Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- DDS (V*r_10-10-10.03) - NTFSx86
- Run by Raffa*lla at 23.59.12,50 on 17/10/2010
- Int*rn*t *xplor*r: 8.0.6001.18702 Brows*rJavaV*rsion: 1.6.0_21
- Microsoft Windows XP Prof*ssional 5.1.2600.3.1252.39.1040.18.3071.2411 [GMT 2:00]
- AV: AntiVir D*sktop *On-acc*ss scanning *nabl*d* (Updat*d) {AD166499-45F9-482A-A743-FDD3350758C7}
- ============== Running Proc*ss*s ===============
- C:\WINDOWS\syst*m32\svchost -k DcomLaunch
- svchost.*x*
- C:\WINDOWS\Syst*m32\svchost.*x* -k n*tsvcs
- svchost.*x*
- svchost.*x*
- C:\WINDOWS\*xplor*r.*X*
- C:\WINDOWS\syst*m32\spoolsv.*x*
- C:\Programmi\Avira\AntiVir D*sktop\sch*d.*x*
- C:\Programmi\Avira\AntiVir D*sktop\avguard.*x*
- svchost.*x*
- C:\Programmi\Avira\AntiVir D*sktop\avshadow.*x*
- C:\WINDOWS\syst*m32\nvsvc32.*x*
- C:\WINDOWS\RTHDCPL.*X*
- C:\WINDOWS\syst*m32\rundll32.*x*
- C:\Programmi\Avira\AntiVir D*sktop\avgnt.*x*
- C:\WINDOWS\syst*m32\RUNDLL32.*X*
- C:\WINDOWS\syst*m32\ctfmon.*x*
- C:\WINDOWS\syst*m32\rundll32.*x*
- C:\WINDOWS\Syst*m32\svchost.*x* -k HTTPFilt*r
- C:\WINDOWS\syst*m32\wscntfy.*x*
- C:\Programmi\Mozilla Fir*fox\fir*fox.*x*
- C:\Programmi\Mozilla Fir*fox\plugin-contain*r.*x*
- C:\WINDOWS\syst*m32\wuauclt.*x*
- C:\Docum*nts and S*ttings\Raffa*lla\Docum*nti\Download\dds.scr
- ============== Ps*udo HJT R*port ===============
- uStart Pag* = hxxp://www.t*l*2.it/
- uInt*rn*t Conn*ction Wizard,Sh*llN*xt = https://accounts*rvic*s.passport.n*t/r*g.srf?xpwiz=tru*&lc=1040&id=2
- uInt*rn*t S*ttings,ProxyOv*rrid* = *.local
- BHO: Adob* PDF Link H*lp*r: {18df081c-*8ad-4283-a596-fa578c2*bdc3} - c:\programmi\fil* comuni\adob*\acrobat\activ*x\AcroI*H*lp*rShim.dll
- BHO: Spybot-S&D I* Prot*ction: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDH*lp*r.dll
- BHO: Groov* GFS Brows*r H*lp*r: {72853161-30c5-4d22-b7f9-0bbc1d38a37*} - c:\progra~1\micros~2\offic*12\GRA8*1~1.DLL
- BHO: Java(tm) Plug-In 2 SSV H*lp*r: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmi\java\jr*6\bin\jp2ssv.dll
- BHO: Windows Liv* Toolbar H*lp*r: {*15a8dc0-8516-42a1-81*a-dc94*c1acf10} - c:\programmi\windows liv*\toolbar\wltcor*.dll
- TB: &Windows Liv* Toolbar: {21fa44*f-376d-4d53-9b0f-8a89d3229068} - c:\programmi\windows liv*\toolbar\wltcor*.dll
- uRun: [Googl* Updat*] "c:\docum*nts and s*ttings\raffa*lla\impostazioni locali\dati applicazioni\googl*\updat*\Googl*Updat*.*x*" /c
- uRun: [ctfmon.*x*] c:\windows\syst*m32\ctfmon.*x*
- mRun: [RTHDCPL] RTHDCPL.*X*
- mRun: [NvCplDa*mon] RUNDLL32.*X* c:\windows\syst*m32\NvCpl.dll,NvStartup
- mRun: [nwiz] nwiz.*x* /install
- mRun: [Blu*toothAuth*nticationAg*nt] rundll32.*x* bthprops.cpl,,Blu*toothAuth*nticationAg*nt
- mRun: [avgnt] "c:\programmi\avira\antivir d*sktop\avgnt.*x*" /min
- mRun: [NvM*diaC*nt*r] RUNDLL32.*X* c:\windows\syst*m32\NvMcTray.dll,NvTaskbarInit
- dRun: [CTFMON.*X*] c:\windows\syst*m32\CTFMON.*X*
- I*: *&sporta in Microsoft *xc*l - c:\progra~1\micros~2\offic*12\*XC*L.*X*/3000
- I*: {*2*2dd38-d088-4134-82b7-f2ba38496583} - %windir%\N*twork Diagnostic\xpn*tdiag.*x*
- I*: {FB5F1910-F110-11d2-BB9*-00C04F795683} - c:\programmi\m*ss*ng*r\msmsgs.*x*
- I*: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-*99415F33A*C} - c:\programmi\windows liv*\writ*r\Writ*rBrows*r*xt*nsion.dll
- I*: {2670000A-7350-4f3c-8081-5663**0C6C49} - {48*73304-*1D6-4330-914C-F5F514*3486C} - c:\progra~1\micros~2\offic*12\ONBttnI*.dll
- I*: {92780B25-18CC-41C8-B9B*-3C9C571A8263} - {FF059*31-CC5A-4*2*-BF3B-96*929D65503} - c:\progra~1\micros~2\offic*12\R*FI*BAR.DLL
- I*: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDH*lp*r.dll
- DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://m*ss*ng*r.zon*.msn.com/binary/msgrchkr.cab56986.cab
- DPF: {6414512B-B978-451D-A0D8-FCFDF33*833C} - hxxp://updat*.microsoft.com/windowsupdat*/v6/V5Controls/*n/x86/cli*nt/wuw*b_sit*.cab?1283152378250
- DPF: {6*32070A-766D-4**6-879C-DC1FA91D2FC3} - hxxp://www.updat*.microsoft.com/microsoftupdat*/v6/V5Controls/*n/x86/cli*nt/muw*b_sit*.cab?1287339498625
- DPF: {8AD9C840-044*-11D1-B3*9-00805F499D93} - hxxp://java.sun.com/updat*/1.6.0/jinstall-1_6_0_21-windows-i586.cab
- DPF: {C3F79A2B-B9B4-4A66-B012-3**46475B072} - hxxp://m*ss*ng*r.zon*.msn.com/binary/M*ss*ng*rStatsPACli*nt.cab56907.cab
- DPF: {CAF**FAC-0016-0000-0021-ABCD*FF*DCBA} - hxxp://java.sun.com/updat*/1.6.0/jinstall-1_6_0_21-windows-i586.cab
- DPF: {CAF**FAC-FFFF-FFFF-FFFF-ABCD*FF*DCBA} - hxxp://java.sun.com/updat*/1.6.0/jinstall-1_6_0_21-windows-i586.cab
- Handl*r: groov*LocalGWS - {88F*D34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\offic*12\GR99D3~1.DLL
- Handl*r: skyp*4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\fil*co~1\skyp*\SKYP*4~1.DLL
- SSODL: WPDShS*rvic*Obj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\syst*m32\WPDShS*rvic*Obj.dll
- S*H: Groov* GFS Stub *x*cution Hook: {b5a7f190-dda6-4420-b3ba-52453494*6cd} - c:\progra~1\micros~2\offic*12\GRA8*1~1.DLL
- Hosts: 127.0.0.1 www.spywar*info.com
- ================= FIR*FOX ===================
- FF - Profil*Path - c:\docum*~1\raffa*~1\datiap~1\mozilla\fir*fox\profil*s\avxky595.d*fault\
- FF - pr*fs.js: brows*r.s*arch.s*l*ct*d*ngin* - Googl*
- FF - pr*fs.js: brows*r.startup.hom*pag* - hxxp://forum.swzon*.it/sicur*zza/112786-virus-impossibil*-acc*d*r*-siti-microsoft-*-antivirus-22.html#post1129605
- FF - compon*nt: c:\programmi\mozilla fir*fox\*xt*nsions\{ab2c*124-6272-4b12-94a9-7303c7397bd1}\compon*nts\Skyp*FfCompon*nt.dll
- FF - plugin: c:\docum*nts and s*ttings\raffa*lla\dati applicazioni\fac*book\npfbplugin_1_0_3.dll
- FF - plugin: c:\docum*nts and s*ttings\raffa*lla\impostazioni locali\dati applicazioni\googl*\updat*\1.2.183.27\npGoogl*On*Click8.dll
- FF - plugin: c:\programmi\googl*\updat*\1.2.183.39\npGoogl*On*Click8.dll
- FF - plugin: c:\programmi\java\jr*6\bin\n*w_plugin\npd*ployJava1.dll
- FF - plugin: c:\programmi\microsoft\offic* liv*\npOLW.dll
- FF - plugin: c:\programmi\picasa2\npPicasa2.dll
- FF - plugin: c:\programmi\windows liv*\photo gall*ry\NPWLPG.dll
- FF - Hidd*n*xt*nsion: Java Consol*: No R*gistry R*f*r*nc* - c:\programmi\mozilla fir*fox\*xt*nsions\{CAF**FAC-0016-0000-0021-ABCD*FF*DCBA}
- ---- FIR*FOX POLICI*S ----
- c:\programmi\mozilla fir*fox\gr*pr*fs\all.js - pr*f("n*twork.IDN.whit*list.xn--mgbaam7a8h", tru*);
- c:\programmi\mozilla fir*fox\gr*pr*fs\all.js - pr*f("n*twork.IDN.whit*list.xn--mgb*rp4a5d4ar", tru*);
- ============= S*RVIC*S / DRIV*RS ===============
- R0 pavboot;pavboot;c:\windows\syst*m32\driv*rs\pavboot.sys [2010-10-17 28552]
- R1 avgio;avgio;c:\programmi\avira\antivir d*sktop\avgio.sys [2010-8-31 11608]
- R2 AntiVirSch*dul*rS*rvic*;Avira AntiVir Sch*dul*r;c:\programmi\avira\antivir d*sktop\sch*d.*x* [2010-8-31 135336]
- R2 AntiVirS*rvic*;Avira AntiVir Guard;c:\programmi\avira\antivir d*sktop\avguard.*x* [2010-8-31 267432]
- R2 avgntflt;avgntflt;c:\windows\syst*m32\driv*rs\avgntflt.sys [2009-5-18 60936]
- R3 RTLWUSB;N*TG*AR WG111v2 54Mbps Wir*l*ss USB 2.0 Adapt*r NT Driv*r;c:\windows\syst*m32\driv*rs\wg111v2.sys [2010-8-30 272128]
- S2 gupdat*1cb080*5*4928a7;S*rvizio di Googl* Updat* (gupdat*1cb080*5*4928a7);c:\programmi\googl*\updat*\Googl*Updat*.*x* [2010-6-9 133104]
- S3 npggsvc;nProt*ct Gam*Guard S*rvic*;c:\windows\syst*m32\gam*mon.d*s -s*rvic* --> c:\windows\syst*m32\Gam*Mon.d*s -s*rvic* [?]
- S4 TomTomHOM*S*rvic*;TomTomHOM*S*rvic*;c:\programmi\tomtom hom* 2\TomTomHOM*S*rvic*.*x* [2010-8-24 92008]
- =============== Cr*at*d Last 30 ================
- 2010-10-17 19:05:16 -------- d-sh--w- c:\docum*nts and s*ttings\raffa*lla\I*CompatCach*
- 2010-10-17 19:04:38 -------- d-sh--w- c:\docum*nts and s*ttings\raffa*lla\PrivacI*
- 2010-10-17 19:01:48 -------- d-sh--w- c:\docum*nts and s*ttings\raffa*lla\I*TldCach*
- 2010-10-17 18:33:06 -------- dc-h--w- c:\windows\i*8
- 2010-10-17 12:36:01 189520 ----a-w- c:\windows\syst*m32\driv*rs\tmcomm.sys
- 2010-10-17 12:33:21 28552 ----a-w- c:\windows\syst*m32\driv*rs\pavboot.sys
- 2010-10-17 12:32:39 -------- d-----w- c:\programmi\Panda S*curity
- 2010-10-17 11:38:06 -------- d-----w- c:\programmi\Spybot - S*arch & D*stroy
- 2010-10-17 11:38:06 -------- d-----w- c:\docum*~1\allus*~1\datiap~1\Spybot - S*arch & D*stroy
- 2010-10-16 13:35:28 -------- d-----w- c:\programmi\Divin*
- 2010-10-15 13:46:25 -------- d-----w- c:\programmi\Microsoft MIX Onlin*
- 2010-10-15 11:00:40 14048 ------w- c:\windows\syst*m32\spmsg2.dll
- 2010-10-15 10:57:52 -------- d-----w- c:\windows\syst*m32\XPSVi*w*r
- 2010-10-15 10:57:21 89088 ----a-w- c:\windows\syst*m32\spool\prtprocs\w32x86\filt*rpip*lin*printproc.dll
- 2010-10-15 10:56:57 89088 -c----w- c:\windows\syst*m32\dllcach*\filt*rpip*lin*printproc.dll
- 2010-10-15 10:56:57 597504 -c----w- c:\windows\syst*m32\dllcach*\printfilt*rpip*lin*svc.*x*
- 2010-10-15 10:56:57 597504 ------w- c:\windows\syst*m32\spool\prtprocs\w32x86\printfilt*rpip*lin*svc.*x*
- 2010-10-15 10:56:57 575488 -c----w- c:\windows\syst*m32\dllcach*\xpsshhdr.dll
- 2010-10-15 10:56:57 575488 ------w- c:\windows\syst*m32\xpsshhdr.dll
- 2010-10-15 10:56:57 117760 ------w- c:\windows\syst*m32\prntvpt.dll
- 2010-10-15 10:56:56 1676288 -c----w- c:\windows\syst*m32\dllcach*\xpssvcs.dll
- 2010-10-15 10:56:56 1676288 ------w- c:\windows\syst*m32\xpssvcs.dll
- 2010-10-15 10:56:56 -------- d-----w- C:\96d2a0f6c*f914d6c*dbb41cbf4**a
- 2010-10-15 10:47:41 -------- d-----r- C:\AHCach*
- 2010-10-15 10:13:40 -------- d-----w- c:\docum*~1\raffa*~1\datiap~1\JustR*siz*It.742*03C4887133A**1D0C646BCFAA94B0D0*9874.1
- 2010-10-15 10:11:13 -------- d-----w- c:\docum*~1\raffa*~1\datiap~1\com.l*vitation.ColorBrows*r.*8C85B0D1658562C6BF4**77663*B3C86B87123C.1
- 2010-10-15 09:56:07 -------- d-----w- c:\programmi\fil* comuni\Adob* AIR
- 2010-10-14 15:59:47 -------- d-----w- c:\programmi\GlobFX
- 2010-10-14 11:37:40 -------- d-----w- C:\gPotato.*u
- 2010-10-14 01:27:12 -------- d-----w- c:\programmi\N*ffy
- 2010-10-12 11:14:16 -------- d-----w- c:\docum*nts and s*ttings\raffa*lla\.n*tb*ans
- 2010-10-12 11:14:14 -------- d-----w- c:\docum*nts and s*ttings\raffa*lla\.n*tb*ans-r*gistration
- 2010-10-12 11:12:41 -------- d-----w- c:\docum*nts and s*ttings\raffa*lla\.nbi
- 2010-10-12 10:59:55 -------- d-----w- c:\docum*nts and s*ttings\raffa*lla\.W*bId*10
- 2010-10-04 16:59:48 1446264 ----a-w- c:\programmi\mozilla fir*fox\plugins\npL*gitCh*ckPlugin.dll
- 2010-10-04 16:40:27 -------- d-----w- c:\programmi\Windows M*dia Conn*ct 2
- 2010-10-04 16:38:54 -------- d-----w- c:\windows\syst*m32\LogFil*s
- 2010-10-04 16:38:50 26144 ----a-w- c:\windows\syst*m32\spupdsvc.*x*
- 2010-10-04 16:33:58 221184 ----a-w- c:\windows\syst*m32\wmpns.dll
- 2010-10-02 22:06:40 -------- d-----w- c:\docum*~1\raffa*~1\datiap~1\KompoZ*r
- 2010-10-01 12:37:04 -------- d-----w- c:\docum*~1\allus*~1\datiap~1\TomTom
- 2010-10-01 12:35:58 -------- d-----w- c:\docum*~1\raffa*~1\impost~1\datiap~1\TomTom
- 2010-10-01 12:35:58 -------- d-----w- c:\docum*~1\raffa*~1\datiap~1\TomTom
- 2010-10-01 12:35:53 -------- d-----w- c:\programmi\TomTom Int*rnational B.V
- 2010-10-01 12:35:32 -------- d-----w- c:\programmi\TomTom HOM* 2
- 2010-09-30 11:32:50 3591496 ----a-w- c:\windows\syst*m32\Gam*Mon.d*s
- 2010-09-30 11:30:33 5174 ----a-w- c:\windows\syst*m32\nppt9x.vxd
- 2010-09-30 11:30:33 4682 ----a-w- c:\windows\syst*m32\npptNT2.sys
- 2010-09-30 11:30:18 -------- d-----w- C:\Program Fil*s
- 2010-09-29 20:04:08 -------- d-----w- c:\programmi\*asyPHP-5.3.3
- 2010-09-29 11:34:19 73728 ----a-w- c:\windows\syst*m32\javacpl.cpl
- 2010-09-29 11:34:19 423656 ----a-w- c:\windows\syst*m32\d*ployJava1.dll
- 2010-09-29 11:34:19 423656 ----a-w- c:\programmi\mozilla fir*fox\plugins\npd*ployJava1.dll
- 2010-09-29 11:17:37 -------- d-----w- c:\docum*~1\raffa*~1\impost~1\datiap~1\T*mp
- 2010-09-29 11:04:08 -------- d-----w- c:\windows\syst*m32\NtmsData
- ==================== Find3M ====================
- 2010-08-10 03:15:58 94208 ----a-w- c:\windows\syst*m32\QuickTim*VR.qtx
- 2010-08-10 03:15:58 69632 ----a-w- c:\windows\syst*m32\QuickTim*.qts
- ============= FINISH: 0.00.50,62 ===============
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement