Spero sia giusto.
ComboFix 09-06-20.04 - vittorio 21/06/2009 19.48.23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1015.476 [GMT 2:00]
Eseguito da: c:\documents and settings\vittorio\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((( Files Creati Da 2009-05-21 al 2009-06-21 )))))))))))))))))))))))))))))))))))
.
2009-06-20 16:34 . 2009-06-20 16:34 -------- d-----w- c:\documents and settings\vittorio\Dati applicazioni\Desktopicon
2009-06-19 19:37 . 2009-06-11 06:55 3298072 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\setup.exe
2009-06-19 19:37 . 2009-06-11 06:55 1261344 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgwd.dll
2009-06-19 19:37 . 2009-06-11 06:55 829208 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgcfgx.dll
2009-06-12 13:00 . 2009-06-12 13:00 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Google
2009-06-11 11:35 . 2009-06-12 08:33 -------- d-----w- c:\programmi\WarRock
2009-06-11 06:55 . 2009-06-11 06:55 1452312 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg8\update\backup\avgupd.dll
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- c:\programmi\GIMP-2.0
2009-06-10 13:17 . 2009-06-10 13:19 -------- d-----w- c:\documents and settings\vittorio\.gimp-2.4
2009-06-10 06:57 . 2009-06-10 12:23 -------- d-----w- c:\documents and settings\vittorio\Dati applicazioni\gtk-2.0
2009-06-10 06:52 . 2009-06-10 13:22 -------- d-----w- c:\documents and settings\vittorio\.gimp-2.6
2009-06-10 06:52 . 2009-06-10 06:52 -------- d-----w- c:\documents and settings\vittorio\.gegl-0.0
2009-06-10 06:45 . 2009-05-07 15:32 347648 ------w- c:\windows\system32\dllcache\localspl.dll
2009-06-10 06:45 . 2009-04-15 14:52 585216 ------w- c:\windows\system32\dllcache\rpcrt4.dll
2009-06-03 19:38 . 2009-06-18 13:30 3561743 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-31 17:50 . 2009-05-31 17:50 -------- d-----w- c:\documents and settings\vittorio\Phone Browser
2009-05-24 13:00 . 2009-05-24 13:00 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-05-24 12:47 . 2009-05-31 12:41 5589408 ----a-w- c:\documents and settings\vittorio\Dati applicazioni\TVU networks\TVU AutoUpgrade\TVUPlayer2.4.5.3.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 15:16 . 2001-08-31 11:00 64498 ----a-w- c:\windows\system32\perfc010.dat
2009-06-21 15:16 . 2001-08-31 11:00 429362 ----a-w- c:\windows\system32\perfh010.dat
2009-06-20 16:34 . 2009-04-03 15:34 -------- d-----w- c:\programmi\VDOWNLOADER
2009-06-19 19:37 . 2008-12-18 10:23 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-18 13:30 . 2009-04-13 20:52 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-06-18 09:56 . 2008-12-20 12:46 -------- d-----w- c:\documents and settings\tommy.VITTORIO-2163A4\Dati applicazioni\LimeWire
2009-06-18 09:54 . 2008-12-18 10:33 -------- d-----w- c:\programmi\eMule
2009-06-17 11:50 . 2008-12-19 19:48 -------- d-----w- c:\documents and settings\tommy.VITTORIO-2163A4\Dati applicazioni\Skype
2009-06-17 11:32 . 2008-12-19 20:01 -------- d-----w- c:\documents and settings\tommy.VITTORIO-2163A4\Dati applicazioni\skypePM
2009-06-17 09:27 . 2009-04-13 20:52 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2009-04-13 20:52 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 08:33 . 2008-12-18 10:19 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-06-11 06:55 . 2008-12-18 10:23 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-03 19:39 . 2009-01-30 09:10 -------- d-----w- c:\programmi\USB Safely Remove
2009-05-07 15:32 . 2004-08-19 13:39 347648 ----a-w- c:\windows\system32\localspl.dll
2009-05-04 18:50 . 2008-12-19 13:44 -------- d-----w- c:\documents and settings\tommy.VITTORIO-2163A4\Dati applicazioni\vlc
2009-05-03 12:37 . 2009-05-03 12:37 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TVU Networks
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-29 04:45 . 2007-01-03 10:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:44 . 2007-01-03 10:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-27 06:46 . 2008-12-20 12:41 -------- d-----w- c:\programmi\Java
2009-04-27 06:45 . 2009-04-01 06:32 152576 ----a-w- c:\documents and settings\vittorio\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-26 15:09 . 2008-12-19 13:47 -------- d-----w- c:\programmi\Messenger Plus! Live
2009-04-24 09:19 . 2008-12-18 10:24 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-04-24 09:19 . 2008-12-18 10:24 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-04-24 09:19 . 2008-12-18 10:24 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-23 07:06 . 2009-04-23 07:05 -------- d-----w- c:\documents and settings\vittorio\Dati applicazioni\vlc
2009-04-19 19:47 . 2007-01-03 10:52 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 10:07 . 2009-04-17 10:07 45 ---h--w- c:\windows\dsez6272.dat
2009-04-15 14:52 . 2007-01-03 10:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LaunchList"="c:\programmi\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-09-12 16264192]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-04-29 124928]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-24 09:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Programmi\\Pinnacle\\Studio 11\\programs\\umi.exe"=
"c:\\Programmi\\LimeWire\\LimeWire.exe"=
"c:\\Programmi\\SopCast\\SopCast.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [18/12/2008 12.24.02 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18/12/2008 12.23.59 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18/12/2008 12.24.02 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [18/12/2008 12.23.54 906520]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [18/12/2008 12.23.53 298776]
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-20 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-06-21 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-21 19:50
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,96,2b,00,32,34,
47,1e,45,c8,28,51,af,b0,29,a3,98,77,a6,ce,0a,c5,3a,31,6e,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,53,12,a5,96,a9,
83,7b,6f,71,3b,04,66,8b,46,0d,96,d3,06,85,bc,c8,2a,1c,0f,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,fa,1e,42,6b,a0,
22,44,80,25,da,ec,7e,55,20,c9,26,31,7c,93,32,56,64,e7,9e,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,b3,29,98,84,d1,
92,15,1d,3e,1e,9e,e0,57,5a,93,61,81,eb,be,62,56,cf,c5,6b,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,ed,ce,7c,54,2f,
88,de,75,cd,44,cd,b9,a6,33,6c,cd,48,1f,83,ca,53,fa,86,74,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,86,c1,1a,c4,89,
5c,28,0a,b0,18,ed,a7,3f,8d,37,a4,e7,76,8c,ab,4a,fa,17,b8,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,22,d1,8b,72,6f,
d3,2f,8d,31,77,e1,ba,b1,f8,68,02,c5,a8,41,29,d2,de,b3,be,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:aa,52,c6,00,84,3c,26,64,57,b7,b1,4b,c3,
70,c8,37,83,6c,56,8b,a0,85,96,ab,e1,b1,63,ea,0a,90,55,2b,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,73,61,25,6e,41,
4b,6a,80,51,fa,6e,91,28,9e,14,cc,6a,a7,da,da,22,aa,02,73,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,25,32,1b,21,28,
8e,cd,fd,b1,cd,45,5a,a8,c4,f8,b9,f3,ca,d9,21,e2,98,3d,4a,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,32,61,b2,f9,9d,
f0,d7,ea,e3,0e,66,d5,eb,bc,2f,6b,ac,09,43,58,d9,49,d5,05,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,aa,7e,01,96,f5,
1f,9b,60,fa,ea,66,7f,d4,3b,6b,70,b1,c4,cf,81,ba,ff,48,62,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•Ñw*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(3388)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Ora fine scansione: 2009-06-21 19.51.45
ComboFix-quarantined-files.txt 2009-06-21 17:51
Pre-Run: 31.578.824.704 byte disponibili
Post-Run: 31.575.941.120 byte disponibili
204 --- E O F --- 2009-06-10 07:26