ComboFix 10-01-11.01 - user 13/01/2010 22.49.30.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.2046.1527 [GMT 1:00]
Eseguito da: c:\documents and settings\user\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\user\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00200000-EE94-0012-94EE-120094EE1200}
FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
FILE ::
"c:\windows\system32\drivers\mfx.sys"
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MFX
-------\Service_MFX
((((((((((((((((((((((((( Files Creati Da 2009-12-13 al 2010-01-13 )))))))))))))))))))))))))))))))))))
.
2010-01-12 22:25 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-12 22:25 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-12 22:25 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-12 22:24 . 2010-01-12 22:24 -------- d-----w- c:\programmi\Avira
2010-01-12 22:24 . 2010-01-12 22:24 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avira
2010-01-12 20:51 . 2009-11-25 10:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-11 09:46 . 2010-01-11 09:46 -------- d-----w- c:\documents and settings\user\Dati applicazioni\Malwarebytes
2010-01-11 09:45 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 09:45 . 2010-01-11 09:46 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2010-01-11 09:45 . 2010-01-11 09:45 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-01-11 09:45 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-10 22:03 . 2010-01-10 22:03 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-08 20:20 . 2010-01-08 20:20 -------- d-sh--w- c:\documents and settings\LocalService\UserData
2010-01-08 20:20 . 2010-01-08 20:20 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2010-01-08 20:20 . 2010-01-08 20:20 -------- d-sh--w- c:\documents and settings\LocalService\IECompatCache
2010-01-08 20:20 . 2010-01-08 20:20 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Threat Expert
2010-01-08 20:20 . 2010-01-08 20:20 -------- d-----r- c:\documents and settings\LocalService\Preferiti
2010-01-08 18:26 . 2010-01-08 18:26 388096 ----a-r- c:\documents and settings\user\Dati applicazioni\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-08 18:26 . 2010-01-08 18:26 -------- d-----w- c:\programmi\TrendMicro
2010-01-03 17:06 . 2010-01-03 17:06 -------- d-----w- c:\documents and settings\user\Impostazioni locali\Dati applicazioni\Threat Expert
2010-01-03 17:02 . 2009-11-24 07:54 56512 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2010-01-03 17:02 . 2009-11-10 16:11 70408 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2010-01-03 17:02 . 2009-08-14 12:44 32552 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2010-01-03 17:02 . 2009-10-16 15:55 115216 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2010-01-03 17:02 . 2010-01-12 13:12 -------- d-----w- c:\programmi\PC Tools Firewall Plus
2010-01-03 17:00 . 2009-11-10 09:28 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-01-03 17:00 . 2009-11-10 09:28 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-01-03 17:00 . 2009-11-10 09:28 1640400 ----a-w- c:\windows\PCTBDCore.dll
2010-01-03 17:00 . 2009-11-10 09:26 767952 ----a-w- c:\windows\BDTSupport.dll
2010-01-03 17:00 . 2009-10-28 00:36 1152444 ----a-w- c:\windows\UDB.zip
2010-01-03 17:00 . 2008-11-26 11:08 131 ----a-w- c:\windows\IDB.zip
2010-01-03 16:58 . 2009-10-30 10:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-03 16:58 . 2009-11-23 12:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-01-03 16:58 . 2009-11-09 10:20 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-01-03 16:58 . 2009-09-03 08:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-01-03 16:58 . 2010-01-13 21:55 -------- d-----w- c:\programmi\Spyware Doctor
2010-01-03 16:58 . 2010-01-03 16:58 -------- d-----w- c:\documents and settings\user\Dati applicazioni\PC Tools
2010-01-03 16:58 . 2010-01-03 16:58 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PC Tools
2010-01-03 16:27 . 2010-01-03 16:27 -------- d-sh--w- c:\documents and settings\Administrator.USER-AB6739F10F\IETldCache
2009-12-18 20:02 . 2009-12-18 20:02 294656 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avglngx.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-13 21:57 . 2008-09-11 07:19 -------- d---a-w- c:\documents and settings\All Users\Dati applicazioni\TEMP
2010-01-13 20:46 . 2009-04-10 11:24 -------- d-----w- c:\programmi\SpywareBlaster
2010-01-12 20:35 . 2009-11-27 18:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-01-12 14:09 . 2008-12-29 21:44 -------- d-----w- c:\documents and settings\user\Dati applicazioni\Azureus
2010-01-12 11:05 . 2009-04-22 16:17 -------- d-----w- c:\programmi\SpeedFan
2010-01-12 10:37 . 2009-03-14 21:59 -------- d-----w- c:\documents and settings\user\Dati applicazioni\Skype
2010-01-11 10:39 . 2008-07-16 16:55 -------- d-----w- c:\programmi\Norton Ghost
2010-01-10 21:30 . 2007-12-17 11:51 196608 ----a-w- c:\windows\system32\drivers\nStandard.bin
2010-01-03 17:04 . 2009-03-28 21:55 -------- d-----w- c:\documents and settings\user\Dati applicazioni\PCToolsFirewallPlus
2010-01-03 17:00 . 2009-03-28 21:52 -------- d-----w- c:\programmi\File comuni\PC Tools
2009-12-26 18:45 . 2008-01-16 21:27 -------- d-----w- c:\programmi\eMule
2009-12-22 10:34 . 2009-12-11 21:00 4043544 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgui.exe
2009-12-22 10:34 . 2009-11-27 19:12 3966744 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgcorex.dll
2009-12-17 19:41 . 2006-03-02 12:00 818476 ----a-w- c:\windows\system32\perfh010.dat
2009-12-17 19:41 . 2006-03-02 12:00 238406 ----a-w- c:\windows\system32\perfc010.dat
2009-12-05 23:41 . 2009-12-05 23:41 -------- d-----w- c:\programmi\Biliardo
2009-12-04 14:22 . 2009-12-04 13:22 -------- d-----w- c:\programmi\Audacity
2009-11-27 19:08 . 2008-10-03 18:52 -------- d-----w- c:\programmi\FlatOut 2
2009-11-27 18:56 . 2008-05-25 10:59 -------- d-----w- c:\programmi\AVG
2009-11-21 15:54 . 2006-03-02 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-04 07:27 . 2009-11-04 07:27 152576 ----a-w- c:\documents and settings\user\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-02 19:42 . 2009-10-02 20:18 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:40 . 2006-03-02 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2006-03-02 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-03-02 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-03-02 12:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
.
Code:<pre>
c:\programmi\AVG\AVG8\avgtray .exe
c:\programmi\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\programmi\HP\HP Software Update\hpwuschd2 .exe
c:\programmi\SweetIM\Messenger\sweetim .exe
</pre>
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-10 8429568]
"nwiz"="nwiz.exe" [2007-05-10 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-10 81920]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"00PCTFW"="c:\programmi\PC Tools Firewall Plus\FirewallGUI.exe" [2009-11-27 2971608]
"ISTray"="c:\programmi\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"avgnt"="c:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FILECO~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\programmi\File comuni\logishrd\WUApp32.exe" [2008-12-17 443664]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\ClubDelGioco\\jre\\jre\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Programmi\\NetMeeting\\conf.exe"=
"c:\\Programmi\\Vuze\\Azureus.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmi\\FlatOut 2\\flatout2.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [03/01/2010 17.58.37 207792]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [03/01/2010 17.58.44 233136]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\programmi\Spyware Doctor\BDT\BDTUpdateService.exe [03/01/2010 18.00.35 112592]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\programmi\Telecom Italia\WanMiniport1st\srvany.exe [27/04/2008 10.51.03 8192]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [03/01/2010 17.58.37 88040]
R2 sdAuxService;PC Tools Auxiliary Service;c:\programmi\Spyware Doctor\pctsAuxs.exe [03/01/2010 17.58.25 359624]
R3 PCTFW-DNS;PCTools Firewall - DNS driver;c:\windows\system32\drivers\pctNdis-DNS.sys [03/01/2010 18.02.06 32552]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [03/01/2010 18.02.06 70408]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [03/01/2010 18.02.06 56512]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [03/01/2010 18.02.04 115216]
--- Altri Servizi/Drivers In Memoria ---
*Deregistered* - PCTSDInjDriver32
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenuto della cartella 'Scheduled Tasks'
2010-01-13 c:\windows\Tasks\User_Feed_Synchronization-{FA22D392-C68C-4111-B4E7-B3A45869C8C8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Scansione supplementare -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-13 22:59
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ñw*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(3956)
c:\windows\system32\WININET.dll
c:\programmi\Windows Media Player\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\windows\system32\OLEPRO32.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Avira\AntiVir Desktop\sched.exe
c:\programmi\Avira\AntiVir Desktop\avguard.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
c:\programmi\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\PC Tools Firewall Plus\FWService.exe
c:\programmi\Spyware Doctor\pctsSvc.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programmi\Packard Bell\Packard Bell Software Suite\PowerSave\HDPBSSS.exe
.
**************************************************************************
.
Ora fine scansione: 2010-01-13 23:01:05 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-01-13 22:01
ComboFix2.txt 2010-01-12 10:49
Pre-Run: 157.663.195.136 byte disponibili
Post-Run: 157.560.938.496 byte disponibili
Current=3 Default=3 Failed=1 LastKnownGood=2 Sets=1,2,3,4
- - End Of File - - 44B2D1B967819E4D67954E4CF806C5C6