ComboFix 09-01-05.03 - Administrator 2009-01-07 0.46.08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.3327.2901 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Dati applicazioni\inst.exe
c:\windows\system32\inetsrv\update
c:\windows\system32\inetsrv\update\kb892130.cat
c:\windows\system32\inetsrv\update\update.exe
c:\windows\system32\inetsrv\update\update.inf
c:\windows\system32\inetsrv\update\update.ver
c:\windows\system32\inetsrv\update\updspapi.dll
c:\windows\system32\inetsrv\update\wgacustom.dll
.
((((((((((((((((((((((((( Files Creati Da 2008-12-06 al 2009-01-06 )))))))))))))))))))))))))))))))))))
.
2009-01-07 00:43 . 2009-01-07 00:43 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Avg8
2009-01-06 22:48 . 2009-01-06 22:48 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2009-01-06 22:48 . 2009-01-06 22:48 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-01-06 22:48 . 2009-01-06 22:48 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2009-01-06 22:48 . 2009-01-04 18:38 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-06 22:48 . 2009-01-04 18:38 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-06 21:37 . 2009-01-06 21:37 <DIR> d-------- c:\programmi\Trend Micro
2009-01-06 18:35 . 2009-01-06 18:35 823,296 --a------ c:\windows\is-U6VEL.exe
2009-01-06 18:35 . 2009-01-06 18:35 10,595 --a------ c:\windows\is-U6VEL.msg
2009-01-06 18:35 . 2009-01-06 18:35 1,672 --a------ c:\windows\is-U6VEL.lst
2009-01-06 17:14 . 2009-01-06 17:14 <DIR> d-------- c:\programmi\JockerSoft
2009-01-06 14:25 . 2008-09-24 19:41 839,680 --a------ c:\windows\system32\lameACM.acm
2009-01-06 14:25 . 2008-09-16 20:23 168,448 --a------ c:\windows\system32\unrar.dll
2009-01-06 14:25 . 2008-10-03 13:30 414 --a------ c:\windows\system32\lame_acm.xml
2009-01-06 14:24 . 2009-01-06 23:39 <DIR> d-------- c:\programmi\K-Lite Codec Pack
2009-01-06 14:24 . 2008-09-19 22:57 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2009-01-06 14:24 . 2008-12-07 19:08 795,648 --a------ c:\windows\system32\xvidcore.dll
2009-01-06 14:24 . 2008-10-28 23:35 684,032 --a------ c:\windows\system32\divx.dll
2009-01-06 14:24 . 2004-01-25 17:18 217,088 --a------ c:\windows\system32\yv12vfw.dll
2009-01-06 14:24 . 2008-12-07 19:08 130,048 --a------ c:\windows\system32\xvidvfw.dll
2009-01-06 14:24 . 2007-09-21 01:52 118,784 --a------ c:\windows\system32\ac3acm.acm
2009-01-06 14:24 . 2008-09-25 09:03 81,920 --a------ c:\windows\system32\dpl100.dll
2009-01-06 14:24 . 2008-12-08 12:53 57,344 --a------ c:\windows\system32\ff_vfw.dll
2009-01-06 14:24 . 2007-07-10 17:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2009-01-05 17:32 . 2009-01-05 17:33 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Canon
2009-01-05 17:29 . 2009-01-05 17:29 <DIR> d-------- c:\programmi\ScanSoft
2009-01-05 17:29 . 2009-01-05 17:29 <DIR> d-------- c:\programmi\File comuni\ScanSoft Shared
2009-01-05 17:29 . 2009-01-05 17:29 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SSScanWizard
2009-01-05 17:29 . 2009-01-05 17:29 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SSScanAppDataDir
2009-01-05 17:29 . 2009-01-05 17:29 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\ScanSoft
2009-01-05 17:29 . 2009-01-05 17:29 516 --a------ c:\windows\MAXLINK.INI
2009-01-05 17:21 . 2009-01-05 17:21 <DIR> d-------- c:\programmi\ArcSoft
2009-01-05 17:21 . 1995-08-01 04:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2009-01-05 17:19 . 2003-09-18 14:32 1,060,864 --a------ c:\windows\system32\MFC71.dll
2009-01-05 17:19 . 1998-11-13 13:07 307,712 --a------ c:\windows\IsUn0410.exe
2009-01-05 17:04 . 2009-01-05 17:04 <DIR> d-------- c:\windows\StartHtmico
2009-01-04 23:02 . 2009-01-04 23:02 <DIR> d-------- c:\programmi\IObit
2009-01-04 23:02 . 2009-01-04 23:20 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\IObit
2009-01-04 22:52 . 2009-01-04 22:54 <DIR> d-------- c:\programmi\Spybot - Search & Destroy
2009-01-04 22:52 . 2009-01-04 23:40 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2009-01-04 22:50 . 2009-01-04 22:51 <DIR> d-------- c:\programmi\Spamihilator
2009-01-04 22:50 . 2009-01-07 00:44 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Spamihilator
2009-01-04 19:31 . 2009-01-04 19:31 <DIR> d-------- c:\programmi\Unlocker
2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\DAEMON Tools Pro
2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\DAEMON Tools
2009-01-03 17:47 . 2009-01-03 17:47 <DIR> d-------- c:\programmi\DAEMON Tools Toolbar
2009-01-03 17:47 . 2009-01-03 17:47 <DIR> d-------- c:\programmi\DAEMON Tools Lite
2009-01-03 17:47 . 2009-01-03 17:47 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\DAEMON Tools Lite
2009-01-03 17:38 . 2009-01-03 17:50 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\DAEMON Tools Lite
2009-01-03 17:38 . 2009-01-03 17:38 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2009-01-03 14:09 . 2009-01-03 14:09 <DIR> d-------- c:\programmi\Maxtor
2009-01-03 14:09 . 2009-01-03 15:43 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Maxtor
2009-01-03 14:07 . 2009-01-03 14:07 <DIR> d--hs---- c:\windows\ftpcache
2009-01-03 14:07 . 2009-01-03 14:07 <DIR> d-------- c:\windows\Downloaded Installations
2009-01-02 15:49 . 2009-01-02 15:52 <DIR> d-------- c:\programmi\DVD Shrink
2009-01-01 18:24 . 2009-01-05 12:45 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\DVD Shrink
2009-01-01 13:25 . 2009-01-01 13:25 <DIR> d-------- c:\programmi\VSO
2009-01-01 13:25 . 2006-05-20 16:16 1,184,984 --a------ c:\windows\system32\wvc1dmod.dll
2009-01-01 13:25 . 2006-05-11 19:21 626,688 --a------ c:\windows\system32\vp7vfw.dll
2009-01-01 13:25 . 2006-09-29 12:24 217,127 --a------ c:\windows\system32\drv43260.dll
2009-01-01 13:25 . 2006-09-29 12:25 208,935 --a------ c:\windows\system32\drv33260.dll
2009-01-01 13:25 . 2006-09-29 12:26 176,165 --a------ c:\windows\system32\drv23260.dll
2009-01-01 13:25 . 2002-12-10 02:20 102,439 --a------ c:\windows\system32\sipr3260.dll
2009-01-01 13:25 . 2007-03-18 20:37 65,602 --a------ c:\windows\system32\cook3260.dll
2009-01-01 10:21 . 2009-01-03 14:07 <DIR> d-------- C:\Maxtor temp
2008-12-31 21:23 . 2009-01-02 19:25 <DIR> d-------- c:\programmi\DVDFab 5
2008-12-31 21:23 . 2009-01-05 12:45 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Vso
2008-12-31 21:23 . 2008-12-31 21:23 47,360 --a------ c:\windows\system32\drivers\pcouffin.sys
2008-12-31 21:23 . 2008-12-31 21:23 47,360 --a------ c:\documents and settings\Administrator\Dati applicazioni\pcouffin.sys
2008-12-30 20:59 . 2008-12-30 20:59 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Bluetooth
2008-12-30 20:47 . 2008-12-30 20:47 <DIR> d-------- c:\programmi\IVT Corporation
2008-12-30 20:47 . 2009-01-05 17:21 <DIR> d--h----- c:\programmi\InstallShield Installation Information
2008-12-30 20:47 . 2004-09-21 18:18 148,830 --a------ c:\windows\system32\drivers\bcbthub.sys
2008-12-30 20:44 . 2008-12-30 20:44 <DIR> d-------- c:\programmi\File comuni\InstallShield
2008-12-30 10:14 . 2008-12-30 10:14 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Media Player Classic
2008-12-30 10:06 . 2008-12-30 10:07 <DIR> d-------- c:\documents and settings\Administrator\dwhelper
2008-12-30 10:04 . 2008-12-30 10:04 1,156 --a------ c:\windows\mozver.dat
2008-12-27 09:34 . 2008-12-27 09:34 <DIR> d--h----- c:\documents and settings\All Users\Dati applicazioni\CanonBJ
2008-12-27 09:34 . 2005-05-06 21:00 140,288 --a------ c:\windows\system32\CNMLM7I.DLL
2008-12-27 09:34 . 2008-04-13 11:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-12-27 09:34 . 2008-04-13 11:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-12-27 09:34 . 2005-05-06 21:00 8,704 --a------ c:\windows\system32\CNMVS7I.DLL
2008-12-27 09:33 . 2008-12-27 09:33 <DIR> d--h----- c:\windows\system32\CanonMP Uninstaller Information
2008-12-27 09:32 . 2009-01-05 17:20 <DIR> d-------- c:\programmi\Canon
2008-12-27 09:32 . 2008-12-27 09:32 <DIR> d--h----- C:\CanonMP
2008-12-27 09:32 . 2005-08-04 03:19 221,184 --a------ c:\windows\system32\CNCC450.DLL
2008-12-27 09:32 . 2005-05-30 11:46 139,264 --a------ c:\windows\system32\CNCL450.DLL
2008-12-27 09:32 . 2005-08-04 03:19 69,632 --a------ c:\windows\system32\CNCI450.DLL
2008-12-27 09:32 . 2005-08-04 03:20 49,152 --a------ c:\windows\system32\cncisco.dll
2008-12-25 17:13 . 2009-01-05 12:19 69 --a------ c:\windows\NeroDigital.ini
2008-12-25 16:53 . 2009-01-07 00:14 <DIR> d-------- c:\programmi\eMule
2008-12-25 16:45 . 2009-01-04 23:10 <DIR> d-------- c:\programmi\IncrediMail
2008-12-25 16:45 . 2008-12-25 16:45 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\IncrediMail
2008-12-25 16:45 . 2008-12-25 16:45 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\IM
2008-12-25 16:37 . 2008-12-25 16:37 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Talkback
2008-12-25 16:37 . 2008-12-25 16:37 10,520 --------- c:\windows\system32\avgrsstx.dll.install_backup
2008-12-25 16:36 . 2008-12-25 16:36 <DIR> d-------- c:\programmi\AVG
2008-12-25 16:36 . 2008-12-25 16:36 0 --a------ c:\windows\nsreg.dat
2008-12-25 15:09 . 2008-12-25 15:09 268 --ah----- C:\sqmdata01.sqm
2008-12-25 15:09 . 2008-12-25 15:09 244 --ah----- C:\sqmnoopt01.sqm
2008-12-25 14:18 . 2008-12-25 14:18 268 --ah----- C:\sqmdata00.sqm
2008-12-25 14:18 . 2008-12-25 14:18 244 --ah----- C:\sqmnoopt00.sqm
2008-12-25 14:17 . 2009-01-05 12:54 <DIR> d-------- c:\documents and settings\Administrator\Dati applicazioni\Nero
2008-12-25 13:54 . 2008-12-25 13:54 4,767 --a------ c:\windows\Irremote.ini
2008-12-25 13:52 . 2008-12-25 13:52 <DIR> d-------- c:\programmi\Windows Sidebar
2008-12-25 13:46 . 2008-12-25 13:53 <DIR> d-------- c:\programmi\Nero
2008-12-25 13:46 . 2008-12-25 14:01 <DIR> d-------- c:\programmi\File comuni\Nero
2008-12-25 13:46 . 2008-12-30 16:42 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Nero
2008-12-25 13:28 . 2008-12-25 13:28 499,712 --a------ c:\windows\system32\msvcp71.dll
2008-12-25 13:23 . 2008-12-25 13:23 0 --a------ c:\windows\ativpsrm.bin
2008-12-25 13:22 . 2008-07-03 21:48 3,107,788 -ra------ c:\windows\system32\ativvaxx.dat
2008-12-25 13:22 . 2008-07-03 21:48 3,107,788 -ra------ c:\windows\system32\ativva5x.dat
2008-12-25 13:22 . 2008-07-03 21:48 887,724 -ra------ c:\windows\system32\ativva6x.dat
2008-12-25 13:22 . 2008-07-03 22:25 421,888 -ra------ c:\windows\system32\ATIDEMGX.dll
2008-12-25 13:22 . 2008-07-03 21:55 307,200 -ra------ c:\windows\system32\atiiiexx.dll
2008-12-25 13:22 . 2008-06-10 16:50 174,819 -ra------ c:\windows\system32\atiicdxx.dat
2008-12-25 13:22 . 2008-05-13 07:10 13,052 -ra------ c:\windows\atiogl.xml
2008-12-25 13:22 . 2007-08-31 08:20 7,167 -ra------ c:\windows\system32\atifglpf.xml
2008-12-25 13:20 . 2008-06-25 17:47 36,864 -ra------ c:\windows\system32\drivers\l1e51x86.sys
2008-12-25 13:15 . 2008-12-25 13:15 37,245 --a------ c:\windows\Ascd_tmp.ini
2008-12-25 13:15 . 2007-12-28 16:22 10,296 --a------ c:\windows\system32\drivers\ASUSHWIO.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 17:04 --------- d-----w c:\programmi\Windows Media Connect 2
2008-12-24 22:01 --------- d-----w c:\programmi\Windows Live
2008-12-24 21:59 86 ----a-w c:\windows\system32\config\systemprofile\DelE01.bat
2008-12-24 21:59 86 ----a-w c:\documents and settings\Default User\DelE01.bat
2008-12-24 21:59 86 ----a-w c:\documents and settings\Administrator\DelE01.bat
2008-12-24 21:58 --------- d-----w c:\programmi\Reference Assemblies
2008-12-24 21:58 --------- d-----w c:\programmi\MSBuild
2008-12-24 21:55 --------- d-----w c:\programmi\Java
2008-12-24 21:55 --------- d-----w c:\programmi\File comuni\Java
2008-12-24 21:53 --------- d-----w c:\programmi\Servizi in linea
2008-12-23 09:24 665,088 ----a-w c:\windows\system32\spsplib1.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IncrediMail"="c:\programmi\IncrediMail\bin\IncMail.exe" [2008-11-09 243072]
"DAEMON Tools Lite"="c:\programmi\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"SpybotSD TeaTimer"="c:\programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mxomssmenu"="c:\programmi\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312]
"Spamihilator"="c:\programmi\Spamihilator\spamihilator.exe" [2008-12-23 1321984]
"OpwareSE2"="c:\programmi\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"RTHDCPL"="RTHDCPL.EXE" [2008-01-29 c:\windows\RTHDCPL.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2002-12-31 15360]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BlueSoleil.lnk - c:\programmi\IVT Corporation\BlueSoleil\BlueSoleil.exe [2008-12-30 1044480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\D:\
0autocheck autochk *
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Programmi\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Programmi\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Programmi\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Programmi\\Spamihilator\\cdcc.exe"=
"c:\\Programmi\\Spamihilator\\dccproc.exe"=
"c:\\Programmi\\Spamihilator\\spamihilator.exe"=
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2002-12-31 143360]
R4 AvgRkx86;avgrkx86.sys;c:\windows\system32\Drivers\avgrkx86.sys --> c:\windows\system32\Drivers\avgrkx86.sys [?]
R4 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys --> c:\windows\system32\Drivers\avgtdix.sys [?]
R4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\programmi\File comuni\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
S3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2008-12-25 36864]
--- Other Services/Drivers In Memory ---
*Deregistered* - AvgLdx86
.
- - - - ORFÃOS REMOVIDOS - - - -
HKLM-RunOnce-<NO NAME> - (no file)
.
------- Supplementare di scansione -------
.
uStart Page = hxxp://mystart.incredimail.com/
uInternet Connection Wizard,ShellNext = hxxp://www.incredimail.com/app/?tag=page_app_welcome&lang=16&version=5853849&setup_id=16000007&aff_id=102&addon=IncrediMail
TCP: {2F6B56A5-A8C9-4E6B-B292-04A9CCED999B} = 62.94.0.1,62.94.0.2
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\bgysjd1s.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&search=
FF - component: c:\programmi\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-07 00:46:55
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(1328)
c:\windows\system32\avgrsstx.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1432)
c:\windows\system32\avgrsstx.dll
.
Ora fine scansione: 2009-01-07 0.47.18
ComboFix-quarantined-files.txt 2009-01-06 23:47:13
Pre-Run: 115.707.838.464 byte disponibili
Post-Run: 115,952,844,800 byte disponibili
240