ComboFix 11-07-01.02 - **** 03/07/2011 11:25:22.3.4 - x86
Microsoft Windows 7 Starter 6.1.7600.0.1252.39.1040.18.1013.376 [GMT 2:00]
Eseguito da: c:\users\***\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
.
----- BITS: Possibili siti infetti -----
.
hxxp://download.windowsupdate.com
.
((((((((((((((((((((((((( Files Creati Da 2011-06-03 al 2011-07-03 )))))))))))))))))))))))))))))))))))
.
.
2011-07-03 09:35 . 2011-07-03 09:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-02 16:02 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-02 16:02 . 2011-07-02 16:02 -------- d-----w- c:\programdata\Malwarebytes
2011-07-02 16:02 . 2011-07-02 16:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-02 16:02 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-02 08:57 . 2011-07-02 08:57 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-02 08:56 . 2010-06-29 05:02 1413632 ----a-w- c:\windows\system32\ole32.dll
2011-07-02 08:56 . 2010-06-29 04:57 4247040 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
2011-07-02 08:52 . 2011-02-23 05:05 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-02 08:52 . 2011-02-23 05:05 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-07-02 08:52 . 2011-02-23 05:05 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-02 08:52 . 2011-02-23 05:05 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-07-02 08:35 . 2011-04-01 15:09 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-07-02 08:35 . 2011-04-01 15:09 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-07-02 08:35 . 2011-07-02 08:35 -------- d-----w- c:\programdata\Avira
2011-07-02 08:35 . 2011-07-02 08:35 -------- d-----w- c:\program files\Avira
2011-07-02 08:33 . 2011-06-20 06:57 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E14FBE1B-C32E-4C84-83DC-629875ADF96A}\mpengine.dll
2011-07-02 08:33 . 2011-05-24 17:14 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-02 08:26 . 2011-07-02 08:27 -------- d-----w- c:\program files\CyberLink
2011-07-02 08:24 . 2011-07-02 08:24 -------- d-----w- c:\programdata\OberonGameConsole
2011-07-02 08:20 . 2011-07-02 08:20 -------- d-----w- c:\program files\Common Files\Oberon Media
2011-07-02 08:20 . 2011-07-02 08:24 -------- d-----w- c:\program files\Game Pack
2011-07-02 08:20 . 2011-07-02 08:20 -------- d-----w- c:\program files\Common Files\Skype
2011-07-02 08:19 . 2011-07-02 08:20 -------- d-----r- c:\program files\Skype
2011-07-02 08:19 . 2011-07-02 08:19 -------- d-----w- c:\programdata\Skype
2011-07-02 08:19 . 2011-07-02 08:19 -------- d-----w- c:\program files\Common Files\Adobe
2011-07-02 08:17 . 2010-07-20 06:26 88616 ----a-w- c:\windows\system32\drivers\btwaudio.sys
2011-07-02 08:17 . 2010-07-20 06:26 111656 ----a-w- c:\windows\system32\drivers\btwavdt.sys
2011-07-02 08:17 . 2010-07-20 06:26 18728 ----a-w- c:\windows\system32\drivers\btwrchid.sys
2011-07-02 08:17 . 2010-07-13 23:25 297000 ----a-w- c:\windows\system32\drivers\btwampfl.sys
2011-07-02 08:17 . 2010-03-02 07:37 33320 ----a-w- c:\windows\system32\drivers\btwl2cap.sys
2011-07-02 08:14 . 2011-07-02 08:14 -------- d-----w- c:\program files\WIDCOMM
2011-07-02 08:14 . 2011-07-02 08:28 -------- d-----w- c:\users\****
2011-07-02 08:12 . 2011-07-02 08:12 -------- d-----w- C:\Recovery
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-02 08:14 . 2010-06-24 02:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-06-16 04:44 . 2011-07-02 08:31 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-07 8555040]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-7-21 836896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-07-13 297000]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-02 33320]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2010-10-07 10752]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-04-01 109056]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2010-07-08 322336]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://samsung.msn.com
IE: Invia immagine alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Invia pagina alla periferica &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\****\AppData\Roaming\Mozilla\Firefox\Profiles\ksnak1my.default\
FF - prefs.js: browser.startup.homepage -
www.google.it.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2011-07-03 11:39:29
ComboFix-quarantined-files.txt 2011-07-03 09:39
ComboFix2.txt 2011-07-03 09:00
ComboFix3.txt 2011-07-02 09:48
.
Pre-Run: 70.688.796.672 byte disponibili
Post-Run: 70.643.240.960 byte disponibili
.
- - End Of File - - 7461F6EA4CD9ED59C83C54B5CDBFA6A4