ComboFix 10-02-12.01 - Armando 13/02/2010 14.42.31.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1015.777 [GMT 1:00]
Eseguito da: c:\documents and settings\Armando\Desktop\ComboFix.exe
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-0111782848-2611252433-320367115-3874
c:\recycler\S-1-5-21-117609710-2025429265-1547161642-1003
c:\recycler\S-1-5-21-1200791401-2173177111-2569383337-1003
c:\recycler\S-1-5-21-2427576251-1231486041-982712095-1872
c:\recycler\S-1-5-21-3234280684-1396253550-4185536343-1003
c:\recycler\S-1-5-21-5516288273-9119671088-100652620-2457
c:\recycler\S-1-5-21-55401569-2533582971-3823923958-1003
c:\recycler\S-1-5-21-6950578542-8882598769-047577704-9039
c:\windows\system32\Thumbs.db
La copia infetta di c:\windows\system32\DRIVERS\atapi.sys è stata trovata e disinfettata
ipristinata copia da - c:\windows\system32\dllcache\atapi.sys
.
((((((((((((((((((((((((( Files Creati Da 2010-01-13 al 2010-02-13 )))))))))))))))))))))))))))))))))))
.
2013-08-25 23:39 . 2008-08-06 13:51 1200128 ----a-w- c:\windows\RtlUpd.exe
2013-08-25 23:39 . 2008-06-18 16:01 77824 ----a-w- c:\windows\SOUNDMAN.EXE
2013-08-25 23:39 . 2007-11-20 16:15 1826816 ----a-w- c:\windows\SkyTel.exe
2013-08-25 23:39 . 2008-08-12 14:10 4751360 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2013-08-25 23:39 . 2008-06-19 14:27 9715200 ----a-w- c:\windows\RTLCPL.EXE
2013-08-25 23:39 . 2008-07-31 13:05 16806912 ----a-w- c:\windows\RTHDCPL.EXE
2013-08-25 23:39 . 2013-08-25 23:39 -------- d-----w- c:\programmi\Realtek
2013-08-25 23:39 . 2008-06-19 14:42 2808832 ----a-w- c:\windows\ALCWZRD.EXE
2013-08-25 23:39 . 2008-06-19 14:20 57344 ----a-w- c:\windows\ALCMTR.EXE
2013-08-25 23:39 . 2007-06-28 14:44 2165760 ----a-w- c:\windows\MicCal.exe
2013-08-25 23:39 . 2008-07-29 13:42 528384 ----a-w- c:\windows\RtlExUpd.dll
2013-08-11 22:34 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2013-08-11 22:33 . 2008-04-13 09:39 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2013-08-11 22:33 . 2008-04-13 09:46 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2013-08-11 22:32 . 2008-04-13 09:46 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2013-08-11 22:32 . 2008-04-13 09:46 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2013-08-11 22:32 . 2008-04-13 09:46 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2013-08-11 22:32 . 2008-04-13 09:46 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2013-08-11 22:32 . 2008-04-13 09:46 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2013-08-11 22:32 . 2008-04-13 17:13 54784 ----a-w- c:\windows\system32\vfwwdm32.dll
2013-08-11 22:32 . 2008-04-13 09:46 121984 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-08-11 22:32 . 2008-04-13 09:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-09-12 13:59 . 2012-09-12 13:59 -------- d-----w- c:\programmi\Elantech
2012-09-12 13:59 . 2008-04-08 13:59 10752 ----a-w- c:\windows\system32\drivers\ASUSACPI.SYS
2012-09-12 13:59 . 2012-09-12 13:59 -------- d-----w- c:\programmi\EeePC
2010-02-13 12:56 . 2010-02-13 12:56 -------- d-----w- c:\documents and settings\Armando\Dati applicazioni\TuneUp Software
2010-02-13 12:56 . 2010-02-13 13:19 -------- d-----w- c:\programmi\TuneUp Utilities 2010
2010-02-13 12:55 . 2010-02-13 13:19 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TuneUp Software
2010-02-13 12:55 . 2010-02-13 12:55 -------- d-sh--w- c:\documents and settings\All Users\Dati applicazioni\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-02-13 11:41 . 2010-02-13 11:41 -------- d-----w- c:\programmi\Trend Micro
2010-02-13 11:32 . 2010-02-13 11:32 -------- d-----w- c:\documents and settings\Armando\Dati applicazioni\Malwarebytes
2010-02-13 11:32 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-13 11:32 . 2010-02-13 11:32 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-02-13 11:32 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-13 11:32 . 2010-02-13 11:32 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-02-13 11:18 . 2010-02-13 11:18 -------- d-----w- c:\documents and settings\Armando\Dati applicazioni\IObit
2010-02-13 11:18 . 2010-02-13 11:18 -------- d-----w- c:\programmi\IObit
2010-02-13 11:09 . 2010-02-13 11:09 -------- d-----w- c:\programmi\CCleaner
2010-02-13 11:03 . 2010-02-13 13:41 -------- d-----w- c:\windows\system32\CatRoot2
2010-02-13 08:41 . 2010-02-13 08:41 -------- d-----w- c:\windows\system32\wbem\Repository
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-25 23:39 . 2008-08-07 23:26 319488 ----a-w- c:\windows\HideWin.exe
2010-02-13 11:03 . 2010-02-13 11:02 76875 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-30 22:01 . 2009-07-08 16:57 -------- d-----w- c:\documents and settings\Armando\Dati applicazioni\vlc
2009-12-30 14:46 . 2009-12-30 14:46 -------- d-----w- c:\documents and settings\Armando\Dati applicazioni\dvdcss
2009-12-09 10:29 . 2009-04-24 13:08 5228 ----a-w- c:\documents and settings\Armando\Dati applicazioni\wklnhst.dat
2008-05-07 14:34 . 2008-08-08 00:00 15523560 ----a-w- c:\programmi\U1 Setup.exe
2008-04-14 12:00 . 2008-08-07 04:35 1081344 --sha-r- c:\windows\system32\ucfykgk.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\programmi\IObit\Advanced SystemCare 3\AWC.exe" [2009-12-26 2335952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 16806912]
"AsusACPIServer"="c:\programmi\EeePC\ACPI\AsAcpiSvr.exe" [2008-09-02 593920]
"ETDWare"="c:\programmi\Elantech\ETDCtrl.exe" [2008-09-03 335872]
"ETDWareDetect"="c:\programmi\Elantech\ETDDect.exe" [2008-08-22 204800]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\0autocheck autochk *
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AsusEPCMonitor"=c:\programmi\EeePC\ACPI\AsEPCMon.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"Persistence"=c:\windows\system32\igfxpers.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5678:TCP"= 5678:TCP:szpbep
S2 xmwjzh;ztwxhr;c:\windows\system32\svchost.exe -k netsvcs [07/08/2008 5.36.02 14336]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [08/08/2008 0.27.42 625024]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
xmwjzh
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global
FF - ProfilePath - c:\documents and settings\Armando\Dati applicazioni\Mozilla\Firefox\Profiles\hysns4cj.default\
FF - plugin: c:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-13 14:47
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xmwjzh]
"ServiceDll"="c:\windows\system32\ucfykgk.dll"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(3516)
c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
c:\programmi\eee storage\xpclient.dll
c:\programmi\eee storage\logicnp.eznamespaceextensions.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
.
**************************************************************************
.
Ora fine scansione: 2010-02-13 14:49:40 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-02-13 13:49
Pre-Run: 67.085.094.912 byte disponibili
Post-Run: 67.056.070.656 byte disponibili
- - End Of File - - CC2EF196B416D88D8820FE8906FBAAA2
continuo a dirti grazie!