Malwarebytes' Anti-Malware 1.41
Versione del database: 2896
Windows 5.1.2600 Service Pack 2
02/10/2009 21.22.32
mbam-log-2009-10-02 (21-22-27).txt
Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 120009
Tempo trascorso: 23 minute(s), 45 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 4
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 4
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
HKEY_CLASSES_ROOT\Typelib\{c20ee2d6-81c3-6a08-79c5-1989da43bc19} (Trojan.Downloader) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Worm.Allaple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\poprock (Trojan.Downloader) -> No action taken.
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
C:\WINDOWS\msa.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\msb.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> No action taken.
Questo è ComboFix:
ComboFix 09-10-01.05 - David 02/10/2009 21.28.57.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.503.209 [GMT 2:00]
Eseguito da: c:\documents and settings\David\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\msa.exe
c:\windows\msb.exe
.
((((((((((((((((((((((((( Files Creati Da 2009-09-02 al 2009-10-02 )))))))))))))))))))))))))))))))))))
.
2009-10-02 18:47 . 2009-10-02 18:47 -------- d-----w- c:\documents and settings\David\Dati applicazioni\Malwarebytes
2009-10-02 18:47 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-02 18:47 . 2009-10-02 18:47 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-10-02 18:47 . 2009-10-02 18:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-10-02 18:47 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-28 19:44 . 2009-09-28 19:44 -------- d-----w- c:\programmi\Business Objects
2009-09-28 19:30 . 2009-09-28 19:30 516096 ----a-w- c:\windows\iwexec.exe
2009-09-28 18:52 . 2009-09-28 18:58 -------- d-----w- c:\programmi\Date Cracker 2000
2009-09-28 18:52 . 2009-09-28 18:52 249856 ------w- c:\windows\Setup1.exe
2009-09-28 18:52 . 2009-09-28 18:52 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-09-23 18:43 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-09-23 18:41 . 2009-09-23 18:41 -------- d-----w- c:\programmi\MSBuild
2009-09-23 18:30 . 2009-09-23 18:30 -------- d-----w- c:\documents and settings\David\Impostazioni locali\Dati applicazioni\Microsoft Help
2009-09-23 18:30 . 2009-09-30 18:58 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-09-23 17:52 . 2009-09-23 17:52 -------- d-----r- C:\MSOCache
2009-09-16 15:36 . 2009-09-16 15:36 -------- d-----w- c:\programmi\coverXP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-02 09:07 . 2009-02-12 18:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Google Updater
2009-09-30 19:46 . 2009-02-09 18:42 -------- d-----w- c:\documents and settings\David\Dati applicazioni\uTorrent
2009-09-30 17:42 . 2009-08-08 16:20 -------- d-----w- c:\documents and settings\David\Dati applicazioni\TeamViewer
2009-09-28 19:43 . 2009-02-02 00:13 68448 ----a-w- c:\documents and settings\David\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-28 19:42 . 2004-09-16 14:31 72032 ----a-w- c:\windows\system32\perfc010.dat
2009-09-28 19:42 . 2004-09-16 14:31 442674 ----a-w- c:\windows\system32\perfh010.dat
2009-09-23 18:41 . 2009-01-26 14:49 -------- d-----w- c:\programmi\Microsoft Works
2009-08-26 09:24 . 2009-01-26 13:04 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Symantec
2009-08-16 07:13 . 2009-04-12 19:39 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-16 07:13 . 2009-04-12 19:39 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-16 07:13 . 2009-04-12 19:39 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-08 16:19 . 2009-08-08 16:19 -------- d-----w- c:\programmi\TeamViewer
2009-08-05 09:05 . 2004-09-16 14:31 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:56 . 2004-09-16 14:30 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 00:18 . 2004-09-16 14:31 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2007-03-11 04:58 . 2009-02-01 22:08 1197796 ----a-w- c:\programmi\WinRAR-ITA v3.62+Crack.rar
1990-10-27 04:02 . 2009-02-01 22:07 189695112 ----a-w- c:\programmi\NERO_8.1_ITA+KEYGEN.rar
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2004-10-29 98394]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2004-10-29 688218]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-16 2007832]
"ZCfgSvc.exe"="c:\windows\system32\ZCfgSvc.exe" [2004-09-06 417856]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-09-06 04:29 180290 ----a-w- c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 07:13 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Asus\\ASUS Live Update\\LiveUpdt.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/04/2009 21.39.13 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/04/2009 21.39.21 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/04/2009 21.38.45 297752]
R2 TeamViewer4;TeamViewer 4;c:\programmi\TeamViewer\Version4\TeamViewer_Service.exe [30/07/2009 17.29.42 185640]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmi\TomTom HOME 2\TomTomHOMEService.exe [24/04/2009 13.57.30 92008]
S2 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\SupportAppMH\cdrom_mon.exe [27/01/2009 17.44.14 81920]
S2 gupdate1c98d3f1537111a;Google Update Service (gupdate1c98d3f1537111a);c:\programmi\Google\Update\GoogleUpdate.exe [12/02/2009 20.24.00 133104]
S2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [07/02/2009 22.39.14 8192]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys --> c:\windows\system32\drivers\nmwcdnsu.sys [?]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys --> c:\windows\system32\drivers\nmwcdnsuc.sys [?]
S3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\drivers\ONDAusbmdm6k.sys [27/01/2009 17.45.00 100352]
S3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\drivers\ONDAusbnmea.sys [27/01/2009 17.45.00 100352]
S3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\drivers\ONDAusbser6k.sys [27/01/2009 17.45.00 100352]
S3 ZD1211BU(Atheros);IEEE 802.11 Wireless LAN Driver (USB)(Atheros);c:\windows\system32\drivers\ZD1211BU.sys [12/02/2009 20.02.03 712704]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-02 c:\windows\Tasks\Google Software Updater.job
- c:\programmi\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-12 18:15]
2009-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-12 18:23]
2009-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-02-12 18:23]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 192.169.0.1:2939
uInternet Settings,ProxyOverride = 127.0.0.1;<local>
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\David\Dati applicazioni\Mozilla\Firefox\Profiles\vi76p9je.default\
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\programmi\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\programmi\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-02 21:34
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ñw*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\LgNotify.dll
.
Ora fine scansione: 2009-10-02 21.37.19
ComboFix-quarantined-files.txt 2009-10-02 19:37
ComboFix2.txt 2009-04-02 10:47
Pre-Run: 38.957.927.424 byte disponibili
Post-Run: 38.936.968.704 byte disponibili
150 --- E O F --- 2009-08-26 11:03