itamax
2010-05-28, 17:19
Hi,
Spybot S&D detected:
Smitfraud-C.gp: [SBI $EE2EF3B5] Impostazioni utente (Chiave di registro, nothing done) HKEY_USERS\S-1-5-21-329068152-1972579041-725345543-1004\Software\Alexa Internet
I tried to fix it with Spybot, but subsequent scans have again found Smitfraud-C.gp.
Is there a way to remove it definitively?
Thank you in advance,
Massimo
Here DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Massimo at 15.04.45,14 on 28/05/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.3071.1119 [GMT 2:00]
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {00000000-F0B8-0012-00E9-917C0802927C}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
============== Running Processes ===============
E:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Programmi\Avira\AntiVir Desktop\sched.exe
svchost.exe
E:\Programmi\Avira\AntiVir Desktop\avguard.exe
E:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
E:\Programmi\Bonjour\mDNSResponder.exe
E:\Programmi\Cisco Systems\VPN Client\cvpnd.exe
E:\Programmi\Java\jre6\bin\jqs.exe
E:\WINDOWS\system32\nvsvc32.exe
e:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
E:\WINDOWS\system32\svchost.exe -k imgsvc
E:\WINDOWS\system32\SearchIndexer.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\RTHDCPL.EXE
E:\Programmi\TortoiseSVN\bin\TSVNCache.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
E:\Programmi\Avira\AntiVir Desktop\avgnt.exe
E:\Programmi\EPSON\Creativity Suite\Event Manager\EEventManager.exe
E:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
E:\Programmi\Avira\AntiVir Desktop\avmailc.exe
E:\Programmi\Avira\AntiVir Desktop\AVWEBGRD.EXE
E:\Programmi\iTunes\iTunesHelper.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Programmi\Eraser\eraser.exe
E:\WINDOWS\system32\wbem\wmiapsrv.exe
E:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
E:\Programmi\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
E:\Programmi\Windows Desktop Search\WindowsSearch.exe
E:\Documents and Settings\Massimo\Dati applicazioni\Dropbox\bin\Dropbox.exe
E:\Programmi\iPod\bin\iPodService.exe
E:\Programmi\File comuni\Nokia\NoA\nokiaaserver.exe
E:\Programmi\PC Connectivity Solution\ServiceLayer.exe
E:\Programmi\Mozilla Thunderbird 3\thunderbird.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Programmi\Mozilla Firefox\firefox.exe
E:\Programmi\FreeCommander\FreeCommander.exe
E:\wamp\wampmanager.exe
e:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
e:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe
E:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
E:\Programmi\Zend\Zend Studio - 7.2.0\ZendStudio.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Programmi\Core Services\IETester\IETester.exe
E:\Programmi\Core Services\IETester\IETester.exe
E:\Programmi\Skype\Phone\Skype.exe
E:\Programmi\Cisco Systems\VPN Client\vpngui.exe
E:\Programmi\WinSCP\WinSCP.exe
E:\Programmi\Microsoft Visual Studio 9.0\Common7\IDE\VWDExpress.exe
E:\Programmi\TrueCrypt\TrueCrypt.exe
E:\Programmi\PSPad editor\PSPad.exe
E:\Programmi\Spybot - Search & Destroy\SpybotSD.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
E:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\WINDOWS\system32\SearchProtocolHost.exe
E:\Documents and Settings\Massimo\Documenti\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.mammapermamma.eu/
uInternet Settings,ProxyOverride = *.local
BHO: Supporto di collegamento per Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - e:\programmi\file comuni\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\progra~1\spybot~1\SDHelper.dll
BHO: DebugBar BHO: {69fc0024-10eb-480a-bbf2-3bf4e78e17b1} - e:\programmi\core services\debugbar\DebugInfoBar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - e:\programmi\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - e:\programmi\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - e:\programmi\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\programmi\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\programmi\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: La barra dell'accessibilità: {11352a67-0178-46b1-8855-d50b2f81c054} - e:\programmi\accessibility_toolbar\Accessibility_Toolbar.dll
TB: Alexa: {ea582743-9076-4178-9aa6-7393fdf4d5ce} - e:\programmi\alexa toolbar\AlxTB2.9.39.dll
TB: DebugBar: {3e1201f4-1707-409f-bb45-a5f192381da0} - e:\programmi\core services\debugbar\DebugToolBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - e:\programmi\google\google toolbar\GoogleToolbar_32.dll
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - e:\programmi\internet explorer\iedvtool.dll
EB: {A202B231-EF71-4A08-BDB9-4CE5AE8BDE0A} - No File
uRun: [CTFMON.EXE] e:\windows\system32\ctfmon.exe
uRun: [Eraser] e:\programmi\eraser\eraser.exe -hide
uRun: [Google Update] "e:\documents and settings\massimo\impostazioni locali\dati applicazioni\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] e:\programmi\spybot - search & destroy\TeaTimer.exe
uRun: [<NO NAME>]
uRun: [NokiaOviSuite2] e:\programmi\nokia\nokia ovi suite\NokiaOviSuite.exe -tray
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE e:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE e:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [ISUSPM Startup] e:\progra~1\fileco~1\instal~1\update~1\isuspm.exe -startup
mRun: [ISUSScheduler] "e:\programmi\file comuni\installshield\updateservice\issch.exe" -start
mRun: [avgnt] "e:\programmi\avira\antivir desktop\avgnt.exe" /min
mRun: [EEventManager] e:\programmi\epson\creativity suite\event manager\EEventManager.exe
mRun: [Adobe Reader Speed Launcher] "e:\programmi\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "e:\programmi\file comuni\adobe\arm\1.0\AdobeARM.exe"
mRun: [NokiaMServer] e:\programmi\file comuni\nokia\mplatform\NokiaMServer /watchfiles startup
mRun: [QuickTime Task] "e:\programmi\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "e:\programmi\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "e:\programmi\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] e:\windows\system32\CTFMON.EXE
StartupFolder: e:\docume~1\massimo\menuav~1\progra~1\esecuz~1\dropbox.lnk - e:\documents and settings\massimo\dati applicazioni\dropbox\bin\Dropbox.exe
StartupFolder: e:\docume~1\alluse~1\menuav~1\progra~1\esecuz~1\vpncli~1.lnk - e:\windows\installer\{ccbaa1f7-e5e1-48b2-9ed9-a79c6a37ce78}\Icon3E5562ED7.ico
StartupFolder: e:\docume~1\alluse~1\menuav~1\progra~1\esecuz~1\window~1.lnk - e:\programmi\windows desktop search\WindowsSearch.exe
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - e:\windows\web\related.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\programmi\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC} - e:\programmi\java\jre6\bin\jp2iexp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\progra~1\spybot~1\SDHelper.dll
LSP: e:\programmi\avira\antivir desktop\avsda.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1213525945812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - e:\programmi\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.2 formamed_en.localhost
Hosts: 192.168.2.9 HP001F2972AB38
================= FIREFOX ===================
FF - ProfilePath - e:\docume~1\massimo\datiap~1\mozilla\firefox\profiles\gnxcvenx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1460988&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.mammapermamma.eu/
FF - component: e:\documents and settings\massimo\dati applicazioni\mozilla\firefox\profiles\gnxcvenx.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll
FF - component: e:\documents and settings\massimo\dati applicazioni\mozilla\firefox\profiles\gnxcvenx.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\winnt_x86-msvc\components\pagespeed.dll
FF - plugin: e:\documents and settings\massimo\impostazioni locali\dati applicazioni\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: e:\programmi\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: e:\programmi\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: e:\programmi\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: e:\programmi\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - e:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - e:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
e:\programmi\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
e:\programmi\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
e:\programmi\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
e:\programmi\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
e:\programmi\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
e:\programmi\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
e:\programmi\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
e:\programmi\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
e:\programmi\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
e:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
e:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
e:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;e:\programmi\avira\antivir desktop\avgio.sys [2009-4-29 11608]
R1 Ext2Fsd;Linux ext2 file system driver;e:\windows\system32\drivers\ext2fsd.sys [2009-1-15 651264]
R2 AntiVirMailService;Avira AntiVir MailGuard;e:\programmi\avira\antivir desktop\avmailc.exe [2009-4-29 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;e:\programmi\avira\antivir desktop\sched.exe [2009-4-29 108289]
R2 AntiVirService;Avira AntiVir Guard;e:\programmi\avira\antivir desktop\avguard.exe [2009-4-29 185089]
R2 AntiVirWebService;Avira AntiVir WebGuard;e:\programmi\avira\antivir desktop\avwebgrd.exe [2009-4-29 434945]
R2 avgntflt;avgntflt;e:\windows\system32\drivers\avgntflt.sys [2009-4-29 56816]
R2 NPF;NetGroup Packet Filter Driver;e:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R3 vsdatant;vsdatant;e:\windows\system32\vsdatant.sys [2005-1-26 280344]
S2 gupdate;Servizio di Google Update (gupdate);e:\programmi\google\update\GoogleUpdate.exe [2010-2-25 135664]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;e:\windows\system32\drivers\bsusbser.sys [2008-6-19 94848]
============== File Associations ===============
.txt=txt_auto_file
=============== Created Last 30 ================
2010-05-24 09:56:15 7375 ----a-w- e:\documents and settings\massimo\.recently-used.xbel
2010-05-07 07:33:38 0 d-----w- e:\windows\Internet Logs
2010-05-07 07:33:22 127376 ----a-w- e:\windows\system32\drivers\dne2000.sys
2010-05-07 07:33:22 101904 ----a-w- e:\windows\system32\dneinobj.dll
2010-05-07 07:33:13 0 d-----w- e:\programmi\file comuni\Deterministic Networks
2010-05-07 07:33:12 0 d-----w- e:\programmi\Cisco Systems
2010-05-07 07:33:02 1593 ----a-w- e:\windows\VPNInstall.MIF
2010-05-05 12:41:55 0 d-----w- e:\programmi\Arena
2010-05-03 07:52:52 0 d-----w- e:\programmi\iPod
2010-05-03 07:52:48 0 d-----w- e:\programmi\iTunes
2010-05-03 07:49:29 0 d-----w- e:\programmi\Bonjour
==================== Find3M ====================
2010-04-20 08:39:10 411368 ----a-w- e:\windows\system32\deployJava1.dll
2010-04-20 08:38:49 619536 ----a-w- e:\windows\system32\perfh010.dat
2010-04-20 08:38:49 134646 ----a-w- e:\windows\system32\perfc010.dat
2010-04-08 11:20:02 91424 ----a-w- e:\windows\system32\dnssd.dll
2010-04-08 11:20:02 107808 ----a-w- e:\windows\system32\dns-sd.exe
2010-03-10 06:15:53 420352 ----a-w- e:\windows\system32\vbscript.dll
2010-03-08 16:14:37 27524 ---ha-w- e:\windows\system32\mlfcache.dat
============= FINISH: 15.05.11,67 ===============
Spybot S&D detected:
Smitfraud-C.gp: [SBI $EE2EF3B5] Impostazioni utente (Chiave di registro, nothing done) HKEY_USERS\S-1-5-21-329068152-1972579041-725345543-1004\Software\Alexa Internet
I tried to fix it with Spybot, but subsequent scans have again found Smitfraud-C.gp.
Is there a way to remove it definitively?
Thank you in advance,
Massimo
Here DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Massimo at 15.04.45,14 on 28/05/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.3071.1119 [GMT 2:00]
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {00000000-F0B8-0012-00E9-917C0802927C}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
============== Running Processes ===============
E:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Programmi\Avira\AntiVir Desktop\sched.exe
svchost.exe
E:\Programmi\Avira\AntiVir Desktop\avguard.exe
E:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
E:\Programmi\Bonjour\mDNSResponder.exe
E:\Programmi\Cisco Systems\VPN Client\cvpnd.exe
E:\Programmi\Java\jre6\bin\jqs.exe
E:\WINDOWS\system32\nvsvc32.exe
e:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
E:\WINDOWS\system32\svchost.exe -k imgsvc
E:\WINDOWS\system32\SearchIndexer.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\RTHDCPL.EXE
E:\Programmi\TortoiseSVN\bin\TSVNCache.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Programmi\File comuni\InstallShield\UpdateService\issch.exe
E:\Programmi\Avira\AntiVir Desktop\avgnt.exe
E:\Programmi\EPSON\Creativity Suite\Event Manager\EEventManager.exe
E:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
E:\Programmi\Avira\AntiVir Desktop\avmailc.exe
E:\Programmi\Avira\AntiVir Desktop\AVWEBGRD.EXE
E:\Programmi\iTunes\iTunesHelper.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Programmi\Eraser\eraser.exe
E:\WINDOWS\system32\wbem\wmiapsrv.exe
E:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
E:\Programmi\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
E:\Programmi\Windows Desktop Search\WindowsSearch.exe
E:\Documents and Settings\Massimo\Dati applicazioni\Dropbox\bin\Dropbox.exe
E:\Programmi\iPod\bin\iPodService.exe
E:\Programmi\File comuni\Nokia\NoA\nokiaaserver.exe
E:\Programmi\PC Connectivity Solution\ServiceLayer.exe
E:\Programmi\Mozilla Thunderbird 3\thunderbird.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Programmi\Mozilla Firefox\firefox.exe
E:\Programmi\FreeCommander\FreeCommander.exe
E:\wamp\wampmanager.exe
e:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
e:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe
E:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
E:\Programmi\Zend\Zend Studio - 7.2.0\ZendStudio.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Programmi\Core Services\IETester\IETester.exe
E:\Programmi\Core Services\IETester\IETester.exe
E:\Programmi\Skype\Phone\Skype.exe
E:\Programmi\Cisco Systems\VPN Client\vpngui.exe
E:\Programmi\WinSCP\WinSCP.exe
E:\Programmi\Microsoft Visual Studio 9.0\Common7\IDE\VWDExpress.exe
E:\Programmi\TrueCrypt\TrueCrypt.exe
E:\Programmi\PSPad editor\PSPad.exe
E:\Programmi\Spybot - Search & Destroy\SpybotSD.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
E:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Massimo\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
E:\WINDOWS\system32\SearchProtocolHost.exe
E:\Documents and Settings\Massimo\Documenti\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.mammapermamma.eu/
uInternet Settings,ProxyOverride = *.local
BHO: Supporto di collegamento per Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - e:\programmi\file comuni\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\progra~1\spybot~1\SDHelper.dll
BHO: DebugBar BHO: {69fc0024-10eb-480a-bbf2-3bf4e78e17b1} - e:\programmi\core services\debugbar\DebugInfoBar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - e:\programmi\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - e:\programmi\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - e:\programmi\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\programmi\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\programmi\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: La barra dell'accessibilità: {11352a67-0178-46b1-8855-d50b2f81c054} - e:\programmi\accessibility_toolbar\Accessibility_Toolbar.dll
TB: Alexa: {ea582743-9076-4178-9aa6-7393fdf4d5ce} - e:\programmi\alexa toolbar\AlxTB2.9.39.dll
TB: DebugBar: {3e1201f4-1707-409f-bb45-a5f192381da0} - e:\programmi\core services\debugbar\DebugToolBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - e:\programmi\google\google toolbar\GoogleToolbar_32.dll
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - e:\programmi\internet explorer\iedvtool.dll
EB: {A202B231-EF71-4A08-BDB9-4CE5AE8BDE0A} - No File
uRun: [CTFMON.EXE] e:\windows\system32\ctfmon.exe
uRun: [Eraser] e:\programmi\eraser\eraser.exe -hide
uRun: [Google Update] "e:\documents and settings\massimo\impostazioni locali\dati applicazioni\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] e:\programmi\spybot - search & destroy\TeaTimer.exe
uRun: [<NO NAME>]
uRun: [NokiaOviSuite2] e:\programmi\nokia\nokia ovi suite\NokiaOviSuite.exe -tray
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE e:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE e:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [ISUSPM Startup] e:\progra~1\fileco~1\instal~1\update~1\isuspm.exe -startup
mRun: [ISUSScheduler] "e:\programmi\file comuni\installshield\updateservice\issch.exe" -start
mRun: [avgnt] "e:\programmi\avira\antivir desktop\avgnt.exe" /min
mRun: [EEventManager] e:\programmi\epson\creativity suite\event manager\EEventManager.exe
mRun: [Adobe Reader Speed Launcher] "e:\programmi\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "e:\programmi\file comuni\adobe\arm\1.0\AdobeARM.exe"
mRun: [NokiaMServer] e:\programmi\file comuni\nokia\mplatform\NokiaMServer /watchfiles startup
mRun: [QuickTime Task] "e:\programmi\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "e:\programmi\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "e:\programmi\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] e:\windows\system32\CTFMON.EXE
StartupFolder: e:\docume~1\massimo\menuav~1\progra~1\esecuz~1\dropbox.lnk - e:\documents and settings\massimo\dati applicazioni\dropbox\bin\Dropbox.exe
StartupFolder: e:\docume~1\alluse~1\menuav~1\progra~1\esecuz~1\vpncli~1.lnk - e:\windows\installer\{ccbaa1f7-e5e1-48b2-9ed9-a79c6a37ce78}\Icon3E5562ED7.ico
StartupFolder: e:\docume~1\alluse~1\menuav~1\progra~1\esecuz~1\window~1.lnk - e:\programmi\windows desktop search\WindowsSearch.exe
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - e:\windows\web\related.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\programmi\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC} - e:\programmi\java\jre6\bin\jp2iexp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\progra~1\spybot~1\SDHelper.dll
LSP: e:\programmi\avira\antivir desktop\avsda.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1213525945812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - e:\programmi\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.2 formamed_en.localhost
Hosts: 192.168.2.9 HP001F2972AB38
================= FIREFOX ===================
FF - ProfilePath - e:\docume~1\massimo\datiap~1\mozilla\firefox\profiles\gnxcvenx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1460988&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.mammapermamma.eu/
FF - component: e:\documents and settings\massimo\dati applicazioni\mozilla\firefox\profiles\gnxcvenx.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll
FF - component: e:\documents and settings\massimo\dati applicazioni\mozilla\firefox\profiles\gnxcvenx.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\winnt_x86-msvc\components\pagespeed.dll
FF - plugin: e:\documents and settings\massimo\impostazioni locali\dati applicazioni\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: e:\programmi\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: e:\programmi\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: e:\programmi\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: e:\programmi\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - e:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - e:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
e:\programmi\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
e:\programmi\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
e:\programmi\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
e:\programmi\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
e:\programmi\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
e:\programmi\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
e:\programmi\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
e:\programmi\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
e:\programmi\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
e:\programmi\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
e:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
e:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
e:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
e:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
e:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;e:\programmi\avira\antivir desktop\avgio.sys [2009-4-29 11608]
R1 Ext2Fsd;Linux ext2 file system driver;e:\windows\system32\drivers\ext2fsd.sys [2009-1-15 651264]
R2 AntiVirMailService;Avira AntiVir MailGuard;e:\programmi\avira\antivir desktop\avmailc.exe [2009-4-29 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;e:\programmi\avira\antivir desktop\sched.exe [2009-4-29 108289]
R2 AntiVirService;Avira AntiVir Guard;e:\programmi\avira\antivir desktop\avguard.exe [2009-4-29 185089]
R2 AntiVirWebService;Avira AntiVir WebGuard;e:\programmi\avira\antivir desktop\avwebgrd.exe [2009-4-29 434945]
R2 avgntflt;avgntflt;e:\windows\system32\drivers\avgntflt.sys [2009-4-29 56816]
R2 NPF;NetGroup Packet Filter Driver;e:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R3 vsdatant;vsdatant;e:\windows\system32\vsdatant.sys [2005-1-26 280344]
S2 gupdate;Servizio di Google Update (gupdate);e:\programmi\google\update\GoogleUpdate.exe [2010-2-25 135664]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;e:\windows\system32\drivers\bsusbser.sys [2008-6-19 94848]
============== File Associations ===============
.txt=txt_auto_file
=============== Created Last 30 ================
2010-05-24 09:56:15 7375 ----a-w- e:\documents and settings\massimo\.recently-used.xbel
2010-05-07 07:33:38 0 d-----w- e:\windows\Internet Logs
2010-05-07 07:33:22 127376 ----a-w- e:\windows\system32\drivers\dne2000.sys
2010-05-07 07:33:22 101904 ----a-w- e:\windows\system32\dneinobj.dll
2010-05-07 07:33:13 0 d-----w- e:\programmi\file comuni\Deterministic Networks
2010-05-07 07:33:12 0 d-----w- e:\programmi\Cisco Systems
2010-05-07 07:33:02 1593 ----a-w- e:\windows\VPNInstall.MIF
2010-05-05 12:41:55 0 d-----w- e:\programmi\Arena
2010-05-03 07:52:52 0 d-----w- e:\programmi\iPod
2010-05-03 07:52:48 0 d-----w- e:\programmi\iTunes
2010-05-03 07:49:29 0 d-----w- e:\programmi\Bonjour
==================== Find3M ====================
2010-04-20 08:39:10 411368 ----a-w- e:\windows\system32\deployJava1.dll
2010-04-20 08:38:49 619536 ----a-w- e:\windows\system32\perfh010.dat
2010-04-20 08:38:49 134646 ----a-w- e:\windows\system32\perfc010.dat
2010-04-08 11:20:02 91424 ----a-w- e:\windows\system32\dnssd.dll
2010-04-08 11:20:02 107808 ----a-w- e:\windows\system32\dns-sd.exe
2010-03-10 06:15:53 420352 ----a-w- e:\windows\system32\vbscript.dll
2010-03-08 16:14:37 27524 ---ha-w- e:\windows\system32\mlfcache.dat
============= FINISH: 15.05.11,67 ===============