.exe
C:\Programmi\PrintView
C:\Programmi\File comuni\{3068AF3A-0AF0-1040-0430-040501110 027}
C:\Programmi\File comuni\{C068AF3A-0AF0-1040-0430-040501110 027}
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Marco\Documenti\RACLE~1
C:\QooBox\Purity\Documents and Settings\Marco\Documenti\YSTEM~1
C:\QooBox\Purity\Documents and Settings\Marco\Documenti\YSTEM~1\explorer.exe
C:\QooBox\Purity\Documents and Settings\Marco\Documenti\YSTEM~1\?ystem
C:\QooBox\Purity\Programmi\ICROSO~1.NET
C:\QooBox\Purity\WINDOWS\DOBE~1
((((((((((((((((((((((((((((((( Files Created from 2006-09-25 to 2006-10-25 ))))))))))))))))))))))))))))))))))
2006-10-25 19:56 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-21 10:07 178,408 --a------ C:\WINDOWS\system32\muweb.dll
2006-10-21 10:07 128,744 --a------ C:\WINDOWS\system32\mucltui.dll
2006-10-20 18:54 28,672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys
2006-10-20 18:33 2 --a------ C:\WINDOWS\system32\wnstsit.exe
2006-10-20 18:22 107,747 --a------ C:\WINDOWS\system32\drv.exe
2006-10-20 18:21 155,267 --a------ C:\WINDOWS\system32\two.exe
2006-09-25 17:22 306,688 --a------ C:\WINDOWS\IsUninst.exe
2006-09-25 17:21 212,480 --a------ C:\WINDOWS\system32\PCDLIB32.DLL
2006-09-25 17:19 115,790 --a------ C:\WINDOWS\system32\drivers\MR97310v.sys
2006-09-25 16:24 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2006-09-25 16:24 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2006-09-25 16:24 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2006-09-25 16:24 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2006-09-25 16:24 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2006-09-25 16:23 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2006-09-25 16:23 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2006-09-25 16:23 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2006-09-25 16:13 61,440 --a------ C:\WINDOWS\system32\mr310ifv.dll
2006-09-25 16:13 49,152 --a------ C:\WINDOWS\system32\mr310exv.dll
2006-09-25 16:13 352,256 --a------ C:\WINDOWS\system32\ijl15.dll
2006-09-25 16:13 28,672 --a------ C:\WINDOWS\system32\mr310exd.dll
2006-09-25 16:13 205,824 --a------ C:\WINDOWS\system32\Vic32.dll
2006-09-25 16:13 135,168 --a------ C:\WINDOWS\system32\mr310ipv.dll
2006-09-25 15:26 516,096 --------- C:\WINDOWS\system32\ati2sgag.exe
2006-09-25 15:22 307,200 -ra------ C:\WINDOWS\system32\atiiiexx.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-10-25 20:28 -------- d-------- C:\Programmi\File comuni
2006-10-25 19:56 -------- d-------- C:\Programmi\Grisoft
2006-10-25 19:30 -------- d-------- C:\Programmi\Mozilla Firefox
2006-10-25 18:24 -------- d-------- C:\Programmi\eMule
2006-10-23 14:50 -------- d-------- C:\Programmi\SpywareBlaster
2006-10-21 18:15 11214 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2006-10-21 11:42 -------- d-------- C:\Programmi\MSXML 4.0
2006-10-20 20:49 -------- d-------- C:\Documents and Settings\Marco\Dati applicazioni\Sun
2006-10-20 20:47 -------- d-------- C:\Programmi\Java
2006-10-20 20:45 -------- d-------- C:\Programmi\File comuni\Java
2006-10-20 20:39 -------- d-------- C:\Documents and Settings\Marco\Dati applicazioni\Talkback
2006-10-20 20:38 -------- d-------- C:\Documents and Settings\Marco\Dati applicazioni\Mozilla
2006-10-20 20:35 -------- d-------- C:\Programmi\Google
2006-10-20 19:04 -------- d-------- C:\Programmi\Lavasoft
2006-10-20 19:04 -------- d-------- C:\Documents and Settings\Marco\Dati applicazioni\Lavasoft
2006-10-20 18:28 -------- d-------- C:\Programmi\MSN Messenger
2006-10-17 19:09 -------- d-------- C:\Documents and Settings\Marco\Dati applicazioni\AdobeUM
2006-10-15 14:50 -------- d-------- C:\Documents and Settings\Marco\Dati applicazioni\Google
2006-10-11 15:31 1002 --a------ C:\Documents and Settings\Marco\Dati applicazioni\AdobeDLM.log
2006-10-11 15:31 0 --a------ C:\Documents and Settings\Marco\Dati applicazioni\dm.ini
2006-10-11 15:31 -------- d-------- C:\Programmi\Adobe
2006-10-11 15:24 -------- d-------- C:\Programmi\File comuni\Adobe
2006-10-11 15:24 -------- d-------- C:\Documents and Settings\Marco\Dati applicazioni\Adobe
2006-09-25 17:22 -------- d-------- C:\Programmi\MGI
2006-09-25 17:19 -------- d-------- C:\Programmi\DC505
2006-09-25 15:27 -------- d-------- C:\Programmi\Internet Explorer
2006-09-25 15:26 -------- d--h----- C:\Programmi\InstallShield Installation Information
2006-09-25 15:26 -------- d-------- C:\Programmi\ATI Technologies
2006-09-13 07:03 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-12 17:51 1245184 --a------ C:\WINDOWS\system32\msxml4.dll
2006-08-25 17:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 14:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 11:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 13:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 15:25 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"LDM"="C:\\Programmi\\Logitech\\Desktop Messenger\\8876480\ \Program\\LogitechDesktopMessenger.exe"
"MsnMsgr"="\"C:\\Programmi\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Aid"="C:\\Documents and Settings\\Marco\\Documenti\\?racle\\w?wexec.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SiS Windows KeyHook"="C:\\WINDOWS\\system32\\keyhook.exe"
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"Smapp"="C:\\Programmi\\Analog Devices\\SoundMAX\\SMTray.ex e"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"nod32kui"="\"C:\\Programmi\\Eset\\nod32kui.exe\" /WAITSERV ICE"
"CnxDslTaskBar"="C:\\Programmi\\Conexant\\AccessRunner ADSL \\CnxDslTb.exe"
"zBrowser Launcher"="C:\\Programmi\\Logitech\\iTouch\\iTouc h.exe"
"Logitech Utility"="Logi_MwX.Exe"
"Ulead AutoDetector"="C:\\Programmi\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"PinnacleDriverCheck"="C:\\WINDOWS\\system32\\PSDrvCheck.exe -CheckReg"
"WinampAgent"="C:\\Programmi\\Winamp\\winampa.exe"
"DAEMON Tools-1033"="\"C:\\Programmi\\D-Tools\\daemon.exe\" -lang 1033"
"awxDTools"="rundll32 C:\\PROGRA~1\\arniWORX\\AWXDTO~1\\awx DTools.dll,awxRegisterDll /r /s"
"SunJavaUpdateSched"="C:\\Programmi\\Java\\jre1.5.0_06\\bin\ \jusched.exe"
"!AVG Anti-Spyware"="\"C:\\Programmi\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Pagina iniziale corrente"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00, 00,3a,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00, 00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00, ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00, a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Precaricatore Bro wseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Daemon di cache delle categorie di componenti"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
Completion time: 06-10-25 20:31:29.29
C:\ComboFix.txt ... 06-10-25 20:31
C:\ComboFix2.txt ... 06-10-25 20:23